Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-126426

[grub2] Prevent unbootable setups with shims without CA8

Linking RHIVOS CVEs to...Migration: Automation ...SWIFT: POC ConversionSync from "Extern...XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Unresolved
    • Icon: Undefined Undefined
    • None
    • rhel-9.8
    • grub2
    • None
    • None
    • rhel-bootloader
    • 2
    • False
    • False
    • Hide

      None

      Show
      None
    • None
    • None
    • None
    • None
    • Unspecified
    • Unspecified
    • Unspecified
    • None

      Recently, grub2 was switched to using "Red Hat  Secure Boot Signing 802" cert for SecureBoot. This can only work if the shim carries signing CA cert and this is not a given. E.g. shim-x64-15.6-1.el9 from RHEL9.2 does not have it and is not capable of booting anything signed by 800-series certs. 

      The proposed solution is to add an explicit:

      Conflicts: shim-x64 < 15.8-1

      or

      Requires: shim-x64 >= 15.8-1

      to the grub2-efi-x64 package.

              bootloader-eng-team bootloader -eng-team
              vkuznets@redhat.com Vitaly Kuznetsov
              bootloader -eng-team bootloader -eng-team
              Release Test Team Release Test Team
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated: