Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-142588

fix secure boot verification for direct kernel boot

Linking RHIVOS CVEs to...Migration: Automation ...Sync from "Extern...XMLWordPrintable

    • Icon: Story Story
    • Resolution: Unresolved
    • Icon: Undefined Undefined
    • rhel-10.2
    • None
    • virt-manager
    • None
    • None
    • 1
    • rhel-virt-core-libvirt-2
    • None
    • False
    • False
    • Hide

      None

      Show
      None
    • None
    • Libvirt Bugs already in Sprint
    • None
    • None
    • Unspecified
    • Unspecified
    • Unspecified
    • None

      Goal

      • Historically edk2 did not enforce secure boot verification for kernels passed from qemu for direct kernel boot. This is going to change and virt-install must be adapted to make sure secure boot installs continue to boot.

      Possible approaches:
      (1) probably simplest: pass shim.efi binary in addition to the kernel, via <shim/> next to <kernel/> in libvirt xml.
      (2) rethink network install workflow, use boot.iso + OEMDRV image with kickstart file.

      Turning secure boot off (temporarely) is an option too, possibly depending on libosinfo hints.

      Maybe it makes sense to turn off secure boot by default for all distros which are EOL, I expect older fedora install images will not boot with secure boot anyway due to shim binaries with known security bugs.

              phrdina@redhat.com Pavel Hrdina
              rhn-engineering-ghoffman Gerd Hoffmann
              virt-maint virt-maint
              Ganesh Hubale Ganesh Hubale
              Votes:
              0 Vote for this issue
              Watchers:
              10 Start watching this issue

                Created:
                Updated: