[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: UEFI Secure Boot changes in d-i and live images



On Sun, Jan 20, 2019 at 12:35:16AM +0000, Ben Hutchings wrote:
>On Sun, 2019-01-20 at 00:16 +0100, Philipp Kern wrote:
>> Hi,
>> 
>> On 2019-01-13 20:23, Steve McIntyre wrote:
>[...]
>> > I'll test all these again in the next couple of days to verify that
>> > things have pulled through as I expect, then it's time to post to
>> > d-d-a and write a blog too. We've made great progress already. These
>> > last changes just tie it all together for end users.
>> 
>> I just tried to test this. As far as I can see grub is still signed by 
>> "secure-boot-test-key-lfaraone" as of netinst from yesterday (Saturday). 
>[...]
>
>Yes, this is expected.

Yup. I'd *thought* I'd tested end-to-end with a clean machine, but it
looks like I fat-fingered the mok key removal and still had Luke's
test key installed. I've just forced cleanup now and retested and I
see the same behaviour as Philipp.

-- 
Steve McIntyre, Cambridge, UK.                                steve@einval.com
"I've only once written 'SQL is my bitch' in a comment. But that code 
 is in use on a military site..." -- Simon Booth


Reply to: