Re: UEFI Secure Boot changes in d-i and live images
On Sun, Jan 20, 2019 at 12:35:16AM +0000, Ben Hutchings wrote:
>On Sun, 2019-01-20 at 00:16 +0100, Philipp Kern wrote:
>> Hi,
>>
>> On 2019-01-13 20:23, Steve McIntyre wrote:
>[...]
>> > I'll test all these again in the next couple of days to verify that
>> > things have pulled through as I expect, then it's time to post to
>> > d-d-a and write a blog too. We've made great progress already. These
>> > last changes just tie it all together for end users.
>>
>> I just tried to test this. As far as I can see grub is still signed by
>> "secure-boot-test-key-lfaraone" as of netinst from yesterday (Saturday).
>[...]
>
>Yes, this is expected.
Yup. I'd *thought* I'd tested end-to-end with a clean machine, but it
looks like I fat-fingered the mok key removal and still had Luke's
test key installed. I've just forced cleanup now and retested and I
see the same behaviour as Philipp.
--
Steve McIntyre, Cambridge, UK. steve@einval.com
"I've only once written 'SQL is my bitch' in a comment. But that code
is in use on a military site..." -- Simon Booth
Reply to: