[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: UEFI Secure Boot sprint report



On Tue, 2018-05-15 at 11:07 +0900, Hideki Yamane wrote:
> Hi,
> 
>  Thanks for the clarification, Ben. Very helpful.
> 
> On Mon, 14 May 2018 15:35:50 +0100
> Ben Hutchings <ben@decadent.org.uk> wrote:
> > The second point (have DAK accept ...) is part of step 7, yes.  It
> > seems to have been implemented now.
> 
>  Then, remaining blocker is only template for GRUB2?

For testing purposes, I think so.  I don't know whether GRUB implements
the policy we want at the moment.

We'll still need a "flag day" on which the signing service, and all
packages that get signed, switch to production signing keys.

Ben.

-- 
Ben Hutchings
Unix is many things to many people,
but it's never been everything to anybody.

Attachment: signature.asc
Description: This is a digitally signed message part


Reply to: