Agenda

0)Open

Microsoft raised open to add GetVariableInfo() update to return more variable 
storage info. Just initial thought. No solid proposal yet.
We will defer the discussion in the next week.

*AR: Sean* to revisit the topic in the next week. We can decide to add or drop 
for UEFI.next.

1) Backlog review

https://github.com/orgs/tianocore/projects/10/views/1 

No new issue.

2) Old issue refresh

2.1) https://github.com/tianocore/edk2/issues/12561 
Pre-quantum is removed. Good to go.

2.2) https://github.com/tianocore/edk2/issues/12688
( https://github.com/tianocore/edk2/issues/12688 )
Doug is working on IEIT removal.
*AR: Doug* to make it ready for review in the next meeting.

Joey has internal discussion for the new table.
*AR: Joey* to submit the new table proposal for discussion in the next meeting.

3) Some idea for image verification

https://github.com/microsoft/mu_basecore/pull/1809 ( 
https://github.com/microsoft/mu_basecore/pull/1809 )

3.1) DB based trust anchor is the right understand.

This aligned with PKI system.
See https://github.com/microsoft/mu_basecore/pull/1809#issuecomment-4937530999

It does add code complexity because current EDK2 code does not support the DB 
based trust anchor yet.
We think it is the right approach, and we need to define the expected behavior 
clearly.

3.2) Joey shared test case design - ImageValidationApp.

See 
https://github.com/Javagedes/mu_basecore/tree/personal/joeyvagedes/securitypkg-image-validation/SecurityPkg/Test/ShellTest/ImageValidationTestApp
Current code coverage data shows more than 95%. Almost covered all code.

*AR: all* to review the test case ( 
https://github.com/Javagedes/mu_basecore/tree/personal/joeyvagedes/securitypkg-image-validation/SecurityPkg/Test/ShellTest/ImageValidationTestApp#all-tests
 ), and submit feedback if there is any.

3.3) Jiewen discussed the multiple signature mechanism.

It is vague today.
See https://github.com/microsoft/mu_basecore/pull/1809#issuecomment-4715281246

Conclusion is:
(1) Multiple WIN_CERTIFICATE entries — SUPPORTED.
(2) Nested signature — NOT supported. It is only for windows.
(3) Multiple SignerInfos in one SignedData — NOT supported.

*AR: Jiewen* to add clarification into UEFI spec ECR.

Thank you
Yao, Jiewen


-=-=-=-=-=-=-=-=-=-=-=-
Groups.io Links: You receive all messages sent to this group.
View/Reply Online (#122043): https://edk2.groups.io/g/devel/message/122043
Mute This Topic: https://groups.io/mt/120396653/21656
Group Owner: [email protected]
Unsubscribe: https://edk2.groups.io/g/devel/unsub [[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-


Reply via email to