Re: UEFI Secure Boot changes in d-i and live images

2019-01-20 Thread Steve McIntyre
On Sun, Jan 20, 2019 at 12:35:16AM +, Ben Hutchings wrote: >On Sun, 2019-01-20 at 00:16 +0100, Philipp Kern wrote: >> Hi, >> >> On 2019-01-13 20:23, Steve McIntyre wrote: >[...] >> > I'll test all these again in the next couple of days to verify that >> > things have pulled through as I expect

Re: UEFI Secure Boot changes in d-i and live images

2019-01-20 Thread Bastian Blank
On Sun, Jan 20, 2019 at 12:35:16AM +, Ben Hutchings wrote: > Yes, this is expected. Does anyone want to implement the proposal I > made at > or are we just going to have a flag day and hope no-one screws up after > that? The FTP

Re: UEFI Secure Boot changes in d-i and live images

2019-01-19 Thread Ben Hutchings
On Sun, 2019-01-20 at 00:16 +0100, Philipp Kern wrote: > Hi, > > On 2019-01-13 20:23, Steve McIntyre wrote: [...] > > I'll test all these again in the next couple of days to verify that > > things have pulled through as I expect, then it's time to post to > > d-d-a and write a blog too. We've made

Re: UEFI Secure Boot changes in d-i and live images

2019-01-19 Thread Philipp Kern
Hi, On 2019-01-13 20:23, Steve McIntyre wrote: I've just pushed changes to a few bits of d-i this weekend to make SB work for amd64: * build/util/efi-image: We can use pre-existing (and already signed) EFI binaries instead of building a new monolithic image ourselves (which won't be

Re: UEFI Secure Boot changes in d-i and live images

2019-01-14 Thread Domenico Andreoli
On Sun, Jan 13, 2019 at 07:23:43PM +, Steve McIntyre wrote: > Hi folks, Hi Steve, > I've just pushed changes to a few bits of d-i this weekend to make SB > work for amd64: Epic!! This is fantastic news :) > The effect of these changes is that the next daily and weekly debian > installer ima

Re: UEFI Secure Boot changes in d-i and live images

2019-01-13 Thread Cyril Brulebois
Hi Steve, Steve McIntyre (2019-01-13): > I've just pushed changes to a few bits of d-i this weekend to make SB > work for amd64: \o/ And thanks to everyone involved! > * build/util/efi-image: > >We can use pre-existing (and already signed) EFI binaries instead >of building a new mono

UEFI Secure Boot changes in d-i and live images

2019-01-13 Thread Steve McIntyre
Hi folks, I've just pushed changes to a few bits of d-i this weekend to make SB work for amd64: * build/util/efi-image: We can use pre-existing (and already signed) EFI binaries instead of building a new monolithic image ourselves (which won't be signed). We'll also need to install the