Re: [systemd-devel] Passing Kernel Params from systemd-boot for Secure Boot UKI

2024-10-08 Thread Lennart Poettering
On Di, 08.10.24 14:25, Mah, Yock Gen (yock.gen@intel.com) wrote: > Thanks! I did below: > ukify build --secureboot-private-key=../../db.key > --secureboot-certificate=../../db.crt --cmdline='yockgen' > --sbat='sbat,1,SBAT > Version,sbat,1,https://github.com/rhboot/shim/blob/main/SBAT.md

Re: [systemd-devel] Passing Kernel Params from systemd-boot for Secure Boot UKI

2024-10-08 Thread Mah, Yock Gen
Thanks! I did below: ukify build --secureboot-private-key=../../db.key --secureboot-certificate=../../db.crt --cmdline='yockgen' --sbat='sbat,1,SBAT Version,sbat,1,https://github.com/rhboot/shim/blob/main/SBAT.md uki-addon.author,1,UKI Addon for System,uki-addon.author,1,https://www.freede

Re: [systemd-devel] Passing Kernel Params from systemd-boot for Secure Boot UKI

2024-10-08 Thread Lennart Poettering
On Di, 08.10.24 12:37, Mah, Yock Gen (yock.gen@intel.com) wrote: > Really appreciate! I tried to create an PE "addon" using below: > > echo "yockgen=b" > cmdline.txt > > objcopy --input binary --output efi-app-x86_64 cmdline.txt > bootdm_b.addon.efi This doesn't look right. You must insert th

Re: [systemd-devel] Passing Kernel Params from systemd-boot for Secure Boot UKI

2024-10-08 Thread Mah, Yock Gen
Really appreciate! I tried to create an PE "addon" using below: echo "yockgen=b" > cmdline.txt objcopy --input binary --output efi-app-x86_64 cmdline.txt bootdm_b.addon.efi sudo sbsign --key ../../db.key --cert ../../db.crt --output bootdm_b.addon.signed bootdm_b.addon.efi But failed at last s

Re: [systemd-devel] Passing Kernel Params from systemd-boot for Secure Boot UKI

2024-10-08 Thread Mikko Rapeli
Hi, On Tue, Oct 08, 2024 at 09:22:05AM +0200, Lennart Poettering wrote: > On Mo, 07.10.24 13:54, Mah, Yock Gen (yock.gen@intel.com) wrote: > > > My Mariner OS is built with following features: > > > > 1, Unified Kernel Image (kernel+initrd+cmdline) > > 2. Systemd-boot as boot loader > > 3. Se

Re: [systemd-devel] Passing Kernel Params from systemd-boot for Secure Boot UKI

2024-10-08 Thread Lennart Poettering
On Mo, 07.10.24 13:54, Mah, Yock Gen (yock.gen@intel.com) wrote: > My Mariner OS is built with following features: > > 1, Unified Kernel Image (kernel+initrd+cmdline) > 2. Systemd-boot as boot loader > 3. Secure Boot enabled > 4. Multi boot > > Systemd-boot config files looks like below > > ``