Re: [Bug 1696154] Comment bridged from LTC Bugzilla

2017-10-05 Thread Steve Langasek
On Thu, Oct 05, 2017 at 01:52:46AM -, bugproxy wrote: > --- Comment From gcwil...@us.ibm.com 2017-10-04 17:33 EDT--- > I have received the KEK from Emily in person. > --- Comment From gcwil...@us.ibm.com 2017-10-04 18:16 EDT--- > BTW, I learned from Emily that Canonical plans

[Bug 1696154] Comment bridged from LTC Bugzilla

2017-10-04 Thread bugproxy
--- Comment From gcwil...@us.ibm.com 2017-10-04 17:33 EDT--- I have received the KEK from Emily in person. --- Comment From gcwil...@us.ibm.com 2017-10-04 18:16 EDT--- BTW, I learned from Emily that Canonical plans to issue Power keys/certs separately from those for the x86 UEFI s

Re: [Bug 1696154] Comment bridged from LTC Bugzilla

2017-10-03 Thread Steve Langasek
Hi Claudio, > --- Comment From cclau...@br.ibm.com 2017-09-27 16:47 EDT--- > (In reply to comment #30) > > Attached is the ESL db update for Canonical's POWER SecureBoot signing key. > > It is signed with Canonical's KEK key, which will be provided to IBM out of > > band to ensure integrit

[Bug 1696154] Comment bridged from LTC Bugzilla

2017-09-27 Thread bugproxy
--- Comment From cclau...@br.ibm.com 2017-09-27 16:47 EDT--- (In reply to comment #30) > Attached is the ESL db update for Canonical's POWER SecureBoot signing key. > It is signed with Canonical's KEK key, which will be provided to IBM out of > band to ensure integrity of the delivery chann

[Bug 1696154] Comment bridged from LTC Bugzilla

2017-09-08 Thread bugproxy
--- Comment From l...@us.ibm.com 2017-09-08 13:05 EDT--- (In reply to comment #27) > (In reply to comment #25) > > Does IBM have any feedback for us regarding the test kernel Andy provided? > > > > We're planning to test this month. We'll give feedback as soon as the test > is completed.

Re: [Bug 1696154] Comment bridged from LTC Bugzilla

2017-09-07 Thread Steve Langasek
On Thu, Sep 07, 2017 at 11:50:09PM -, bugproxy wrote: > --- Comment From l...@us.ibm.com 2017-09-07 19:41 EDT--- > (In reply to comment #25) > > Does IBM have any feedback for us regarding the test kernel Andy provided? > We're planning to test this month. We'll give feedback as soon

[Bug 1696154] Comment bridged from LTC Bugzilla

2017-09-07 Thread bugproxy
--- Comment From l...@us.ibm.com 2017-09-07 19:41 EDT--- (In reply to comment #25) > Does IBM have any feedback for us regarding the test kernel Andy provided? > We're planning to test this month. We'll give feedback as soon as the test is completed. The tentative target will be Sept. 29

[Bug 1696154] Comment bridged from LTC Bugzilla

2017-08-01 Thread bugproxy
--- Comment From cclau...@br.ibm.com 2017-08-01 19:06 EDT--- (In reply to comment #15) > One open technical question from the Canonical side: can you confirm that > the POWER firmware implementation will support embedded certificate chains > as part of the vmlinux signature data? Our exist

[Bug 1696154] Comment bridged from LTC Bugzilla

2017-07-20 Thread bugproxy
--- Comment From drbr...@us.ibm.com 2017-07-20 17:52 EDT--- Canonical please clarify. I was on a call with Andrew Cloke earlier today. He said this could be done but not done in time for 17.10 GA in October. It would happen after 17.10 GA. -- You received this bug notification because y

[Bug 1696154] Comment bridged from LTC Bugzilla

2017-07-20 Thread bugproxy
--- Comment From drbr...@us.ibm.com 2017-07-20 14:16 EDT--- Canonical please clarify. I was on a call with Andrew Cloke earlier today. He said this could be done but not done in time for 17.10 GA in October. It would happen after 17.10 GA. -- You received this bug notification because y

[Bug 1696154] Comment bridged from LTC Bugzilla

2017-07-18 Thread bugproxy
--- Comment From l...@us.ibm.com 2017-07-18 17:15 EDT--- Is there any update that you can share at the moment? -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1696154 Title: [17.10 FEAT] Sign

[Bug 1696154] Comment bridged from LTC Bugzilla

2017-07-13 Thread bugproxy
--- Comment From l...@us.ibm.com 2017-07-13 16:51 EDT--- Hi Canonical, Please let me know if there are any concerns on signing the the Ubuntu kernel for the 17.10 release. Thanks, Vicky -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to

[Bug 1696154] Comment bridged from LTC Bugzilla

2017-07-10 Thread bugproxy
--- Comment From l...@us.ibm.com 2017-07-10 16:49 EDT--- Hi Canonical, Here are some clarifications on the feature from the security team: > To clarify, this feature is only asking for a change to the Ubuntu kernel > build > process to produce a signed kernel and no other development. T