[Bug 1939565] Re: kernel signed by mok failed to boot if secure boot is on

2021-09-03 Thread Yuan-Chen Cheng
got the other single failure case and confirm it's caused by another mistake. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1939565 Title: kernel signed by mok failed to boot if secure boot is on T

[Bug 1939565] Re: kernel signed by mok failed to boot if secure boot is on

2021-09-01 Thread Yuan-Chen Cheng
per my current test on i+n, it works fine. There seems to have some other single failure case, still wait the machine to be availe. Give so, close it here for now. ** Changed in: oem-priority Status: Confirmed => Fix Released ** Changed in: oem-priority Status: Fix Released => Inv

Re: [Bug 1939565] Re: kernel signed by mok failed to boot if secure boot is on

2021-08-30 Thread Steve Langasek
On Sun, Aug 29, 2021 at 09:02:38PM -, Jacob wrote: > Could we add an option to `update-secureboot-policy` so that it can > generate a key that works for signing modules & kernels ? This would be a low priority to change, and we would need to take a good deal of care around the user interface

[Bug 1939565] Re: kernel signed by mok failed to boot if secure boot is on

2021-08-30 Thread Yuan-Chen Cheng
It test pass on UMA machine. I heard there is failed case on I+N, will also test on that. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1939565 Title: kernel signed by mok failed to boot if secure b

[Bug 1939565] Re: kernel signed by mok failed to boot if secure boot is on

2021-08-30 Thread Yuan-Chen Cheng
Hi Ivan, per check, I do add "-config /usr/lib/shim/mok/openssl.cnf" as create mok for kernel in development mode. I'll re-create a key and update test result. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/

[Bug 1939565] Re: kernel signed by mok failed to boot if secure boot is on

2021-08-30 Thread Ivan Hu
Follow up the tests for comment#12, the same test kernel v5.14.0-rc7 signed with the original created key in /var/lib/shim-signed/test_kernel will not boot up with getting the invalid signature error. compare the keys between /var/lib/shim-signed/test_kernel and comment#12(/var/lib/test_ker/), th

[Bug 1939565] Re: kernel signed by mok failed to boot if secure boot is on

2021-08-29 Thread Jacob
Hi Steve Langasek, Could we add an option to `update-secureboot-policy` so that it can generate a key that works for signing modules & kernels ? As an aside, if an attacker has compromised a system and they generate a signing key ... they could modify and attempt to enrol a key that allows kernel

[Bug 1939565] Re: kernel signed by mok failed to boot if secure boot is on

2021-08-29 Thread Steve Langasek
A signed kernel module and a signed kernel have different security properties: a signed kernel has access to the firmware state prior to calling ExitBootServices, a module does not. So, no, this implementation in the shim package which was implemented specifically to support dkms modules should no

[Bug 1939565] Re: kernel signed by mok failed to boot if secure boot is on

2021-08-29 Thread Jacob
Hi Steve Langasek, If an attacker is able to sign a custom kernel module & compromise a system via that means is there a reason to restrict the rather easy to use `update-secureboot-policy --new-key` method to only kernel modules? (Can we modify it to allow signing kernels in addition to kernel

[Bug 1939565] Re: kernel signed by mok failed to boot if secure boot is on

2021-08-24 Thread Steve Langasek
The original bug report does not say how the MOK has been generated. If it is generated using the maintainer script integrations in shim- signed (the update-secureboot-policy command), note that the openssl config in /usr/lib/shim/mok/openssl.cnf generates a key which is specifically annotated as

[Bug 1939565] Re: kernel signed by mok failed to boot if secure boot is on

2021-08-24 Thread Ivan Hu
Got the Latitude 7520 machine, from the shim's log, it seems something wrong in the self signed certificate and the binary is not authorized. And do some tests, basically base on the comment#6, install another test kernel and signed/enrolled with another MOK key manually. 1. install test kernel(u

[Bug 1939565] Re: kernel signed by mok failed to boot if secure boot is on

2021-08-19 Thread Yuan-Chen Cheng
AI: the message scroll up, so let me pass the machine to Ivan. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1939565 Title: kernel signed by mok failed to boot if secure boot is on To manage notifi

[Bug 1939565] Re: kernel signed by mok failed to boot if secure boot is on

2021-08-19 Thread Ivan Hu
Test again with my UEFI develop kit(RainbowPass) platform by following procedures and still cannot reproduce this issue. 1. install focal 2. update shim-signed to 1.40.6+15.4.0ubuntu7 and grub2 to 2.04-1ubuntu26.12 3. install mainline kernel(unsigned), https://kernel.ubuntu.com/~kernel-ppa/mainl

[Bug 1939565] Re: kernel signed by mok failed to boot if secure boot is on

2021-08-19 Thread Yuan-Chen Cheng
AI: $ sudo mokutil --set-verbose true, and capture the log. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1939565 Title: kernel signed by mok failed to boot if secure boot is on To manage notificat

[Bug 1939565] Re: kernel signed by mok failed to boot if secure boot is on

2021-08-18 Thread Ivan Hu
After singing kernel modules and enroll key to MOK, still cannot reproduce this with my UEFI develop kit(RainbowPass) platform. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1939565 Title: kernel si

[Bug 1939565] Re: kernel signed by mok failed to boot if secure boot is on

2021-08-17 Thread Yuan-Chen Cheng
Could you also enrolled mok for kernel module? (One mok for kernel and the other for kernel module) It seem two mok will confuse shim. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1939565 Title: k

[Bug 1939565] Re: kernel signed by mok failed to boot if secure boot is on

2021-08-17 Thread Ivan Hu
Manually test with my UEFI develop kit(RainbowPass) platform by following procedures and cannot reproduce this issue. 1. install focal 2. update shim-signed to 1.40.6+15.4.0ubuntu7 and grub2 to 2.04-1ubuntu26.12 3. install mainline kernel(unsigned), https://kernel.ubuntu.com/~kernel-ppa/mainline/

[Bug 1939565] Re: kernel signed by mok failed to boot if secure boot is on

2021-08-15 Thread Rex Tsai
** Tags added: oem-priority -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1939565 Title: kernel signed by mok failed to boot if secure boot is on To manage notifications about this bug go to: https

[Bug 1939565] Re: kernel signed by mok failed to boot if secure boot is on

2021-08-14 Thread Yuan-Chen Cheng
note upgrade the follow pkg shim-signed: 1.40.7+15.4-0ubuntu9 grub-common 2.04-1ubuntu26.13 grub2-common 2.04-1ubuntu26.13 from the proposed channel does not help. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpa

[Bug 1939565] Re: kernel signed by mok failed to boot if secure boot is on

2021-08-14 Thread Yuan-Chen Cheng
as this is reproduced, grub version # dpkg -l |grep grub ii grub-common2.04-1ubuntu26.12 amd64GRand Unified Bootloader (common files) ii grub-efi-amd64 2.04-1ubuntu44.2

[Bug 1939565] Re: kernel signed by mok failed to boot if secure boot is on

2021-08-13 Thread Ivan Hu
@ycheng-twn Have you also updated the Grub2? -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1939565 Title: kernel signed by mok failed to boot if secure boot is on To manage notifications about thi

[Bug 1939565] Re: kernel signed by mok failed to boot if secure boot is on

2021-08-12 Thread Kai-Chuan Hsieh
@ycheng-twn I try to update my manifest and install iso on DLPN-MT-EVT-C1/BIOS 0.10.28. The ISO is http://10.101.46.50:8080/job/dell-bto-focal-fossa-davos-adl/lastSuccessfulBuild/artifact/out/dell-bto-focal-fossa-davos-adl-X142-20210812-9.iso I can finish the installation and the secure boot is

[Bug 1939565] Re: kernel signed by mok failed to boot if secure boot is on

2021-08-11 Thread Yuan-Chen Cheng
downgrade shim-signed to 1.40.4+15+1552672080.a4a1fbe-0ubuntu2 and shim 15+1552672080.a4a1fbe-0ubuntu2 Then I can't reproduce this issue. ** Changed in: oem-priority Assignee: (unassigned) => Yuan-Chen Cheng (ycheng-twn) -- You received this bug notification because you are a member of Ubu