Branch: refs/heads/master
  Home:   https://github.com/tianocore/edk2
  Commit: 3c01a11daae2285b271a003122019e0b5cc52399
      
https://github.com/tianocore/edk2/commit/3c01a11daae2285b271a003122019e0b5cc52399
  Author: Gerd Hoffmann <[email protected]>
  Date:   2026-04-08 (Wed, 08 Apr 2026)

  Changed paths:
    M OvmfPkg/Bhyve/BhyveX64.dsc
    M OvmfPkg/CloudHv/CloudHvX64.dsc
    M OvmfPkg/IntelTdx/IntelTdxX64.dsc
    M OvmfPkg/LoongArchVirt/LoongArchVirtQemu.dsc
    M OvmfPkg/Microvm/MicrovmX64.dsc
    M OvmfPkg/OvmfPkgIa32X64.dsc
    M OvmfPkg/OvmfPkgX64.dsc

  Log Message:
  -----------
  OvmfPkg: set PcdRequireSelfSignedPk to FALSE

Recent UEFI spec versions do not require a self-signed PK any more.
There is no good reason for OVMF to stick to this requirement, but
there is one reason to remove it:  It is not needed to enable
CustomMode then to enroll secure boot keys which are not self-signed.

Signed-off-by: Gerd Hoffmann <[email protected]>


  Commit: 0a7ed7ed345749707dea0f8f264ef42924a65546
      
https://github.com/tianocore/edk2/commit/0a7ed7ed345749707dea0f8f264ef42924a65546
  Author: Gerd Hoffmann <[email protected]>
  Date:   2026-04-08 (Wed, 08 Apr 2026)

  Changed paths:
    M OvmfPkg/EnrollDefaultKeys/EnrollDefaultKeys.c

  Log Message:
  -----------
  OvmfPkg/EnrollDefaultKeys: do not require CustomMode

If OVMF is built with  PcdRequireSelfSignedPk=FALSE it is possible to
enroll an unsigned platform key (PK) without depending on CustomMode for
that.

Update EnrollDefaultKeys accordingly.  If setting CustomMode fails do
not consider that a fatal error.  Print a warning instead.  Also update
Settings.CustomMode only in case CustomMode has been enabled
successfully, so we can use that later on to check whenever CustomMode
must be disabled or not.

Signed-off-by: Gerd Hoffmann <[email protected]>


  Commit: 75ea215310cdc88554d22de6430ac4988dbc5156
      
https://github.com/tianocore/edk2/commit/75ea215310cdc88554d22de6430ac4988dbc5156
  Author: Gerd Hoffmann <[email protected]>
  Date:   2026-04-08 (Wed, 08 Apr 2026)

  Changed paths:
    M OvmfPkg/EnrollDefaultKeys/EnrollDefaultKeys.c

  Log Message:
  -----------
  OvmfPkg/EnrollDefaultKeys: do not check VendorKeys

AuthVariableLib behavior wrt VendorKeys changes depending on
PcdRequireSelfSignedPk state.  Given this is not security critical
just skip the VendorKeys check in EnrollDefaultKeys

Signed-off-by: Gerd Hoffmann <[email protected]>


  Commit: e3e5c415988db20ca2e8c9343a34bdb18467544a
      
https://github.com/tianocore/edk2/commit/e3e5c415988db20ca2e8c9343a34bdb18467544a
  Author: Gerd Hoffmann <[email protected]>
  Date:   2026-04-08 (Wed, 08 Apr 2026)

  Changed paths:
    M OvmfPkg/IgvmSecureBootDxe/IgvmSecureBootDxe.c
    M OvmfPkg/IgvmSecureBootDxe/IgvmSecureBootDxe.inf

  Log Message:
  -----------
  OvmfPkg/IgvmSecureBootDxe: enable CustomMode only if needed

If OVMF is built with PcdRequireSelfSignedPk=FALSE we do not need
CustomMode to enroll an unsigned platform key (PK).

Signed-off-by: Gerd Hoffmann <[email protected]>


Compare: https://github.com/tianocore/edk2/compare/3ed3b7a4aeaf...e3e5c415988d

To unsubscribe from these emails, change your notification settings at 
https://github.com/tianocore/edk2/settings/notifications


_______________________________________________
edk2-commits mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/edk2-commits

Reply via email to