Branch: refs/heads/master
Home: https://github.com/tianocore/edk2
Commit: 3c01a11daae2285b271a003122019e0b5cc52399
https://github.com/tianocore/edk2/commit/3c01a11daae2285b271a003122019e0b5cc52399
Author: Gerd Hoffmann <[email protected]>
Date: 2026-04-08 (Wed, 08 Apr 2026)
Changed paths:
M OvmfPkg/Bhyve/BhyveX64.dsc
M OvmfPkg/CloudHv/CloudHvX64.dsc
M OvmfPkg/IntelTdx/IntelTdxX64.dsc
M OvmfPkg/LoongArchVirt/LoongArchVirtQemu.dsc
M OvmfPkg/Microvm/MicrovmX64.dsc
M OvmfPkg/OvmfPkgIa32X64.dsc
M OvmfPkg/OvmfPkgX64.dsc
Log Message:
-----------
OvmfPkg: set PcdRequireSelfSignedPk to FALSE
Recent UEFI spec versions do not require a self-signed PK any more.
There is no good reason for OVMF to stick to this requirement, but
there is one reason to remove it: It is not needed to enable
CustomMode then to enroll secure boot keys which are not self-signed.
Signed-off-by: Gerd Hoffmann <[email protected]>
Commit: 0a7ed7ed345749707dea0f8f264ef42924a65546
https://github.com/tianocore/edk2/commit/0a7ed7ed345749707dea0f8f264ef42924a65546
Author: Gerd Hoffmann <[email protected]>
Date: 2026-04-08 (Wed, 08 Apr 2026)
Changed paths:
M OvmfPkg/EnrollDefaultKeys/EnrollDefaultKeys.c
Log Message:
-----------
OvmfPkg/EnrollDefaultKeys: do not require CustomMode
If OVMF is built with PcdRequireSelfSignedPk=FALSE it is possible to
enroll an unsigned platform key (PK) without depending on CustomMode for
that.
Update EnrollDefaultKeys accordingly. If setting CustomMode fails do
not consider that a fatal error. Print a warning instead. Also update
Settings.CustomMode only in case CustomMode has been enabled
successfully, so we can use that later on to check whenever CustomMode
must be disabled or not.
Signed-off-by: Gerd Hoffmann <[email protected]>
Commit: 75ea215310cdc88554d22de6430ac4988dbc5156
https://github.com/tianocore/edk2/commit/75ea215310cdc88554d22de6430ac4988dbc5156
Author: Gerd Hoffmann <[email protected]>
Date: 2026-04-08 (Wed, 08 Apr 2026)
Changed paths:
M OvmfPkg/EnrollDefaultKeys/EnrollDefaultKeys.c
Log Message:
-----------
OvmfPkg/EnrollDefaultKeys: do not check VendorKeys
AuthVariableLib behavior wrt VendorKeys changes depending on
PcdRequireSelfSignedPk state. Given this is not security critical
just skip the VendorKeys check in EnrollDefaultKeys
Signed-off-by: Gerd Hoffmann <[email protected]>
Commit: e3e5c415988db20ca2e8c9343a34bdb18467544a
https://github.com/tianocore/edk2/commit/e3e5c415988db20ca2e8c9343a34bdb18467544a
Author: Gerd Hoffmann <[email protected]>
Date: 2026-04-08 (Wed, 08 Apr 2026)
Changed paths:
M OvmfPkg/IgvmSecureBootDxe/IgvmSecureBootDxe.c
M OvmfPkg/IgvmSecureBootDxe/IgvmSecureBootDxe.inf
Log Message:
-----------
OvmfPkg/IgvmSecureBootDxe: enable CustomMode only if needed
If OVMF is built with PcdRequireSelfSignedPk=FALSE we do not need
CustomMode to enroll an unsigned platform key (PK).
Signed-off-by: Gerd Hoffmann <[email protected]>
Compare: https://github.com/tianocore/edk2/compare/3ed3b7a4aeaf...e3e5c415988d
To unsubscribe from these emails, change your notification settings at
https://github.com/tianocore/edk2/settings/notifications
_______________________________________________
edk2-commits mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/edk2-commits