Bug#996202: EFI Secure Boot for systemd-boot

2024-05-22 Thread Luca Boccassi
On Fri, 10 May 2024 at 15:51, Luca Boccassi wrote: > > On Fri, 10 May 2024 at 15:49, Steve McIntyre wrote: > > > > On Fri, May 10, 2024 at 03:44:35PM +0100, Luca Boccassi wrote: > > >On Fri, 10 May 2024 at 15:36, Steve McIntyre wrote: > > >> On Fri, May 10, 2024 at 04:29:00PM +0200, Ansgar 🙀 wro

Bug#996202: EFI Secure Boot for systemd-boot

2024-05-10 Thread Luca Boccassi
On Fri, 10 May 2024 at 15:49, Steve McIntyre wrote: > > On Fri, May 10, 2024 at 03:44:35PM +0100, Luca Boccassi wrote: > >On Fri, 10 May 2024 at 15:36, Steve McIntyre wrote: > >> On Fri, May 10, 2024 at 04:29:00PM +0200, Ansgar 🙀 wrote: > >> > >> >Maybe we should use a non-trusted cert for the in

Bug#996202: EFI Secure Boot for systemd-boot

2024-05-10 Thread Steve McIntyre
On Fri, May 10, 2024 at 03:44:35PM +0100, Luca Boccassi wrote: >On Fri, 10 May 2024 at 15:36, Steve McIntyre wrote: >> On Fri, May 10, 2024 at 04:29:00PM +0200, Ansgar 🙀 wrote: >> >> >Maybe we should use a non-trusted cert for the initial setup and only >> >switch to a proper cert once everything

Bug#996202: EFI Secure Boot for systemd-boot

2024-05-10 Thread Luca Boccassi
On Fri, 10 May 2024 at 15:36, Steve McIntyre wrote: > > On Fri, May 10, 2024 at 04:29:00PM +0200, Ansgar 🙀 wrote: > >Hi, > > > >On Fri, 2024-05-10 at 15:20 +0100, Luca Boccassi wrote: > >> On Thu, 04 Apr 2024 20:41:59 +0100 Luca Boccassi > >> > On IRC Steve mentioned that he's ok with proceeding

Bug#996202: EFI Secure Boot for systemd-boot

2024-05-10 Thread Steve McIntyre
On Fri, May 10, 2024 at 04:29:00PM +0200, Ansgar 🙀 wrote: >Hi, > >On Fri, 2024-05-10 at 15:20 +0100, Luca Boccassi wrote: >> On Thu, 04 Apr 2024 20:41:59 +0100 Luca Boccassi >> > On IRC Steve mentioned that he's ok with proceeding with this. >> > jcristau from DSA said that it's the FTP team that

Bug#996202: EFI Secure Boot for systemd-boot

2024-05-10 Thread Ansgar 🙀
Hi, On Fri, 2024-05-10 at 15:20 +0100, Luca Boccassi wrote: > On Thu, 04 Apr 2024 20:41:59 +0100 Luca Boccassi > > On IRC Steve mentioned that he's ok with proceeding with this. > > jcristau from DSA said that it's the FTP team that should confirm the > > request > > for the new intermediate sig

Bug#996202: EFI Secure Boot for systemd-boot

2024-05-10 Thread Luca Boccassi
On Thu, 04 Apr 2024 20:41:59 +0100 Luca Boccassi wrote: > On Fri, 22 Mar 2024 18:13:35 + Luca Boccassi > wrote: > > On Mon, 4 Mar 2024 at 23:58, Luca Boccassi wrote: > > > > > > On Mon, 4 Mar 2024 at 23:28, Steve McIntyre > wrote: > > > > > > > Modulo those questions, let's talk infrastruct

Bug#996202: EFI Secure Boot for systemd-boot

2024-04-04 Thread Luca Boccassi
On Fri, 22 Mar 2024 18:13:35 + Luca Boccassi wrote: > On Mon, 4 Mar 2024 at 23:58, Luca Boccassi wrote: > > > > On Mon, 4 Mar 2024 at 23:28, Steve McIntyre wrote: > > > > > Modulo those questions, let's talk infrastructure. Off the top of my > > > head, in no particular order... > > > > > > 

Bug#996202: EFI Secure Boot for systemd-boot

2024-03-22 Thread Luca Boccassi
On Mon, 4 Mar 2024 at 23:58, Luca Boccassi wrote: > > On Mon, 4 Mar 2024 at 23:28, Steve McIntyre wrote: > > > Modulo those questions, let's talk infrastructure. Off the top of my > > head, in no particular order... > > > > * We'll need to create a new intermediate signing cert for > > syst

Bug#996202: EFI Secure Boot for systemd-boot

2024-03-09 Thread Luca Boccassi
On Sat, 9 Mar 2024 at 09:59, Pascal Hambourg wrote: > > On 05/03/2024 at 00:58, Luca Boccassi wrote: > > On Mon, 4 Mar 2024 at 23:28, Steve McIntyre wrote: > >> > >> What's your plan for installing as the secondary boot loader for shim > >> to call? > > > > 'bootctl update' already recognises and

Bug#996202: EFI Secure Boot for systemd-boot

2024-03-09 Thread Pascal Hambourg
On 05/03/2024 at 00:58, Luca Boccassi wrote: On Mon, 4 Mar 2024 at 23:28, Steve McIntyre wrote: What's your plan for installing as the secondary boot loader for shim to call? 'bootctl update' already recognises and prefers foo.efi.signed if present, so installing to the ESP is easy (PR still

Bug#996202: EFI Secure Boot for systemd-boot

2024-03-04 Thread Luca Boccassi
On Mon, 4 Mar 2024 at 23:28, Steve McIntyre wrote: > > Hey folks, > > On Mon, Mar 04, 2024 at 02:13:25AM +, Luca Boccassi wrote: > >On Fri, 19 Nov 2021 09:33:00 +0100 Bastian Blank > >wrote: > >> Hi > >> > >> I'm rescinding this request. I've got a working prototype, but I > >don't > >> know

Bug#996202: EFI Secure Boot for systemd-boot

2024-03-04 Thread Steve McIntyre
Hey folks, On Mon, Mar 04, 2024 at 02:13:25AM +, Luca Boccassi wrote: >On Fri, 19 Nov 2021 09:33:00 +0100 Bastian Blank >wrote: >> Hi >> >> I'm rescinding this request.  I've got a working prototype, but I >don't >> know where this would go. >> >> Bastian > >The upstream Shim reviewers grou

Bug#996202: EFI Secure Boot for systemd-boot

2024-03-03 Thread Luca Boccassi
On Fri, 19 Nov 2021 09:33:00 +0100 Bastian Blank wrote: > Hi > > I'm rescinding this request.  I've got a working prototype, but I don't > know where this would go. > > Bastian The upstream Shim reviewers group now accepts systemd-boot as a 2nd stage bootloader, trusted by Shim builds signed wi