Bug#996202: EFI Secure Boot for systemd-boot

2024-05-22 Thread Luca Boccassi
On Fri, 10 May 2024 at 15:51, Luca Boccassi wrote: > > On Fri, 10 May 2024 at 15:49, Steve McIntyre wrote: > > > > On Fri, May 10, 2024 at 03:44:35PM +0100, Luca Boccassi wrote: > > >On Fri, 10 May 2024 at 15:36, Steve McIntyre wrote: > > >> On Fri, May 10, 2024 at 04:29:00PM +0200, Ansgar 

Bug#996202: EFI Secure Boot for systemd-boot

2024-05-10 Thread Luca Boccassi
On Fri, 10 May 2024 at 15:49, Steve McIntyre wrote: > > On Fri, May 10, 2024 at 03:44:35PM +0100, Luca Boccassi wrote: > >On Fri, 10 May 2024 at 15:36, Steve McIntyre wrote: > >> On Fri, May 10, 2024 at 04:29:00PM +0200, Ansgar  wrote: > >> > >> >Maybe we should use a non-trusted cert for the

Bug#996202: EFI Secure Boot for systemd-boot

2024-05-10 Thread Steve McIntyre
On Fri, May 10, 2024 at 03:44:35PM +0100, Luca Boccassi wrote: >On Fri, 10 May 2024 at 15:36, Steve McIntyre wrote: >> On Fri, May 10, 2024 at 04:29:00PM +0200, Ansgar  wrote: >> >> >Maybe we should use a non-trusted cert for the initial setup and only >> >switch to a proper cert once everything

Bug#996202: EFI Secure Boot for systemd-boot

2024-05-10 Thread Luca Boccassi
On Fri, 10 May 2024 at 15:36, Steve McIntyre wrote: > > On Fri, May 10, 2024 at 04:29:00PM +0200, Ansgar  wrote: > >Hi, > > > >On Fri, 2024-05-10 at 15:20 +0100, Luca Boccassi wrote: > >> On Thu, 04 Apr 2024 20:41:59 +0100 Luca Boccassi > >> > On IRC Steve mentioned that he's ok with proceeding

Bug#996202: EFI Secure Boot for systemd-boot

2024-05-10 Thread Steve McIntyre
On Fri, May 10, 2024 at 04:29:00PM +0200, Ansgar  wrote: >Hi, > >On Fri, 2024-05-10 at 15:20 +0100, Luca Boccassi wrote: >> On Thu, 04 Apr 2024 20:41:59 +0100 Luca Boccassi >> > On IRC Steve mentioned that he's ok with proceeding with this. >> > jcristau from DSA said that it's the FTP team that

Bug#996202: EFI Secure Boot for systemd-boot

2024-05-10 Thread Ansgar 
Hi, On Fri, 2024-05-10 at 15:20 +0100, Luca Boccassi wrote: > On Thu, 04 Apr 2024 20:41:59 +0100 Luca Boccassi > > On IRC Steve mentioned that he's ok with proceeding with this. > > jcristau from DSA said that it's the FTP team that should confirm the > > request > > for the new intermediate

Bug#996202: EFI Secure Boot for systemd-boot

2024-05-10 Thread Luca Boccassi
On Thu, 04 Apr 2024 20:41:59 +0100 Luca Boccassi wrote: > On Fri, 22 Mar 2024 18:13:35 + Luca Boccassi > wrote: > > On Mon, 4 Mar 2024 at 23:58, Luca Boccassi wrote: > > > > > > On Mon, 4 Mar 2024 at 23:28, Steve McIntyre > wrote: > > > > > > > Modulo those questions, let's talk

Bug#996202: EFI Secure Boot for systemd-boot

2024-04-04 Thread Luca Boccassi
On Fri, 22 Mar 2024 18:13:35 + Luca Boccassi wrote: > On Mon, 4 Mar 2024 at 23:58, Luca Boccassi wrote: > > > > On Mon, 4 Mar 2024 at 23:28, Steve McIntyre wrote: > > > > > Modulo those questions, let's talk infrastructure. Off the top of my > > > head, in no particular order... > > > > > > 

Bug#996202: EFI Secure Boot for systemd-boot

2024-03-22 Thread Luca Boccassi
On Mon, 4 Mar 2024 at 23:58, Luca Boccassi wrote: > > On Mon, 4 Mar 2024 at 23:28, Steve McIntyre wrote: > > > Modulo those questions, let's talk infrastructure. Off the top of my > > head, in no particular order... > > > > * We'll need to create a new intermediate signing cert for > >

Bug#996202: EFI Secure Boot for systemd-boot

2024-03-09 Thread Luca Boccassi
On Sat, 9 Mar 2024 at 09:59, Pascal Hambourg wrote: > > On 05/03/2024 at 00:58, Luca Boccassi wrote: > > On Mon, 4 Mar 2024 at 23:28, Steve McIntyre wrote: > >> > >> What's your plan for installing as the secondary boot loader for shim > >> to call? > > > > 'bootctl update' already recognises

Bug#996202: EFI Secure Boot for systemd-boot

2024-03-09 Thread Pascal Hambourg
On 05/03/2024 at 00:58, Luca Boccassi wrote: On Mon, 4 Mar 2024 at 23:28, Steve McIntyre wrote: What's your plan for installing as the secondary boot loader for shim to call? 'bootctl update' already recognises and prefers foo.efi.signed if present, so installing to the ESP is easy (PR

Bug#996202: EFI Secure Boot for systemd-boot

2024-03-04 Thread Luca Boccassi
On Mon, 4 Mar 2024 at 23:28, Steve McIntyre wrote: > > Hey folks, > > On Mon, Mar 04, 2024 at 02:13:25AM +, Luca Boccassi wrote: > >On Fri, 19 Nov 2021 09:33:00 +0100 Bastian Blank > >wrote: > >> Hi > >> > >> I'm rescinding this request. I've got a working prototype, but I > >don't > >>

Bug#996202: EFI Secure Boot for systemd-boot

2024-03-04 Thread Steve McIntyre
Hey folks, On Mon, Mar 04, 2024 at 02:13:25AM +, Luca Boccassi wrote: >On Fri, 19 Nov 2021 09:33:00 +0100 Bastian Blank >wrote: >> Hi >> >> I'm rescinding this request.  I've got a working prototype, but I >don't >> know where this would go. >> >> Bastian > >The upstream Shim reviewers

Bug#996202: EFI Secure Boot for systemd-boot

2024-03-03 Thread Luca Boccassi
On Fri, 19 Nov 2021 09:33:00 +0100 Bastian Blank wrote: > Hi > > I'm rescinding this request.  I've got a working prototype, but I don't > know where this would go. > > Bastian The upstream Shim reviewers group now accepts systemd-boot as a 2nd stage bootloader, trusted by Shim builds signed