Re: Fedora 31 Self-Contained Change proposal: Include several modules in the EFI build of Grub2 for security use-cases

2019-06-26 Thread Benjamin Doron
Hi all, I've written some scripts to help with the signature verification aspect of this change. I've attempted to have them seamlessly handle different environments, but please let me know if you observe any misbehaviour. I'd particularly like to get input on the second script. The first can

Fedora 31 Self-Contained Change proposal: Include several modules in the EFI build of Grub2 for security use-cases

2019-06-10 Thread Ben Cotton
https://fedoraproject.org/wiki/Changes/Include_security_modules_in_efi_Grub2 == Summary == Include Grub's "verify," "cryptodisk" and "luks" modules in grubx64.efi of the 'grub2-efi-x64' package. Note: Although the build process will automatically include explicit dependencies ("mpi,"

Fedora 31 Self-Contained Change proposal: Include several modules in the EFI build of Grub2 for security use-cases

2019-06-10 Thread Ben Cotton
https://fedoraproject.org/wiki/Changes/Include_security_modules_in_efi_Grub2 == Summary == Include Grub's "verify," "cryptodisk" and "luks" modules in grubx64.efi of the 'grub2-efi-x64' package. Note: Although the build process will automatically include explicit dependencies ("mpi,"