Re: [edk2] [PATCH 1/2] OvmfPkg: inherit Image Verification Policy defaults from SecurityPkg

2016-01-06 Thread Fu, Siyuan
Hi, Laszlo Thanks for the detail explanation of the whole story, the change is good to me. Reviewed-by: Fu Siyuan -Original Message- From: Laszlo Ersek [mailto:ler...@redhat.com] Sent: Thursday, January 7, 2016 5:19 AM To: edk2-de...@ml01.01.org Cc: Justen, Jordan

[edk2] [PATCH 1/2] OvmfPkg: inherit Image Verification Policy defaults from SecurityPkg

2016-01-06 Thread Laszlo Ersek
Secure Boot support was originally addded to OvmfPkg on 2012-Mar-09, in SVN r13093 (git 8cee3de7e9f4), titled OvmfPkg: Enable secure-boot support when SECURE_BOOT_ENABLE==TRUE At that time the image verification policies in SecurityPkg/SecurityPkg.dec were: - option ROM image: 0x00