Re: Bad shim signature on kernel loading with patchset from 25.05.2023 and up

2023-06-26 Thread Ard Biesheuvel
On Mon, 26 Jun 2023 at 16:14, Daniel Kiper wrote: > > On Mon, Jun 26, 2023 at 03:58:15PM +0200, Ard Biesheuvel wrote: > > On Mon, 26 Jun 2023 at 15:56, Daniel Kiper wrote: > > > > > > On Mon, Jun 26, 2023 at 03:14:18PM +0200, Tobias Powalowski via > > > Grub-devel wrote: > > > > Am Mo., 26.

Re: Bad shim signature on kernel loading with patchset from 25.05.2023 and up

2023-06-26 Thread Daniel Kiper
On Mon, Jun 26, 2023 at 03:58:15PM +0200, Ard Biesheuvel wrote: > On Mon, 26 Jun 2023 at 15:56, Daniel Kiper wrote: > > > > On Mon, Jun 26, 2023 at 03:14:18PM +0200, Tobias Powalowski via Grub-devel > > wrote: > > > Am Mo., 26. Juni 2023 um 14:28 Uhr schrieb Daniel Kiper > > > : > > > Hey,

Re: Bad shim signature on kernel loading with patchset from 25.05.2023 and up

2023-06-26 Thread Ard Biesheuvel
On Mon, 26 Jun 2023 at 15:56, Daniel Kiper wrote: > > On Mon, Jun 26, 2023 at 03:14:18PM +0200, Tobias Powalowski via Grub-devel > wrote: > > Am Mo., 26. Juni 2023 um 14:28 Uhr schrieb Daniel Kiper > > : > > Hey, > > > > Thomas, good point. I completely missed that. > > > >

Re: Bad shim signature on kernel loading with patchset from 25.05.2023 and up

2023-06-26 Thread Daniel Kiper
On Mon, Jun 26, 2023 at 03:14:18PM +0200, Tobias Powalowski via Grub-devel wrote: > Am Mo., 26. Juni 2023 um 14:28 Uhr schrieb Daniel Kiper : > Hey, > > Thomas, good point. I completely missed that. > > Tobias, please try Ard patch with the change suggested by Thomas. If > you

Re: Bad shim signature on kernel loading with patchset from 25.05.2023 and up

2023-06-26 Thread Tobias Powalowski via Grub-devel
Am Mo., 26. Juni 2023 um 14:28 Uhr schrieb Daniel Kiper : > Hey, > > Thomas, good point. I completely missed that. > > Tobias, please try Ard patch with the change suggested by Thomas. If you > have not done that yet... > > Daniel > > Hi Daniel, Thomas and Ard, yes both together work :) Sorry

Re: Bad shim signature on kernel loading with patchset from 25.05.2023 and up

2023-06-26 Thread Daniel Kiper
Hey, Thomas, good point. I completely missed that. Tobias, please try Ard patch with the change suggested by Thomas. If you have not done that yet... Daniel On Mon, Jun 26, 2023 at 09:49:19AM +0200, Tobias Powalowski via Grub-devel wrote: > Hi, > removing it removes the error, but boot does

Re: Bad shim signature on kernel loading with patchset from 25.05.2023 and up

2023-06-26 Thread Tobias Powalowski via Grub-devel
Hi, removing it removes the error, but boot does not happen then. It errors now with: cannot load image. greetings tpowa Am Mo., 26. Juni 2023 um 09:06 Uhr schrieb Thomas Frauendorfer < thomas.frauendor...@gmail.com>: > On Thu, Jun 22, 2023 at 3:00 PM Tobias Powalowski via Grub-devel > wrote: >

Re: Bad shim signature on kernel loading with patchset from 25.05.2023 and up

2023-06-26 Thread Thomas Frauendorfer
On Thu, Jun 22, 2023 at 3:00 PM Tobias Powalowski via Grub-devel wrote: > > Hi, > just curious since the patchset from 25.05.2023, I cannot use Secure Boot on > my project anymore. The kernel hash cannot be validated anymore and shim > bails out with bad shim signature. > Any help would be

Re: Bad shim signature on kernel loading with patchset from 25.05.2023 and up

2023-06-23 Thread Tobias Powalowski via Grub-devel
Hi, no that patch does not solve the issue for me, still getting shim bad signature error. greetings tpowa -- Tobias Powalowski Arch Linux Developer & Package Maintainer (tpowa) https://www.archlinux.org tp...@archlinux.org Archboot Developer https://archboot.com St.

Re: Bad shim signature on kernel loading with patchset from 25.05.2023 and up

2023-06-23 Thread Ard Biesheuvel
On Fri, 23 Jun 2023 at 16:18, Tobias Powalowski wrote: > > Am Fr., 23. Juni 2023 um 16:02 Uhr schrieb Daniel Kiper : >> >> On Thu, Jun 22, 2023 at 11:40:47AM +0200, Tobias Powalowski via Grub-devel >> wrote: >> > Hi tackled it down to this commit: >> >

Re: Bad shim signature on kernel loading with patchset from 25.05.2023 and up

2023-06-23 Thread Dimitri John Ledkov
On Fri, 23 Jun 2023 at 15:12, Ard Biesheuvel wrote: > > On Fri, 23 Jun 2023 at 15:46, Tobias Powalowski > wrote: > > > > > > > > Am Fr., 23. Juni 2023 um 15:41 Uhr schrieb Ard Biesheuvel : > >> > >> On Thu, 22 Jun 2023 at 11:41, Tobias Powalowski > >> wrote: > >> > > >> > Hi tackled it down to

Re: Bad shim signature on kernel loading with patchset from 25.05.2023 and up

2023-06-23 Thread Tobias Powalowski via Grub-devel
Am Fr., 23. Juni 2023 um 16:02 Uhr schrieb Daniel Kiper : > On Thu, Jun 22, 2023 at 11:40:47AM +0200, Tobias Powalowski via Grub-devel > wrote: > > Hi tackled it down to this commit: > > https://git.savannah.gnu.org/cgit/grub.git/commit/ > > ?id=6a080b9cde0be5d08b71daf17a806067e32fc13f > > I hope

Re: Bad shim signature on kernel loading with patchset from 25.05.2023 and up

2023-06-23 Thread Ard Biesheuvel
On Fri, 23 Jun 2023 at 15:46, Tobias Powalowski wrote: > > > > Am Fr., 23. Juni 2023 um 15:41 Uhr schrieb Ard Biesheuvel : >> >> On Thu, 22 Jun 2023 at 11:41, Tobias Powalowski >> wrote: >> > >> > Hi tackled it down to this commit: >> >

Re: Bad shim signature on kernel loading with patchset from 25.05.2023 and up

2023-06-23 Thread Daniel Kiper
On Thu, Jun 22, 2023 at 11:40:47AM +0200, Tobias Powalowski via Grub-devel wrote: > Hi tackled it down to this commit: > https://git.savannah.gnu.org/cgit/grub.git/commit/ > ?id=6a080b9cde0be5d08b71daf17a806067e32fc13f I hope you run the GRUB with this [1] patch. If not please use the latest

Re: Bad shim signature on kernel loading with patchset from 25.05.2023 and up

2023-06-23 Thread Dimitri John Ledkov
Hi, On Fri, 23 Jun 2023 at 14:46, Tobias Powalowski via Grub-devel wrote: > > > > Am Fr., 23. Juni 2023 um 15:41 Uhr schrieb Ard Biesheuvel : >> >> On Thu, 22 Jun 2023 at 11:41, Tobias Powalowski >> wrote: >> > >> > Hi tackled it down to this commit: >> >

Re: Bad shim signature on kernel loading with patchset from 25.05.2023 and up

2023-06-23 Thread Tobias Powalowski via Grub-devel
Am Fr., 23. Juni 2023 um 15:41 Uhr schrieb Ard Biesheuvel : > On Thu, 22 Jun 2023 at 11:41, Tobias Powalowski > wrote: > > > > Hi tackled it down to this commit: > > > https://git.savannah.gnu.org/cgit/grub.git/commit/?id=6a080b9cde0be5d08b71daf17a806067e32fc13f > > starting with this commit

Re: Bad shim signature on kernel loading with patchset from 25.05.2023 and up

2023-06-23 Thread Ard Biesheuvel
On Thu, 22 Jun 2023 at 11:41, Tobias Powalowski wrote: > > Hi tackled it down to this commit: > https://git.savannah.gnu.org/cgit/grub.git/commit/?id=6a080b9cde0be5d08b71daf17a806067e32fc13f > starting with this commit shim verification fails for kernel hash with bad > shim verification and

Re: Bad shim signature on kernel loading with patchset from 25.05.2023 and up

2023-06-22 Thread Tobias Powalowski via Grub-devel
Hi tackled it down to this commit: https://git.savannah.gnu.org/cgit/grub.git/commit/?id=6a080b9cde0be5d08b71daf17a806067e32fc13f starting with this commit shim verification fails for kernel hash with bad shim verification and makes Secure Boot impossible. Hope you find a quick solution for fixing

Re: Bad shim signature on kernel loading with patchset from 25.05.2023 and up

2023-06-22 Thread Tobias Powalowski via Grub-devel
Hi, further debugged it, it appears to be the patchset from Ard to cause this bad shim verification breakage. greetings tpowa -- Tobias Powalowski Arch Linux Developer & Package Maintainer (tpowa) https://www.archlinux.org tp...@archlinux.org Archboot Developer

Bad shim signature on kernel loading with patchset from 25.05.2023 and up

2023-06-22 Thread Tobias Powalowski via Grub-devel
Hi, just curious since the patchset from 25.05.2023, I cannot use Secure Boot on my project anymore. The kernel hash cannot be validated anymore and shim bails out with bad shim signature. Any help would be appreciated. greetings tpowa -- Tobias Powalowski Arch Linux Developer & Package

Bad shim signature on kernel loading with patchset from 25.05.2023 and up

2023-06-22 Thread Tobias Powalowski via Grub-devel
Hi , I tackled it down to this commit: https://git.savannah.gnu.org/cgit/grub.git/commit/?id=6a080b9cde0be5d08b71daf17a806067e32fc13f starting with this commit shim verification fails for kernel hash with bad shim verification and makes Secure Boot impossible. Hope you find a quick solution for