Re: Runtime updates to EFI secure variables

2012-07-13 Thread James Bottomley
On Fri, 2012-07-13 at 19:02 +0100, Matthew Garrett wrote: > On Fri, Jul 13, 2012 at 06:12:26PM +0100, James Bottomley wrote: > > > This means (provided we have access to the relevant keys) we can move > > the platform into and out of Setup Mode as well as add signing and other > > keys. > > I'm p

Re: Runtime updates to EFI secure variables

2012-07-13 Thread Matthew Garrett
On Fri, Jul 13, 2012 at 06:12:26PM +0100, James Bottomley wrote: > This means (provided we have access to the relevant keys) we can move > the platform into and out of Setup Mode as well as add signing and other > keys. I'm pretty sure that the expected behaviour is to use EFI_VARIABLE_APPEND_WR