[Bug 1890835] Re: secureboot-db 2020 update

2021-07-05 Thread Dimitri John Ledkov
A newer dbx update has been published, thus this version should not go out to updates & security. The new update requires SBAT capable shim, which is in progress being rolled out at the moment. ** Tags removed: verification-needed-bionic verification-needed-focal verification-needed-xenial **

[Bug 1890835] Re: secureboot-db 2020 update

2021-01-24 Thread Mathew Hodson
** Changed in: secureboot-db (Ubuntu) Importance: Undecided => Medium ** Changed in: secureboot-db (Ubuntu Trusty) Importance: Undecided => Medium ** Changed in: secureboot-db (Ubuntu Xenial) Importance: Undecided => Medium ** Changed in: secureboot-db (Ubuntu Bionic) Importance:

[Bug 1890835] Re: secureboot-db 2020 update

2021-01-21 Thread Mathew Hodson
Removed the verification-failed tags so that this bug doesn't show up in the -proposed cleanup report of packages to remove from -proposed. ** Tags removed: block-proposed-groovy verification-failed-bionic verification-failed-focal verification-failed-xenial verification-needed ** Tags added:

[Bug 1890835] Re: secureboot-db 2020 update

2020-10-29 Thread Rex Tsai
Based on comment #15, I assume the same deb will be released again to focal-updates, Ubuntu only roll it back to focal-proposed to provide Feodra community has more time to address the problem. If it's an Ubuntu only machines, users are free and allowed to use the same deb right now. -- You

[Bug 1890835] Re: secureboot-db 2020 update

2020-10-22 Thread Dimitri John Ledkov
** Tags added: block-proposed-focal block-proposed-groovy -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1890835 Title: secureboot-db 2020 update To manage notifications about this bug go to:

[Bug 1890835] Re: secureboot-db 2020 update

2020-10-20 Thread Steve Langasek
The focal SRU has been rolled back for the time being from focal-updates to focal-proposed, due to compatibility concerns with current Fedora. They will be re-released at a later date. For the time being I am marking verification-failed to block promotion, but this does not mean they should be

[Bug 1890835] Re: secureboot-db 2020 update

2020-09-24 Thread Jamie Strandboge
"Yes, ESM will be poked after other series release this." Dimitri - do we plan to respin trusty media with the upgraded grub? -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1890835 Title:

[Bug 1890835] Re: secureboot-db 2020 update

2020-09-22 Thread Launchpad Bug Tracker
This bug was fixed in the package secureboot-db - 1.6~20.04.1 --- secureboot-db (1.6~20.04.1) focal; urgency=medium * Ship MS 2020 split arch dbx updates. LP: #1890835 * Add arm64 architecture. * Add breaks on grub-efi-$arch-signed less than security pocket. -- Dimitri John

[Bug 1890835] Re: secureboot-db 2020 update

2020-09-22 Thread Łukasz Zemczak
Publishing secureboot-db for focal-updates and focal-security. As discussed, this is fine to go to -security too as it the package is basically a 'pure data' package. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 1890835] Re: secureboot-db 2020 update

2020-09-18 Thread Dimitri John Ledkov
Slow phasing is merged and deployed now. ** Tags removed: verification-needed-focal ** Tags added: verification-done-focal -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1890835 Title:

[Bug 1890835] Re: secureboot-db 2020 update

2020-09-18 Thread Dimitri John Ledkov
Booted 20.04.1 ISO, in a 4k ovmf qemu KVM VM with secureboot MS keys and installed secureboot-db from focal-proposed, checking in journalctl that dbxupdate from 1.6~20.04.1 got applied. Shut down the VM. Attempted to boot 20.04 BETA iso, and it failed to boot with Verification failed Security

[Bug 1890835] Re: secureboot-db 2020 update

2020-09-18 Thread Dimitri John Ledkov
Yes, ESM will be poked after other series release this. ** Tags removed: block-proposed-focal -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1890835 Title: secureboot-db 2020 update To manage

[Bug 1890835] Re: secureboot-db 2020 update

2020-09-04 Thread Łukasz Zemczak
Someone will have to poke the ESM team to take care of trusty. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1890835 Title: secureboot-db 2020 update To manage notifications about this bug go to:

[Bug 1890835] Re: secureboot-db 2020 update

2020-09-03 Thread Łukasz Zemczak
Hello Dimitri, or anyone else affected, Accepted secureboot-db into bionic-proposed. The package will build now and be available at https://launchpad.net/ubuntu/+source/secureboot- db/1.4.1 in a few hours, and then in the -proposed repository. Please help us by testing this new package. See

[Bug 1890835] Re: secureboot-db 2020 update

2020-09-03 Thread Łukasz Zemczak
Hello Dimitri, or anyone else affected, Accepted secureboot-db into focal-proposed. The package will build now and be available at https://launchpad.net/ubuntu/+source/secureboot- db/1.6~20.04.1 in a few hours, and then in the -proposed repository. Please help us by testing this new package.

[Bug 1890835] Re: secureboot-db 2020 update

2020-09-02 Thread Francis Ginther
** Tags added: id-57571331a85e0e034520474d -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1890835 Title: secureboot-db 2020 update To manage notifications about this bug go to:

[Bug 1890835] Re: secureboot-db 2020 update

2020-08-26 Thread Dimitri John Ledkov
Reuploaded with breaks on versions of signed grubs less than those in the security pocket. This however may introduce an inverse problem of attempting to either remove signed grub, or remove secureboot-db, to resolve the conflict if for some reason users prohibit upgrading the signed grub

[Bug 1890835] Re: secureboot-db 2020 update

2020-08-21 Thread Łukasz Zemczak
Apologies if this is completely not a thing, but I'm a bit worried about cases where people install the secureboot-db update but still have the old grub2 installed (as there is no breaks). Will that cause a problem? Since if I understand it (but I might be wrong), wouldn't they be unable to boot

[Bug 1890835] Re: secureboot-db 2020 update

2020-08-20 Thread Dimitri John Ledkov
** Description changed: + NB! do not release this update to -updates, until slow phasing is + available, at 4% per day. + + NB! ideally phase one series at the time, to ensure we can deal with a + flood of support requests if any arise. + [Impact]  * Ship 2020 dbxupdate from MS

[Bug 1890835] Re: secureboot-db 2020 update

2020-08-20 Thread Dimitri John Ledkov
** Description changed: - secureboot-db 2020 update + [Impact] - Expecting long period in -proposed. + * Ship 2020 dbxupdate from MS - Test to ensure certified laptops are not bricked before publishing to - updates. + [Test Case] - Expecting slow phasing in -updates, at 4% a day, 25

[Bug 1890835] Re: secureboot-db 2020 update

2020-08-20 Thread Launchpad Bug Tracker
This bug was fixed in the package secureboot-db - 1.6 --- secureboot-db (1.6) groovy; urgency=medium * Ship MS 2020 split arch dbx updates. LP: #1890835 * Add arm64 architecture. -- Dimitri John Ledkov Fri, 24 Jul 2020 00:34:57 +0100 ** Changed in: secureboot-db (Ubuntu

[Bug 1890835] Re: secureboot-db 2020 update

2020-08-20 Thread Dimitri John Ledkov
** Description changed: secureboot-db 2020 update Expecting long period in -proposed. - Expecting slow phasing in -updates. + Test to ensure certified laptops are not bricked before publishing to + updates. - One series at the time. + Expecting slow phasing in -updates, at 4% a day,

[Bug 1890835] Re: secureboot-db 2020 update

2020-08-20 Thread Dimitri John Ledkov
** Description changed: secureboot-db 2020 update + + Expecting long period in -proposed. + + Expecting slow phasing in -updates. + + One series at the time. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 1890835] Re: secureboot-db 2020 update

2020-08-16 Thread Dimitri John Ledkov
** Also affects: secureboot-db (Ubuntu Trusty) Importance: Undecided Status: New ** Also affects: secureboot-db (Ubuntu Groovy) Importance: Undecided Status: New ** Also affects: secureboot-db (Ubuntu Bionic) Importance: Undecided Status: New ** Also affects: