https://bugzilla.novell.com/show_bug.cgi?id=842144 https://bugzilla.novell.com/show_bug.cgi?id=842144#c6 --- Comment #6 from Andrey Borzenkov <arvidjaar@gmail.com> 2013-09-26 10:41:11 UTC --- (In reply to comment #5)
That trick was with the grub2-efi from 12.3.
You filed bug against 13.1 Unless you can reproduce it with grub from that version, the bug should be closed as invalid.
In "insmod" really disabled -- perhaps that's part of the problem. In my opinion, it should be checking the validity of insmod loads (either a signature verification or file hash check from a compiled-in list of hashes).
Current grub2 supports (mandatory) signature verification. Minor details are key management and what to do with volatile files (grub.cfg, grubenv and similar) :) But this better is discussed in feature request.
I am not sure to what extent UUID searches depend on "insmod",
Signed grub binary includes support for UUID search. -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.