[opensuse-factory] Secure Boot again

All, I'd like to suggest that the openSUSE 12.3 boot/install media have the new Linux Foundation pre-boot Secure Boot utility as the first stage of booting. That is in addition to the already discussed plans for handling UEFI secure boot after the initial install. == details There is a new Linux Foundation pre-boot Secure Boot utility available. http://www.linuxfoundation.org/news-media/blogs/browse/2012/10/linux-foundat... Interesting and I'm glad to see it, but it doesn't fundamentally change things for UEFI Secure Boot systems running openSUSE 12.3 and newer. But it does for non-compliant systems that don't have a way to disable Secure Boot during OS installs. As it strongly implies, a pre-boot loader is being created by the Linux Foundation and they are going through the process of getting it signed by an official Microsoft Key. That means all UEFI Secure Boot systems will see this new pre-boot loader as being properly signed. (The new pre-boot loader is going to require a human is at the keyboard before it advances to the boot sequence, so it is not a panacea, especially for servers.) Thus the mechanism to boot non-Microsoft signed media like the openSUSE install media becomes: - Disable Secure Boot in the bios, either one time or permanently OR - Boot via the new Linux Foundation pre-boot loader, confirm you are physically present, then continue boot process to non-signed CD/OS/etc. It seems the openSUSE 12.3 install/boot media should have the new pre-boot loader as the first stage of booting. That would also mean that people using those media won't have to disable secure boot in the bios during installs. It will make the install process much more seemless if the user doesn't have to go into the bios prior to doing the install. Greg -- To unsubscribe, e-mail: opensuse-factory+unsubscribe@opensuse.org To contact the owner, e-mail: opensuse-factory+owner@opensuse.org

On Thursday 01 November 2012 13.49:10 Greg Freemyer wrote:
- Boot via the new Linux Foundation pre-boot loader, confirm you are physically present, then continue boot process to non-signed CD/OS/etc.
How will be the case of pxe booting machine will be handle. Still supported ? -- Bruno Friedmann openSUSE Member & Ambassador GPG KEY : D5C9B751C4653227 irc: tigerfoot -- To unsubscribe, e-mail: opensuse-factory+unsubscribe@opensuse.org To contact the owner, e-mail: opensuse-factory+owner@opensuse.org

On Sun, Nov 04, 2012 at 05:40:12PM +0100, Bruno Friedmann wrote:
On Thursday 01 November 2012 13.49:10 Greg Freemyer wrote:
- Boot via the new Linux Foundation pre-boot loader, confirm you are physically present, then continue boot process to non-signed CD/OS/etc.
How will be the case of pxe booting machine will be handle. Still supported ?
If your BIOS supports this, through UEFI, yes, it will. PXE boot is a BIOS issue, not an OS issue. greg k-h -- To unsubscribe, e-mail: opensuse-factory+unsubscribe@opensuse.org To contact the owner, e-mail: opensuse-factory+owner@opensuse.org

Le jeudi 01 novembre 2012 à 13:49 -0400, Greg Freemyer a écrit :
All,
I'd like to suggest that the openSUSE 12.3 boot/install media have the new Linux Foundation pre-boot Secure Boot utility as the first stage of booting.
That is in addition to the already discussed plans for handling UEFI secure boot after the initial install.
There is no plan to support the Linux Foundation pre-boot stuff, simply because it is not relevant with the plans for Secure Boot on openSUSE (which I explained during Secure Boot BoF during osC). I'll try to find some time this week to blog with my slides about it. -- Frederic Crozat <fcrozat@suse.com> SUSE -- To unsubscribe, e-mail: opensuse-factory+unsubscribe@opensuse.org To contact the owner, e-mail: opensuse-factory+owner@opensuse.org
participants (4)
-
Bruno Friedmann
-
Frederic Crozat
-
Greg Freemyer
-
Greg KH