On Sat, Jul 21, 2012 at 05:35:48PM +1000, Basil Chupin wrote:
On 17/07/12 17:38, Andreas Jaeger wrote:
On 07/17/2012 08:08 AM, Basil Chupin wrote:
On 25/06/12 14:43, Chris Jones wrote:
So what was the decision/end result with the UEFI situation? Where does OpenSUSE stand with the situation?
Regards
Chris asked this question on 25 June, and the last post on this subject was from Jim Henderson on 26 June.
Seems you're missing quite a few emails. The latest were from the 3rd of July. Michael Chang and others are looking for a solution here,
Andreas
I just came across this. Of any use?-
http://www.zdnet.com/linux-developers-working-on-windows-uefi-secure-boot-pr...
Thanks, we had been use it (OVMF) built from James's project in verfying the bootloader signing results. :) The current progress is we successfully walking through the process below. 1. create/generate PK/KEK key pairs 2. create/generate our own key pairs, say SUSE_KEY 3. enroll PKpub, KEKpub in setup mode, enable secure boot 4. build the stub loader (shim) with embedded SUSE_KEYpub public key certifcate. 5. sign shim with KEKpriv 6. sign bootloader (elilo and grub2) with SUSE_KEYpriv 7. verify signed shim could run in secure boot enabled 8. verify signed bootloaer could run in secure boot enabled 9. verffy any unsigned images cannot run in secure boot enabled 10. verify any unsigned images could run in secure boot disabled PS. Both sign tools, pesign and sbsign, are used in above process and verified to work. If you interested in more detail, below is the wiki page created for the procedure. http://en.opensuse.org/openSUSE:UEFI_Image_File_Sign_Tools http://en.opensuse.org/openSUSE:UEFI_Secure_boot_using_qemu-kvm I've tried to collect the relevant packages in my obs project https://build.opensuse.org/project/show?project=home%3Amichael-chang%3AUEFI And if you want to try building the OVMF from scratch, this wiki page may be useful. http://en.opensuse.org/SDB:UEFI_EDK2_Build_Howto_On_openSUSE12_1 Sorry the information is not consolidated well, we are still working on it. Thanks to people who involves in this topic (esp for James, Gary and Joey). Thanks, Michael
BC
-- Using openSUSE 12.2 x86_64 KDE 4.8.4 & kernel 3.4.4.2 on a system with- AMD FX 8-core 3.6/4.2GHz processor 16GB PC14900/1866MHz Quad Channel Corsair "Vengeance" RAM Gigabyte AMD3+ m/board; Gigabyte nVidia GTX550Ti 1GB DDR5 GPU
-- To unsubscribe, e-mail: opensuse-project+unsubscribe@opensuse.org To contact the owner, email: opensuse-project+owner@opensuse.org
-- To unsubscribe, e-mail: opensuse-project+unsubscribe@opensuse.org To contact the owner, email: opensuse-project+owner@opensuse.org