At the moment the best options are:
- rotate online signing key
- build new shim with old signing key in vendorx (revoked ESL)
- build new kernels with old signing key built-in revoked keyring
This is to ensure that old shim & old kernel can boot or kexec new kernels.
To ensure new shim cannot boot old kernels.
To ensure that new kernels cannot kexec old kernels.
This is revocation strategy used by Canonical Kernel Team for Ubuntu
Kernels.
There is no sbat for kernels yet (and/or nobody has yet started to use sbat
for kernels).
On Wed, 13 Dec 2023, 22:04 Bastian Blank, <
[email protected]> wrote:
Hi
I don't think we currently have a documented way to revoke old kernels
for secure boot. Are there known plans by other distributions? Or
should we just force the inclusion of SBAT and use it as intended?
Regards,
Bastian
--
... The prejudices people feel about each other disappear when they get
to know each other.
-- Kirk, "Elaan of Troyius", stardate 4372.5
<div dir="auto">At the moment the best options are:<div dir="auto"><br></div><div dir="auto">- rotate online signing key</div><div dir="auto">- build new shim with old signing key in vendorx (revoked ESL)</div><div dir="auto">- build new kernels with old
signing key built-in revoked keyring</div><div dir="auto"><br></div><div dir="auto">This is to ensure that old shim & old kernel can boot or kexec new kernels.</div><div dir="auto">To ensure new shim cannot boot old kernels.</div><div dir="auto">To
ensure that new kernels cannot kexec old kernels.</div><div dir="auto"><br></div><div dir="auto">This is revocation strategy used by Canonical Kernel Team for Ubuntu Kernels.</div><div dir="auto"><br></div><div dir="auto">There is no sbat for kernels yet
(and/or nobody has yet started to use sbat for kernels).</div></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Wed, 13 Dec 2023, 22:04 Bastian Blank, <<a href="mailto:
[email protected]">
[email protected]</a>> wrote:<br></div><
blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">Hi<br>
I don't think we currently have a documented way to revoke old kernels<br> for secure boot. Are there known plans by other distributions? Or<br> should we just force the inclusion of SBAT and use it as intended?<br>
Regards,<br>
Bastian<br>
-- <br>
... The prejudices people feel about each other disappear when they get<br>
to know each other.<br>
-- Kirk, "Elaan of Troyius", stardate 4372.5<br>
</blockquote></div>
--- SoupGate-Win32 v1.05
* Origin: fsxNet Usenet Gateway (21:1/5)