From: Jan Kiszka <jan.kiszka@siemens.com>
To: cip-dev@lists.cip-project.org
Cc: Sai Sree Kartheek Adivi <s-adivi@ti.com>,
Quirin Gylstorff <quirin.gylstorff@siemens.com>,
Alexander Heinisch <alexander.heinisch@siemens.com>
Subject: [isar-cip-core][PATCH v2 8/7] doc: Update README.secureboot regarding recent deployment enhancements
Date: Thu, 27 Aug 2026 09:44:21 +0200 [thread overview]
Message-ID: <369c5862-54c1-429c-83fc-100b287f209e@siemens.com> (raw)
In-Reply-To: <cover.1787757655.git.jan.kiszka@siemens.com>
[reposted against the correct series version, sorry]
From: Jan Kiszka <jan.kiszka@siemens.com>
Explain the automatic certificates deployment and its dependencies.
There is no longer the need to explain manual key creation, we can
simply reference the new single-key-to-efi-certs package. Keep the
manual deployment method for special causes.
Signed-off-by: Jan Kiszka <jan.kiszka@siemens.com>
---
doc/README.secureboot.md | 39 +++++++++++++++++++++++++++++----------
1 file changed, 29 insertions(+), 10 deletions(-)
diff --git a/doc/README.secureboot.md b/doc/README.secureboot.md
index 3bcb3f58..2a387f07 100644
--- a/doc/README.secureboot.md
+++ b/doc/README.secureboot.md
@@ -273,32 +273,51 @@ lrwxrwxrwx 1 root root 0 Jun 30 13:20 sda5 -> ../../../../pci0000:00/0000:00:1f.
Secureboot for a generic UEFI x86 target works similar to the QEMU target,
except the enrollment of the secure boot keys.
-### Generate keys from Debian snakeoil keys
+### Generate keys from a single signing key
-For testing purposes, the snakeoil keys from OVMF package can be used to
-convert the certificate into a efi authority file use the following commands:
+The recipe `single-key-to-efi-certs` can be used to generate a Debian package
+that contains the required EFI certificates for enabling secure boot. It uses
+a single key/cert pair as basis. Unless otherwise configured, this pair will
+be taken from the corresponding Debian snakeoil set which is fine only for
+testing purposes. The package will contain the `.auth` files required for
+manual deployment:
-```bash
-cert-to-efi-sig-list recipes-devtools/secure-boot-secrets/files/bookworm/PkKek-1-snakeoil.pem PK.esl
-sign-efi-sig-list -k recipes-devtools/secure-boot-secrets/files/bookworm/PkKek-1-snakeoil.key -c recipes-devtools/secure-boot-secrets/files/bookworm/PkKek-1-snakeoil.pem PK PK.esl PK.auth
+```
+$ dpkg -c build/tmp/deploy/isar-apt/cip-core-trixie/apt/cip-core-trixie/pool/main/s/single-key-to-efi-certs/single-key-to-efi-certs_0.1_arm64.deb
+[...]
+-rw-r--r-- root/root 2549 1970-01-01 02:00 ./usr/share/secure-boot-efi-certs/KEK.auth
+-rw-r--r-- root/root 2549 1970-01-01 02:00 ./usr/share/secure-boot-efi-certs/PK.auth
+-rw-r--r-- root/root 2549 1970-01-01 02:00 ./usr/share/secure-boot-efi-certs/db.auth
```
-The package `efitools` needs to be installed for this.
+### Automatic secure boot certificate enrollment
-In this case, the PK.esl can be used as DB and KEK keys. The PK.auth file is for PK key.
+By default, isar-cip-core images contain an early boot service
+(initramfs-sbcerts-hook) which will deploy the required EFI certificates during
+first boot and restart the machine into secure boot afterwards. This will only
+happen when the machine is in Setup Mode and no other certificates have been
+deployed to the Allowed Signature Database yet. This also ensures that disk
+encryption on first boot will only take place when the machine was securely
+booted so that the encryption key is sealed against this state in the TPM.
-### Secure boot key enrollment
+The certificates needed for this auto-enrollment are taken from a package that
+provides `secure-boot-efi-certs`. The `single-key-to-efi-certs` package is the
+default provider of this in isar-cip-core.
+
+### Manual secure boot certificate enrollment
> :exclamation:**IMPORTANT** This document is not for generating a Machine Owner Key(MOK).
> :exclamation:**IMPORTANT** Enrollment of secure boot keys must occur
> in a secure environment.
-The following keys need to be enrolled onto the device:
+The certificates for the following keys need to be enrolled onto the device:
- The Platform Key (PK)
- The Key Exchange Key (KEK)
- Allowed Signatures Database
+You can obtain them from the single-key-to-efi-certs package described before.
+
The enrollment can typically be achieved with the help of
[efi-updatevar](https://manpages.debian.org/bookworm/efitools/efi-updatevar.1.en.html)
on the device.
--
2.47.3
prev parent reply other threads:[~2026-08-27 7:44 UTC|newest]
Thread overview: 14+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-26 15:20 [isar-cip-core][PATCH v2 0/7] Provide measured boot via fTPM for arm64, early deploy EFI certificates Jan Kiszka
2026-08-26 15:20 ` [isar-cip-core][PATCH v2 1/7] secure-boot-efi-keys: Add recipe to create " Jan Kiszka
2026-09-14 6:59 ` [cip-dev] " MOESSBAUER, Felix
2026-09-14 7:16 ` Jan Kiszka
2026-08-26 15:20 ` [isar-cip-core][PATCH v2 2/7] cip-initramfs-functions: Add secure_boot_enabled helper Jan Kiszka
2026-08-26 15:20 ` [isar-cip-core][PATCH v2 3/7] cip-core-initramfs: Automatically deploy EFI secure boot certificates on first boot Jan Kiszka
2026-09-23 9:36 ` Heinisch, Alexander (FT RPD CED SES-AT)
2026-08-26 15:20 ` [isar-cip-core][PATCH v2 4/7] u-boot: Add patches to enable measured boot with fTPM Jan Kiszka
2026-09-08 16:41 ` [isar-cip-core][PATCH v3 " Jan Kiszka
2026-09-14 6:25 ` [isar-cip-core][PATCH v4 " Jan Kiszka
2026-08-26 15:20 ` [isar-cip-core][PATCH v2 5/7] u-boot: Refactor ftpm-stmm.cfg to enable measured boot for all Jan Kiszka
2026-08-26 15:20 ` [isar-cip-core][PATCH v2 6/7] u-boot: Drop obsolete config workaround Jan Kiszka
2026-08-26 15:20 ` [isar-cip-core][PATCH v2 7/7] initramfs-crypt-hook: Prevent encryption without secure boot Jan Kiszka
2026-08-27 7:44 ` Jan Kiszka [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=369c5862-54c1-429c-83fc-100b287f209e@siemens.com \
--to=jan.kiszka@siemens.com \
--cc=alexander.heinisch@siemens.com \
--cc=cip-dev@lists.cip-project.org \
--cc=quirin.gylstorff@siemens.com \
--cc=s-adivi@ti.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.