All of lore.kernel.org
 help / color / mirror / Atom feed
* Xen.efi and secure boot
@ 2012-11-26 17:57 George Dunlap
  2012-11-26 18:16 ` Andrew Cooper
                   ` (3 more replies)
  0 siblings, 4 replies; 22+ messages in thread
From: George Dunlap @ 2012-11-26 17:57 UTC (permalink / raw)
  To: xen-devel@lists.xen.org, Jan Beulich, Keir Fraser, Ian Campbell


[-- Attachment #1.1: Type: text/plain, Size: 659 bytes --]

So while doing a bit of investigation into a request that we have
instructions for how to sign a Xen binary, I came across a related pair of
questions.  If we boot from a signed Xen binary, then:
1. Will Xen then successfully boot a signed dom0 kernel / initrd?
2. Will Xen fail to boot an unsigned dom0 kernel / initrd?

I think if Xen is signed, then ideally we want both 1 and 2 to be true,
right?  Does UEFI provide a way to check the signature of files?  Does it
happen automatically, or would we need to add extra support?  Or would we
need to embed a public key within the Xen binary and have Xen check the
signatures of files that it reads?

 -George

[-- Attachment #1.2: Type: text/html, Size: 686 bytes --]

[-- Attachment #2: Type: text/plain, Size: 126 bytes --]

_______________________________________________
Xen-devel mailing list
Xen-devel@lists.xen.org
http://lists.xen.org/xen-devel

^ permalink raw reply	[flat|nested] 22+ messages in thread

end of thread, other threads:[~2012-11-30 12:15 UTC | newest]

Thread overview: 22+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2012-11-26 17:57 Xen.efi and secure boot George Dunlap
2012-11-26 18:16 ` Andrew Cooper
2012-11-27 10:51   ` George Dunlap
2012-11-27 11:20     ` Alan Cox
2012-11-27 13:43     ` Pasi Kärkkäinen
2012-11-27 10:56   ` Ian Campbell
2012-11-27 11:23     ` Alan Cox
2012-11-26 20:12 ` Stefano Stabellini
2012-11-26 21:51   ` Alan Cox
2012-11-27  9:50     ` George Dunlap
2012-11-27 11:00       ` Jan Beulich
2012-11-27  8:05 ` Jan Beulich
2012-11-28 15:33 ` Jan Beulich
2012-11-30 10:27   ` Jan Beulich
2012-11-30 10:42     ` George Dunlap
2012-11-30 10:58       ` Mats Petersson
2012-11-30 11:05       ` Jan Beulich
2012-11-30 10:56     ` George Dunlap
2012-11-30 11:23       ` Jan Beulich
2012-11-30 11:26         ` Jan Beulich
2012-11-30 11:34         ` George Dunlap
2012-11-30 12:15           ` Jan Beulich

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.