From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from lists.gnu.org (lists.gnu.org [209.51.188.17]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.lore.kernel.org (Postfix) with ESMTPS id 25AE6C5B552 for ; Tue, 10 Jun 2025 16:36:40 +0000 (UTC) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1uP1xK-0008Oy-73; Tue, 10 Jun 2025 12:36:10 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1uP1uY-0007sW-U8 for grub-devel@gnu.org; Tue, 10 Jun 2025 12:33:19 -0400 Received: from mx0b-001b2d01.pphosted.com ([148.163.158.5]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1uP1uW-00053f-LO for grub-devel@gnu.org; Tue, 10 Jun 2025 12:33:18 -0400 Received: from pps.filterd (m0353725.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.2/8.18.1.2) with ESMTP id 55A9dvCT003285; Tue, 10 Jun 2025 16:33:13 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to; s=pp1; bh=1i4ny1 D4hoaKxbZZ79INIMt8PPBZkpvP5T7Y5+n1kZc=; b=O2u3Q2exaBLOU1K7LKh+gn UkiMVGyEYSlMKv0jj0Cc7dQGtMT9gTINv837c26xZ/TuJWwgepji6uULIKmKueVe JOf3/O9HTELMU0VlMN/LicAuTujFVbU+G3ruxgdT/NYTh3QLnIQuUo+bcxhI/lUL uLV1vFPaNieoWX2MF2Yb8CqDW9ebHVPCYJmluzhx0ipnL7J209oqTsFkr/4+EUVb Fj8b85ASLd3waYIoNsiy3HAI0W03N100KUwO0iT5BgPP+IQmyG44XgctuNYRTvy3 Dl2US/Npm5SUU2s/WCfLgL23u+Rlf9zGUWn11jTcT8u/TywglYhVT8JYErwnVsiQ == Received: from ppma23.wdc07v.mail.ibm.com (5d.69.3da9.ip4.static.sl-reverse.com [169.61.105.93]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 474bunyjy0-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Tue, 10 Jun 2025 16:33:13 +0000 (GMT) Received: from pps.filterd (ppma23.wdc07v.mail.ibm.com [127.0.0.1]) by ppma23.wdc07v.mail.ibm.com (8.18.1.2/8.18.1.2) with ESMTP id 55ADjHVF027957; Tue, 10 Jun 2025 16:33:12 GMT Received: from smtprelay04.dal12v.mail.ibm.com ([172.16.1.6]) by ppma23.wdc07v.mail.ibm.com (PPS) with ESMTPS id 47518mb86r-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Tue, 10 Jun 2025 16:33:12 +0000 Received: from smtpav04.wdc07v.mail.ibm.com (smtpav04.wdc07v.mail.ibm.com [10.39.53.231]) by smtprelay04.dal12v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 55AGXBsY24445664 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Tue, 10 Jun 2025 16:33:12 GMT Received: from smtpav04.wdc07v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 9C0E258056; Tue, 10 Jun 2025 16:33:11 +0000 (GMT) Received: from smtpav04.wdc07v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id B93EC58045; Tue, 10 Jun 2025 16:33:10 +0000 (GMT) Received: from ltc.linux.ibm.com (unknown [9.5.196.140]) by smtpav04.wdc07v.mail.ibm.com (Postfix) with ESMTP; Tue, 10 Jun 2025 16:33:10 +0000 (GMT) MIME-Version: 1.0 Date: Tue, 10 Jun 2025 22:03:10 +0530 From: sudhakar To: Daniel Kiper Cc: grub-devel@gnu.org, dja@axtens.net, jan.setjeeilers@oracle.com, julian.klode@canonical.com, mate.kukri@canonical.com, pjones@redhat.com, msuchanek@suse.com, mlewando@redhat.com, stefanb@linux.ibm.com Subject: Re: [PATCH v2 03/21] docs/grub: Document signing grub with an appended signature In-Reply-To: <20250522181911.wocdh6u5liwrugkb@tomti.i.net-space.pl> References: <20250326193242.703506-1-sudhakar@linux.ibm.com> <20250326193242.703506-4-sudhakar@linux.ibm.com> <20250522181911.wocdh6u5liwrugkb@tomti.i.net-space.pl> Message-ID: <63330777667dcc0259985b7fdf2dc33c@linux.ibm.com> X-Sender: sudhakar@linux.ibm.com X-TM-AS-GCONF: 00 X-Authority-Analysis: v=2.4 cv=H4Hbw/Yi c=1 sm=1 tr=0 ts=68485e49 cx=c_pps a=3Bg1Hr4SwmMryq2xdFQyZA==:117 a=3Bg1Hr4SwmMryq2xdFQyZA==:17 a=kj9zAlcOel0A:10 a=6IFa9wvqVegA:10 a=JuTF4qcAAAAA:8 a=VnNF1IyMAAAA:8 a=rkJ3ZaabW1ldYPoT5QwA:9 a=CjuIK1q_8ugA:10 a=WlT8qwTXB_Kj6um4hl3b:22 X-Proofpoint-Spam-Details-Enc: AW1haW4tMjUwNjEwMDEzMSBTYWx0ZWRfXweuVoygG1sL+ tNRSUjdpXZZmaC3HJpDWOnKIvBRDCLnYrHo7B/xMnjAMjpiBb73XoFsv7jsnxLu7QJY0Ng8zgci svhFFu6IxtB1YkGFa2KboIdLt56WHWfpgADog0KIjcuNjiS+d2gBdokKaNx6/dyR/3MrBl8d2E0 NGWy5dn/9dT/KlwKz4z5FrgFWWhsy0L69IfATdYakJ9I4ePsEPJ9iyHX/zi/QLURu8MellZEirj AnS7Q5tG+2lYKHYQboZEEJ/2wqfsfztFmMSZqJnsQOv9bFsqZYzyzWeW9XaztaX/Y4+ScpvxGiX P7RWxuSq2U8TjWRubAYQZIqqsI3v5rjqb7kwV74AfpxbO7/eObTSTcDgOz/orkYA3a7NOKuqqKk YGgUz/x+3cVmGHRHEKA4QQYe1kPdL9NOhlUhyd3M3ZmZ1AJVdP70aeQ0Bpgzx1PpEV2tLyG7 X-Proofpoint-GUID: VNqH79-0SmTi3T-gSVwgIXKzPVYdb4Jh X-Proofpoint-ORIG-GUID: VNqH79-0SmTi3T-gSVwgIXKzPVYdb4Jh X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1099,Hydra:6.0.736,FMLib:17.12.80.40 definitions=2025-06-10_07,2025-06-10_01,2025-03-28_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 suspectscore=0 mlxlogscore=999 phishscore=0 lowpriorityscore=0 spamscore=0 bulkscore=0 clxscore=1015 adultscore=0 priorityscore=1501 malwarescore=0 mlxscore=0 impostorscore=0 classifier=spam authscore=0 authtc=n/a authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.19.0-2505280000 definitions=main-2506100131 Received-SPF: pass client-ip=148.163.158.5; envelope-from=sudhakar@linux.ibm.com; helo=mx0b-001b2d01.pphosted.com X-Spam_score_int: -26 X-Spam_score: -2.7 X-Spam_bar: -- X-Spam_report: (-2.7 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H5=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, RCVD_IN_VALIDITY_SAFE_BLOCKED=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: grub-devel@gnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: The development of GNU GRUB List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Reply-To: The development of GNU GRUB Content-Transfer-Encoding: base64 Content-Type: text/plain; charset="utf-8"; Format="flowed" Errors-To: grub-devel-bounces+grub-devel=archiver.kernel.org@gnu.org Sender: grub-devel-bounces+grub-devel=archiver.kernel.org@gnu.org SGkgRGFuaWVsLAoKVGhhbmsgeW91IGZvciB5b3VyIHZhbHVhYmxlIHJldmlldyBjb21tZW50cy4g YWRkcmVzc2VkIGFsbCB5b3VyIApjb21tZW50cy4KCk9uIDIwMjUtMDUtMjIgMjM6NDksIERhbmll bCBLaXBlciB3cm90ZToKPiBPbiBUaHUsIE1hciAyNywgMjAyNSBhdCAwMTowMjoyNEFNICswNTMw LCBTdWRoYWthciBLdXBwdXNhbXkgd3JvdGU6Cj4+IEZyb206IERhbmllbCBBeHRlbnMgPGRqYUBh eHRlbnMubmV0Pgo+PiAKPj4gU2lnbmluZyBncnViIGZvciBmaXJtd2FyZSB0aGF0IHZlcmlmaWVz IGFuIGFwcGVuZGVkIHNpZ25hdHVyZSBpcyBhCj4gCj4gcy9ncnViL0dSVUIvCj4gCj4gVGhlIHBy b2plY3QgbmFtZSBpcyBHUlVCLiBQbGVhc2UgZml4IGl0IGV2ZXJ5d2hlcmUuCj4gCj4+IGJpdCBm aWRkbHkuIEkgZG9uJ3Qgd2FudCBwZW9wbGUgdG8gaGF2ZSB0byBmaWd1cmUgaXQgb3V0IGZyb20g c2NyYXRjaAo+PiBzbyBkb2N1bWVudCBpdCBoZXJlLgo+PiAKPj4gU2lnbmVkLW9mZi1ieTogRGFu aWVsIEF4dGVucyA8ZGphQGF4dGVucy5uZXQ+Cj4+IFNpZ25lZC1vZmYtYnk6IFN1ZGhha2FyIEt1 cHB1c2FteSA8c3VkaGFrYXJAbGludXguaWJtLmNvbT4KPj4gUmV2aWV3ZWQtYnk6IFN0ZWZhbiBC ZXJnZXIgPHN0ZWZhbmJAbGludXguaWJtLmNvbT4KPj4gUmV2aWV3ZWQtYnk6IEF2bmlzaCBDaG91 aGFuIDxhdm5pc2hAbGludXguaWJtLmNvbT4KPj4gLS0tCj4+ICBkb2NzL2dydWIudGV4aSB8IDMy ICsrKysrKysrKysrKysrKysrKysrKysrKysrKysrKysrCj4+ICAxIGZpbGUgY2hhbmdlZCwgMzIg aW5zZXJ0aW9ucygrKQo+PiAKPj4gZGlmZiAtLWdpdCBhL2RvY3MvZ3J1Yi50ZXhpIGIvZG9jcy9n cnViLnRleGkKPj4gaW5kZXggMGU4NzdlMDI2Li4xOWJiZTliMmIgMTAwNjQ0Cj4+IC0tLSBhL2Rv Y3MvZ3J1Yi50ZXhpCj4+ICsrKyBiL2RvY3MvZ3J1Yi50ZXhpCj4+IEBAIC05MjYyLDYgKzkyNjIs MzggQEAgaW1hZ2Ugd29ya3MgdW5kZXIgVUVGSSBzZWN1cmUgYm9vdCBhbmQgY2FuIAo+PiBtYWlu dGFpbiB0aGUgc2VjdXJlLWJvb3QgY2hhaW4uIEl0Cj4+ICB3aWxsIGFsc28gYmUgbmVjZXNzYXJ5 IHRvIGVucm9sbCB0aGUgcHVibGljIGtleSB1c2VkIGludG8gYSByZWxldmFudCAKPj4gZmlybXdh cmUKPj4gIGtleSBkYXRhYmFzZS4KPj4gCj4+ICtAc2VjdGlvbiBTaWduaW5nIEdSVUIgd2l0aCBh biBhcHBlbmRlZCBzaWduYXR1cmUKPj4gK1RoZSBAZmlsZXtjb3JlLmltZ30gaXRzZWxmIGNhbiBi ZSBzaWduZWQgd2l0aCBhIExpbnV4IGtlcm5lbCAKPj4gbW9kdWxlLXN0eWxlCj4+ICthcHBlbmRl ZCBzaWduYXR1cmUuCj4+ICtUbyBzdXBwb3J0IElFRUUxMjc1IHBsYXRmb3JtcyB3aGVyZSB0aGUg Ym9vdCBpbWFnZSBpcyBvZnRlbiBsb2FkZWQgCj4+IGRpcmVjdGx5Cj4+ICtmcm9tIGEgZGlzayBw YXJ0aXRpb24gcmF0aGVyIHRoYW4gZnJvbSBhIGZpbGUgc3lzdGVtLCB0aGUgCj4+IEBmaWxle2Nv cmUuaW1nfQo+PiArY2FuIHNwZWNpZnkgdGhlIHNpemUgYW5kIGxvY2F0aW9uIG9mIHRoZSBhcHBl bmRlZCBzaWduYXR1cmUgd2l0aCBhbiAKPj4gRUxGCj4+ICtub3RlIGFkZGVkIGJ5IEBjb21tYW5k e2dydWItaW5zdGFsbH0uCj4+ICtBbiBpbWFnZSBjYW4gYmUgc2lnbmVkIHRoaXMgd2F5IHVzaW5n IHRoZSBAY29tbWFuZHtzaWduLWZpbGV9IGNvbW1hbmQgCj4+IGZyb20KPj4gK3RoZSBMaW51eCBr ZXJuZWw6Cj4+ICtAZXhhbXBsZQo+PiArQGdyb3VwCj4+ICsjIGdydWIua2V5IGlzIHlvdXIgcHJp dmF0ZSBrZXkgYW5kIGNlcnRpZmljYXRlLmRlciBpcyB5b3VyIHB1YmxpYyBrZXkKPj4gKyMgRGV0 ZXJtaW5lIHRoZSBzaXplIG9mIHRoZSBhcHBlbmRlZCBzaWduYXR1cmUuIEl0IGRlcGVuZHMgb24g dGhlIAo+PiBzaWduaW5nCj4+ICsjIGNlcnRpZmljYXRlIGFuZCB0aGUgaGFzaCBhbGdvcml0aG0K Pj4gK3RvdWNoIGVtcHR5Cj4+ICtzaWduLWZpbGUgU0hBMjU2IGdydWIua2V5IGNlcnRpZmljYXRl LmRlciBlbXB0eSBlbXB0eS5zaWcKPiAKPiBXb3VsZCBub3Qgc2lnbmluZyAvZGV2L251bGwgaW5z dGVhZCBvZiBlbXB0eSB3b3JrPwoKSXQgaXMgd29yayBmb3IgL2Rldi9udWxsLiBhZGRyZXNzZWQg dGhpcyBpbiB2MwoKPiAKPj4gK1NJR19TSVpFPWBzdGF0IC1jICclcycgZW1wdHkuc2lnYAo+PiAr cm0gZW1wdHkgZW1wdHkuc2lnCj4+ICsjIEJ1aWxkIGEgZ3J1YiBpbWFnZSB3aXRoICRTSUdfU0la RSByZXNlcnZlZCBmb3IgdGhlIHNpZ25hdHVyZQo+PiArZ3J1Yi1pbnN0YWxsIC0tYXBwZW5kZWQt c2lnbmF0dXJlLXNpemUgJFNJR19TSVpFIC0tbW9kdWxlcz0iLi4uIiAuLi4KPj4gKyMgUmVwbGFj ZSB0aGUgcmVzZXJ2ZWQgc2l6ZSB3aXRoIGEgc2lnbmF0dXJlOgo+PiArIyBjdXQgb2ZmIHRoZSBs YXN0ICRTSUdfU0laRSBieXRlcyB3aXRoIHRydW5jYXRlJ3MgbWludXMgbW9kaWZpZXIKPj4gK3Ry dW5jYXRlIC1zIC0kU0lHX1NJWkUgL2Jvb3QvZ3J1Yi9wb3dlcnBjLWllZWUxMjc1L2NvcmUuZWxm IAo+PiBjb3JlLmVsZi51bnNpZ25lZAo+IAo+IFRoaXMgY291bGQgYmUgcG9zc2libHkgZG9uZSBi eSBncnViLWluc3RhbGwvZ3J1Yi1ta2ltYWdlLiBUaGVuIHlvdSAKPiB3b3VsZAo+IGhhdmUgb25l IHN0ZXAgbGVzcy4gT3IgZXZlbiBhdXRvbWF0ZSBzaWduaW5nIHByb2Nlc3MgYnkgY2FsbGluZyAK PiBzaWduLWZpbGUKPiBmcm9tIHRoZSBHUlVCIHV0aWxzLgoKSW4gdjMsIEkgcmVkdWNlZCB0aGUg dHJ1bmNhdGUgc3RlcCBhbmQgYWRkZWQgdGhlIHNhbWUgaW4gCmdydWItaW5zdGFsbC9ncnViLW1r aW1hZ2UuCkluIGZ1dHVyZSwgSSB3aWxsIGFkZCBhdXRvbWF0ZSBzaWduaW5nIHByb2Nlc3MgaW4g dGhlIEdSVUIgdXRpbHMKCj4+ICsjIHNpZ24gdGhlIHRyaW1tZWQgZmlsZSB3aXRoIGFuIGFwcGVu ZGVkIHNpZ25hdHVyZSwgcmVzdG9yaW5nIHRoZSAKPj4gY29ycmVjdCBzaXplCj4+ICtzaWduLWZp bGUgU0hBMjU2IGdydWIua2V5IGNlcnRpZmljYXRlLmRlciBjb3JlLmVsZi51bnNpZ25lZCAKPj4g Y29yZS5lbGYuc2lnbmVkCj4+ICsjIERvbid0IGZvcmdldCB0byBpbnN0YWxsIHRoZSBzaWduZWQg aW1hZ2UgYXMgcmVxdWlyZWQKPj4gKyMgKGUuZy4gb24gcG93ZXJwYy1pZWVlMTI3NSwgdG8gdGhl IFBSZVAgcGFydGl0aW9uKQo+PiArQGVuZCBncm91cAo+PiArQGVuZCBleGFtcGxlCj4+ICtBcyB3 aXRoIFVFRkkgc2VjdXJlIGJvb3QsIGl0IGlzIG5lY2Vzc2FyeSB0byBidWlsZC1pbiB0aGUgcmVx dWlyZWQgCj4+IG1vZHVsZXMsCj4+ICtvciBzaWduIHRoZW0gc2VwYXJhdGVseS4KCj4gRGFuaWVs CgpfX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fXwpHcnViLWRl dmVsIG1haWxpbmcgbGlzdApHcnViLWRldmVsQGdudS5vcmcKaHR0cHM6Ly9saXN0cy5nbnUub3Jn L21haWxtYW4vbGlzdGluZm8vZ3J1Yi1kZXZlbAo=