From: Jan Kiszka <jan.kiszka@siemens.com>
To: "Heinisch,
Alexander (FT RPD CED SES-AT)" <alexander.heinisch@siemens.com>,
cip-dev@lists.cip-project.org
Cc: Sai Sree Kartheek Adivi <s-adivi@ti.com>,
Quirin Gylstorff <quirin.gylstorff@siemens.com>
Subject: Re: [isar-cip-core][PATCH 3/7] cip-core-initramfs: Automatically deploy secure boot keys on first boot
Date: Wed, 26 Aug 2026 10:43:16 +0200 [thread overview]
Message-ID: <ec62bbb3-42ad-45d1-b80f-dd5bf8cb0861@siemens.com> (raw)
In-Reply-To: <6ac309bf-4031-4140-a91f-201364052d94@siemens.com>
On 26.08.26 10:17, Heinisch, Alexander (FT RPD CED SES-AT) wrote:
>
>
> Am 26.08.2026 um 07:41 schrieb Jan Kiszka:
>> From: Jan Kiszka <jan.kiszka@siemens.com>
>>
>> This both simplifies the initial deployment of secure boot to a device
>> as well as makes sure that we will always seal the disk encryption key
>> against the right state.
>>
>> We only deploy if secure boot is off and the db is found empty. So this
>> hook is not intended to be used for key exchange or key db extensions.
>> The former will be once handled via SWUpdate packages, the latter might
>> be considered given a concrete use case.
>>
>> Note that due to the primitive implementation of efivarfs detection in
>> efitools, we need to deploy a horrible hack to make it work against the
>> mount implementation of busybox in the initramfs. A patch to improve
>> that issue is pending upstream.
>>
>> Signed-off-by: Jan Kiszka <jan.kiszka@siemens.com>
>> ---
>> .../cip-core-initramfs/cip-core-initramfs.bb | 1 +
>> .../initramfs-sbkeys-hook/files/hook | 16 +++++++++
>> .../initramfs-sbkeys-hook/files/local-top | 34 +++++++++++++++++++
>> .../initramfs-sbkeys-hook/files/mount-stub | 13 +++++++
>> .../initramfs-sbkeys-hook_0.1.bb | 32 +++++++++++++++++
>> 5 files changed, 96 insertions(+)
>> create mode 100644 recipes-initramfs/initramfs-sbkeys-hook/files/hook
>> create mode 100644 recipes-initramfs/initramfs-sbkeys-hook/files/
>> local-top
>> create mode 100755 recipes-initramfs/initramfs-sbkeys-hook/files/
>> mount-stub
>> create mode 100644 recipes-initramfs/initramfs-sbkeys-hook/
>> initramfs-sbkeys-hook_0.1.bb
>>
>> diff --git a/recipes-initramfs/cip-core-initramfs/cip-core-
>> initramfs.bb b/recipes-initramfs/cip-core-initramfs/cip-core-initramfs.bb
>> index b686185c..241e6af6 100644
>> --- a/recipes-initramfs/cip-core-initramfs/cip-core-initramfs.bb
>> +++ b/recipes-initramfs/cip-core-initramfs/cip-core-initramfs.bb
>> @@ -22,6 +22,7 @@ INITRAMFS_INSTALL:append:factory-reset = "
>> initramfs-factory-reset-hook"
>> INITRAMFS_INSTALL:append:ftpm-stmm = " initramfs-tee-ftpm-hook"
>> INITRAMFS_INSTALL:append:swupdate = " initramfs-abrootfs-hook"
>> INITRAMFS_INSTALL:append:swupdate = " initramfs-${RO_ROOTFS_TYPE}-hook"
>> +INITRAMFS_INSTALL:append:secureboot = " initramfs-sbkeys-hook"
>> INITRAMFS_INSTALL:append:secureboot = " initramfs-verity-hook"
>> # abrootfs cannot be installed together with verity
>> INITRAMFS_INSTALL:remove:secureboot = "initramfs-abrootfs-hook"
>> diff --git a/recipes-initramfs/initramfs-sbkeys-hook/files/hook b/
>> recipes-initramfs/initramfs-sbkeys-hook/files/hook
>> new file mode 100644
>> index 00000000..770d4454
>> --- /dev/null
>> +++ b/recipes-initramfs/initramfs-sbkeys-hook/files/hook
>> @@ -0,0 +1,16 @@
>> +#
>> +# CIP Core, generic profile
>> +#
>> +# Copyright (c) Siemens AG, 2026
>> +#
>> +# Authors:
>> +# Jan Kiszka <jan.kiszka@siemens.com>
>> +#
>> +# SPDX-License-Identifier: MIT
>> +#
>> +
>> +copy_file binary /usr/share/secure-boot-efi-keys/db.auth
>> +copy_file binary /usr/share/secure-boot-efi-keys/KEK.auth
>> +copy_file binary /usr/share/secure-boot-efi-keys/PK.auth
>> +
>> +copy_file binary /usr/share/initramfs-sbkeys-hook/mount
>> diff --git a/recipes-initramfs/initramfs-sbkeys-hook/files/local-top
>> b/recipes-initramfs/initramfs-sbkeys-hook/files/local-top
>> new file mode 100644
>> index 00000000..48fe45d4
>> --- /dev/null
>> +++ b/recipes-initramfs/initramfs-sbkeys-hook/files/local-top
>> @@ -0,0 +1,34 @@
>> +#
>> +# CIP Core, generic profile
>> +#
>> +# Copyright (c) Siemens AG, 2026
>> +#
>> +# Authors:
>> +# Jan Kiszka <jan.kiszka@siemens.com>
>> +#
>> +# SPDX-License-Identifier: MIT
>> +#
>> +
>> +. /scripts/cip-initramfs-functions
>> +
>> +if secure_boot_enabled; then
>> + exit 0
>> +fi
>> +
>> +ORIG_PATH="$PATH"
>> +export PATH="/usr/share/initramfs-sbkeys-hook:$PATH"
>> +
>> +if ! efi-readvar -v db | grep -q "has no entries"; then
>> + export PATH="$ORIG_PATH"
>> + log_warning_msg "Not securely booting, but keys already deployed"
>> + exit 0
>> +fi
>> +
>> +log_begin_msg "Deploying EFI secure boot keys"
>> +efi-updatevar -f /usr/share/secure-boot-efi-keys/db.auth db
>> +efi-updatevar -f /usr/share/secure-boot-efi-keys/KEK.auth KEK
>> +efi-updatevar -f /usr/share/secure-boot-efi-keys/PK.auth PK
>> +log_end_msg
>> +
>> +log_success_msg "Rebooting after key deployment..."
>> +reboot
>> diff --git a/recipes-initramfs/initramfs-sbkeys-hook/files/mount-stub
>> b/recipes-initramfs/initramfs-sbkeys-hook/files/mount-stub
>> new file mode 100755
>> index 00000000..408b584e
>> --- /dev/null
>> +++ b/recipes-initramfs/initramfs-sbkeys-hook/files/mount-stub
>> @@ -0,0 +1,13 @@
>> +#!/bin/sh
>> +#
>> +# CIP Core, generic profile
>> +#
>> +# Copyright (c) Siemens AG, 2026
>> +#
>> +# Authors:
>> +# Jan Kiszka <jan.kiszka@siemens.com>
>> +#
>> +# SPDX-License-Identifier: MIT
>> +#
>> +
>> +echo "none on /sys/firmware/efi/efivars type efivarfs"
> what about "cat /proc/mounts" to get the actual systems mount points
> instead of mocking expected behaviour?
>
https://git.kernel.org/pub/scm/linux/kernel/git/jejb/efitools.git/tree/lib/kernel_efivars.c#n69
Was my first try as well, before reading that.
Jan
--
Siemens AG, Foundational Technologies
Linux Expert Center
next prev parent reply other threads:[~2026-08-26 8:43 UTC|newest]
Thread overview: 19+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-26 5:41 [isar-cip-core][PATCH 0/7] Provide measured boot via fTPM for arm64, early deploy EFI keys Jan Kiszka
2026-08-26 5:41 ` [isar-cip-core][PATCH 1/7] secure-boot-efi-keys: Add recipe to create " Jan Kiszka
2026-08-26 8:31 ` Heinisch, Alexander (FT RPD CED SES-AT)
2026-08-26 8:44 ` Jan Kiszka
2026-08-26 8:47 ` Heinisch, Alexander (FT RPD CED SES-AT)
2026-08-26 5:41 ` [isar-cip-core][PATCH 2/7] cip-initramfs-functions: Add secure_boot_enabled helper Jan Kiszka
2026-08-26 7:51 ` Heinisch, Alexander (FT RPD CED SES-AT)
2026-08-26 7:54 ` Jan Kiszka
2026-08-26 9:33 ` Heinisch, Alexander (FT RPD CED SES-AT)
2026-08-26 5:41 ` [isar-cip-core][PATCH 3/7] cip-core-initramfs: Automatically deploy secure boot keys on first boot Jan Kiszka
2026-08-26 8:17 ` Heinisch, Alexander (FT RPD CED SES-AT)
2026-08-26 8:43 ` Jan Kiszka [this message]
2026-08-26 5:41 ` [isar-cip-core][PATCH 4/7] u-boot: Add patches to enable measured boot with fTPM Jan Kiszka
2026-08-26 5:41 ` [isar-cip-core][PATCH 5/7] u-boot: Refactor ftpm-stmm.cfg to enable measured boot for all Jan Kiszka
2026-08-26 5:41 ` [isar-cip-core][PATCH 6/7] u-boot: Drop obsolete config workaround Jan Kiszka
2026-08-26 5:41 ` [isar-cip-core][PATCH 7/7] initramfs-crypt-hook: Prevent encryption without secure boot Jan Kiszka
2026-10-01 9:41 ` Quirin Gylstorff
2026-10-01 16:16 ` Jan Kiszka
2026-08-27 7:42 ` [isar-cip-core][PATCH 8/7] doc: Update README.secureboot regarding recent deployment enhancements Jan Kiszka
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=ec62bbb3-42ad-45d1-b80f-dd5bf8cb0861@siemens.com \
--to=jan.kiszka@siemens.com \
--cc=alexander.heinisch@siemens.com \
--cc=cip-dev@lists.cip-project.org \
--cc=quirin.gylstorff@siemens.com \
--cc=s-adivi@ti.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.