From: Matthew Garrett <mjg-H+wXaHxf7aLQT0dZR+AlfA@public.gmane.org> To: Jiri Kosina <jkosina-AlSwsSmVLrQ@public.gmane.org> Cc: linux-kernel-u79uwXL29TY76Z2rM5mHXA@public.gmane.org, linux-security-module-u79uwXL29TY76Z2rM5mHXA@public.gmane.org, linux-efi-u79uwXL29TY76Z2rM5mHXA@public.gmane.org, James Bottomley <James.Bottomley-d9PhHud1JfjCXq6kfMZ53/egYHeGw8Jk@public.gmane.org>, Shea Levy <shea-yfkUTty7RcRWk0Htik3J/w@public.gmane.org>, Vivek Goyal <vgoyal-H+wXaHxf7aLQT0dZR+AlfA@public.gmane.org> Subject: Re: [RFC] Second attempt at kernel secure boot support Date: Tue, 6 Nov 2012 13:16:34 +0000 [thread overview] Message-ID: <20121106131634.GA1818@srcf.ucam.org> (raw) In-Reply-To: <alpine.LNX.2.00.1211061350100.24253-ztGlSCb7Y1iN3ZZ/Hiejyg@public.gmane.org> On Tue, Nov 06, 2012 at 01:51:15PM +0100, Jiri Kosina wrote: > On Wed, 31 Oct 2012, Matthew Garrett wrote: > > shim generates a public and private key. > > It seems to me that this brings quite a huge delay into the boot process > both for "regular" and resume cases (as shim has no way to know what is > going to happen next). Mostly because obtaining enough entropy is > generally very difficult when we have just shim running, right? pseudorandom keys should be sufficient here. It's intended to deal with the case of an automated attack rather than a deliberate effort to break into a given user's system. > > It hands the kernel the private key in a boot parameter and stores the > > public key in a boot variable. On suspend, the kernel signs the suspend > > image with that private key and discards it. On the next boot, shim > > generates a new key pair and hands the new private key to the kernel > > along with the old public key. The kernel verifies the suspend image > > before resuming it. The only way to subvert this would be to be able to > > access kernel memory directly, which means the attacker has already won. > > I like this protocol, but after some off-line discussions, I still have > doubts about it. Namely: how do we make sure that there is noone tampering > with the variable? The variable has the same level of security as MOK, so that would be a more attractive target. > - consider securely booted win8 (no Linux installed on that machine, so > the variable for storing public key doesn't exist yet), possibly being > taken over by a malicious user > - he/she creates this secure variable from within the win8 and stores > his/her own public key into it You can't create a non-RT variable from the OS. > - he/she supplies a signed shim (as provided by some Linux distro vendor), > signed kernel (as provided by some Linux distro vendor) and specially > crafted resume image, signed by his/her own private key shim detects that the key has the RT bit set and deletes it. > - he/she reboots the machine in a way that shim+distro kernel+hacker's S4 > image is used to resume And so this step can't happen. -- Matthew Garrett | mjg59-1xO5oi07KQx4cg9Nei1l7Q@public.gmane.org
next prev parent reply other threads:[~2012-11-06 13:16 UTC|newest]
Thread overview: 203+ messages / expand[flat|nested] mbox.gz Atom feed top
[not found] <1348152065-31353-1-git-send-email-mjg@redhat.com>
[not found] ` <1348152065-31353-2-git-send-email-mjg@redhat.com>
[not found] ` <1348152065-31353-2-git-send-email-mjg-H+wXaHxf7aLQT0dZR+AlfA@public.gmane.org>
2012-10-20 0:15 ` [PATCH V2 01/10] Secure boot: Add new capability joeyli
2012-10-20 9:02 ` Matt Fleming
[not found] ` <1348152065-31353-9-git-send-email-mjg@redhat.com>
[not found] ` <1348152065-31353-9-git-send-email-mjg-H+wXaHxf7aLQT0dZR+AlfA@public.gmane.org>
2012-10-22 13:22 ` [PATCH V2 08/10] efi: Enable secure boot lockdown automatically when enabled in firmware Matt Fleming
[not found] ` <1348152065-31353-1-git-send-email-mjg-H+wXaHxf7aLQT0dZR+AlfA@public.gmane.org>
2012-10-29 7:49 ` [RFC] Second attempt at kernel secure boot support Jiri Kosina
[not found] ` <alpine.LRH.2.00.1210290848450.10392-1ReQVI26iDCaZKY3DrU6dA@public.gmane.org>
2012-10-29 17:41 ` Matthew Garrett
2012-10-31 14:50 ` Jiri Kosina
2012-10-31 14:54 ` Josh Boyer
[not found] ` <CA+5PVA63EHiXbGAox+FmJPvztSj_i7QgnDG8vdj=p0xE+dqgGQ-JsoAwUIsXosN+BqQ9rBEUg@public.gmane.org>
2012-10-31 14:59 ` Shea Levy
2012-10-31 15:55 ` Alan Cox
[not found] ` <20121031155503.1aaf4c93-38n7/U1jhRXW96NNrWNlrekiAK3p4hvP@public.gmane.org>
2012-10-31 15:55 ` Jiri Kosina
[not found] ` <alpine.LNX.2.00.1210311653080.12781-ztGlSCb7Y1iN3ZZ/Hiejyg@public.gmane.org>
2012-10-31 17:03 ` Alan Cox
[not found] ` <20121031170334.59833fb1-38n7/U1jhRXW96NNrWNlrekiAK3p4hvP@public.gmane.org>
2012-10-31 17:01 ` Shea Levy
2012-10-31 17:17 ` Alan Cox
2012-10-31 17:10 ` Matthew Garrett
2012-10-31 17:21 ` Alan Cox
[not found] ` <20121031172121.14cc1215-38n7/U1jhRXW96NNrWNlrekiAK3p4hvP@public.gmane.org>
2012-10-31 17:17 ` Matthew Garrett
2012-10-31 17:39 ` Alan Cox
2012-10-31 17:37 ` Matthew Garrett
[not found] ` <20121031173750.GB18615-1xO5oi07KQx4cg9Nei1l7Q@public.gmane.org>
2012-10-31 17:49 ` Alan Cox
2012-10-31 17:45 ` Matthew Garrett
2012-10-31 20:14 ` Oliver Neukum
2012-10-31 21:58 ` Chris Friesen
[not found] ` <50919EED.3020601-b7o/lNNmKxtBDgjK7y7TUQ@public.gmane.org>
2012-10-31 22:00 ` Jiri Kosina
2012-10-31 22:19 ` Oliver Neukum
2012-11-01 9:08 ` James Bottomley
[not found] ` <1351760905.2391.19.camel-sFMDBYUN5F8GjUHQrlYNx2Wm91YjaHnnhRte9Li2A+AAvxtiuMwx3w@public.gmane.org>
2012-11-01 9:20 ` Jiri Kosina
[not found] ` <alpine.LNX.2.00.1211011017230.6606-ztGlSCb7Y1iN3ZZ/Hiejyg@public.gmane.org>
2012-11-01 9:38 ` James Bottomley
[not found] ` <1351762703.2391.31.camel-sFMDBYUN5F8GjUHQrlYNx2Wm91YjaHnnhRte9Li2A+AAvxtiuMwx3w@public.gmane.org>
2012-11-01 9:45 ` Jiri Kosina
2012-11-01 9:59 ` James Bottomley
2012-11-01 10:06 ` Jiri Kosina
[not found] ` <1351763954.2391.37.camel-sFMDBYUN5F8GjUHQrlYNx2Wm91YjaHnnhRte9Li2A+AAvxtiuMwx3w@public.gmane.org>
2012-11-01 14:29 ` Eric Paris
2012-11-01 14:42 ` James Bottomley
[not found] ` <1351780935.2391.58.camel-sFMDBYUN5F8GjUHQrlYNx2Wm91YjaHnnhRte9Li2A+AAvxtiuMwx3w@public.gmane.org>
2012-11-01 14:49 ` Matthew Garrett
2012-11-01 15:06 ` James Bottomley
[not found] ` <1351782390.2391.69.camel-sFMDBYUN5F8GjUHQrlYNx2Wm91YjaHnnhRte9Li2A+AAvxtiuMwx3w@public.gmane.org>
2012-11-01 15:17 ` Eric Paris
2012-11-01 16:26 ` Matthew Garrett
2012-11-01 15:06 ` Alan Cox
[not found] ` <20121101150654.19efe0b5-38n7/U1jhRXW96NNrWNlrekiAK3p4hvP@public.gmane.org>
2012-11-01 16:29 ` Matthew Garrett
2012-11-01 16:40 ` Alan Cox
2012-11-01 14:59 ` Eric Paris
2012-11-01 15:11 ` Alan Cox
[not found] ` <CACLa4pvh3v3Mhq8oe3dzRL8ytBgmitPkCGUSfVCR5WdQopjRMQ-JsoAwUIsXosN+BqQ9rBEUg@public.gmane.org>
2012-11-01 15:18 ` James Bottomley
[not found] ` <1351783096.2391.77.camel-sFMDBYUN5F8GjUHQrlYNx2Wm91YjaHnnhRte9Li2A+AAvxtiuMwx3w@public.gmane.org>
2012-11-01 17:50 ` Eric Paris
2012-11-01 21:03 ` James Bottomley
2012-11-01 21:06 ` Matthew Garrett
2012-11-01 21:14 ` James Bottomley
2012-11-01 21:18 ` Matthew Garrett
2012-11-01 21:35 ` Alan Cox
2012-11-01 21:31 ` Alan Cox
2012-11-01 21:28 ` Matthew Garrett
[not found] ` <20121101212843.GA20309-1xO5oi07KQx4cg9Nei1l7Q@public.gmane.org>
2012-11-01 21:37 ` Alan Cox
2012-11-01 21:34 ` Matthew Garrett
2012-11-01 21:58 ` Alan Cox
[not found] ` <20121101215817.79e50ec2-38n7/U1jhRXW96NNrWNlrekiAK3p4hvP@public.gmane.org>
2012-11-01 21:57 ` Matthew Garrett
[not found] ` <20121101215752.GA21154-1xO5oi07KQx4cg9Nei1l7Q@public.gmane.org>
2012-11-02 8:49 ` Eric W. Biederman
2012-11-02 14:00 ` Matthew Garrett
2012-11-02 22:03 ` Eric W. Biederman
[not found] ` <87liejacix.fsf-aS9lmoZGLiVWk0Htik3J/w@public.gmane.org>
2012-11-02 22:19 ` Chris Friesen
2012-11-02 23:46 ` Alan Cox
2012-11-03 0:23 ` Matthew Garrett
2012-11-03 0:55 ` Alan Cox
2012-11-03 0:20 ` Matthew Garrett
2012-11-03 0:47 ` Eric W. Biederman
2012-11-03 1:03 ` Alan Cox
[not found] ` <87sj8rwm0p.fsf-aS9lmoZGLiVWk0Htik3J/w@public.gmane.org>
2012-11-03 1:43 ` Matthew Garrett
2012-11-03 16:31 ` Alan Cox
2012-11-03 16:37 ` Matthew Garrett
2012-11-03 16:37 ` Eric Paris
[not found] ` <CACLa4pt3_Fc5fHKf=ihzV0zDb7zvCyzWp92YLakjGqL7MCaiEA-JsoAwUIsXosN+BqQ9rBEUg@public.gmane.org>
2012-11-03 16:42 ` Matthew Garrett
2012-11-02 17:19 ` Vivek Goyal
[not found] ` <CACLa4puzLR2om6SHw3wVnfZ1nezVsKOp8+705AdHZ4_=JamYfw-JsoAwUIsXosN+BqQ9rBEUg@public.gmane.org>
2012-11-01 14:46 ` Alan Cox
2012-11-01 15:04 ` Eric Paris
2012-11-01 20:27 ` Pavel Machek
2012-11-01 21:02 ` Chris Friesen
[not found] ` <5092E361.7080901-b7o/lNNmKxtBDgjK7y7TUQ@public.gmane.org>
2012-11-02 15:48 ` Vivek Goyal
[not found] ` <20121102154833.GG3300-H+wXaHxf7aLQT0dZR+AlfA@public.gmane.org>
2012-11-02 16:54 ` Chris Friesen
[not found] ` <5093FADA.2040004-b7o/lNNmKxtBDgjK7y7TUQ@public.gmane.org>
2012-11-02 17:03 ` Vivek Goyal
2012-11-03 23:09 ` Jiri Kosina
[not found] ` <alpine.LNX.2.00.1211040008280.24253-ztGlSCb7Y1iN3ZZ/Hiejyg@public.gmane.org>
2012-11-05 6:38 ` Eric W. Biederman
[not found] ` <87390ok0zy.fsf-aS9lmoZGLiVWk0Htik3J/w@public.gmane.org>
2012-11-05 14:40 ` Jiri Kosina
2012-11-05 15:31 ` Jiri Kosina
2012-11-05 15:37 ` Chris Friesen
2012-11-05 18:22 ` Vivek Goyal
2012-11-02 16:33 ` Pavel Machek
2012-11-02 16:52 ` James Bottomley
[not found] ` <1351875164.2439.42.camel-sFMDBYUN5F8GjUHQrlYNx2Wm91YjaHnnhRte9Li2A+AAvxtiuMwx3w@public.gmane.org>
2012-11-02 16:54 ` Matthew Garrett
2012-11-02 17:48 ` James Bottomley
2012-11-02 17:54 ` Matthew Garrett
[not found] ` <20121102175416.GA11816-1xO5oi07KQx4cg9Nei1l7Q@public.gmane.org>
2012-11-02 17:57 ` James Bottomley
2012-11-02 18:04 ` Matthew Garrett
[not found] ` <20121102180458.GA12052-1xO5oi07KQx4cg9Nei1l7Q@public.gmane.org>
2012-11-02 19:18 ` Eric Paris
2012-11-02 23:38 ` James Bottomley
2012-11-03 0:22 ` Matthew Garrett
2012-11-03 12:03 ` James Bottomley
2012-11-03 13:46 ` Matthew Garrett
[not found] ` <20121103134630.GA28166-1xO5oi07KQx4cg9Nei1l7Q@public.gmane.org>
2012-11-03 22:56 ` James Bottomley
[not found] ` <1351983400.2417.21.camel-sFMDBYUN5F8GjUHQrlYNx2Wm91YjaHnnhRte9Li2A+AAvxtiuMwx3w@public.gmane.org>
2012-11-04 4:28 ` Matthew Garrett
[not found] ` <20121104042802.GA11295-1xO5oi07KQx4cg9Nei1l7Q@public.gmane.org>
2012-11-04 9:14 ` James Bottomley
2012-11-04 13:52 ` Matthew Garrett
[not found] ` <20121104135251.GA17894-1xO5oi07KQx4cg9Nei1l7Q@public.gmane.org>
2012-11-05 6:14 ` Eric W. Biederman
[not found] ` <87d2zsmv8r.fsf-aS9lmoZGLiVWk0Htik3J/w@public.gmane.org>
2012-11-05 7:12 ` H. Peter Anvin
[not found] ` <509766DB.9090906-YMNOUZJC4hwAvxtiuMwx3w@public.gmane.org>
2012-11-05 7:24 ` Eric W. Biederman
[not found] ` <87625kh5r2.fsf-aS9lmoZGLiVWk0Htik3J/w@public.gmane.org>
2012-11-05 7:40 ` H. Peter Anvin
2012-11-05 8:50 ` Eric W. Biederman
[not found] ` <87k3u0cu1k.fsf-aS9lmoZGLiVWk0Htik3J/w@public.gmane.org>
2012-11-05 8:53 ` H. Peter Anvin
2012-11-05 12:38 ` Matthew Garrett
[not found] ` <20121105123858.GB4374-1xO5oi07KQx4cg9Nei1l7Q@public.gmane.org>
2012-11-05 13:44 ` Alan Cox
[not found] ` <20121105134436.08993fd6-38n7/U1jhRXW96NNrWNlrekiAK3p4hvP@public.gmane.org>
2012-11-05 13:46 ` Matthew Garrett
2012-11-05 19:16 ` Eric W. Biederman
[not found] ` <87sj8nc137.fsf-aS9lmoZGLiVWk0Htik3J/w@public.gmane.org>
2012-11-05 20:25 ` Matthew Garrett
2012-11-06 2:46 ` Eric W. Biederman
[not found] ` <87hap3zbw7.fsf-aS9lmoZGLiVWk0Htik3J/w@public.gmane.org>
2012-11-06 3:12 ` Matthew Garrett
2012-11-06 3:36 ` Eric W. Biederman
2012-11-06 3:53 ` Matthew Garrett
[not found] ` <20121106035352.GA24698-1xO5oi07KQx4cg9Nei1l7Q@public.gmane.org>
2012-11-06 5:19 ` Eric W. Biederman
2012-11-06 5:34 ` Matthew Garrett
2012-11-06 7:56 ` Florian Weimer
[not found] ` <878vafqi5q.fsf-ZqZwdwZz9NfTBotR3TxKnbNAH6kLmebB@public.gmane.org>
2012-11-06 15:14 ` Chris Friesen
2012-11-06 15:19 ` Jiri Kosina
[not found] ` <50992946.4060101-b7o/lNNmKxtBDgjK7y7TUQ@public.gmane.org>
2012-11-06 21:51 ` Florian Weimer
2012-11-06 21:55 ` Matthew Garrett
2012-11-06 22:06 ` Florian Weimer
[not found] ` <87fw4mv11b.fsf-ZqZwdwZz9NfTBotR3TxKnbNAH6kLmebB@public.gmane.org>
2012-11-06 22:31 ` Matthew Garrett
2012-11-06 22:49 ` Alan Cox
2012-11-06 22:47 ` Matthew Garrett
[not found] ` <CAMFK0gt7oAr4ArD8FmD8QE+i4g4rSTmQjbbLcjs02xwQeXGx-A@mail.gmail.com>
[not found] ` <CAMFK0gt7oAr4ArD8FmD8QE+i4g4rSTmQjbbLcjs02xwQeXGx-A-JsoAwUIsXosN+BqQ9rBEUg@public.gmane.org>
2012-11-07 14:55 ` Matthew Garrett
2012-11-08 10:18 ` James Courtier-Dutton
[not found] ` <CAAMvbhFF=kb8TJ4oE+40Zrx7HD1OkD0NOYj7QEZegZKGtqDm_A@mail.gmail.com>
[not found] ` <CAAMvbhFF=kb8TJ4oE+40Zrx7HD1OkD0NOYj7QEZegZKGtqDm_A-JsoAwUIsXosN+BqQ9rBEUg@public.gmane.org>
2012-11-08 11:19 ` Alan Cox
2012-11-06 9:12 ` Alan Cox
[not found] ` <20121106091217.4a5240f0-38n7/U1jhRXW96NNrWNlrekiAK3p4hvP@public.gmane.org>
2012-11-06 13:17 ` Matthew Garrett
2012-11-06 8:13 ` Valdis.Kletnieks
2012-11-05 8:20 ` James Bottomley
2012-11-05 12:36 ` Matthew Garrett
2012-11-04 11:53 ` Pavel Machek
2012-11-05 21:25 ` Florian Weimer
2012-11-02 14:55 ` Vivek Goyal
2012-11-01 10:12 ` Oliver Neukum
2012-10-31 17:21 ` Jiri Kosina
2012-10-31 15:56 ` Matthew Garrett
[not found] ` <20121031155635.GA14294-1xO5oi07KQx4cg9Nei1l7Q@public.gmane.org>
2012-10-31 17:08 ` Alan Cox
2012-10-31 17:08 ` Shea Levy
2012-10-31 16:04 ` Jiri Kosina
2012-10-31 16:10 ` Josh Boyer
2012-10-31 15:02 ` Matthew Garrett
2012-11-02 15:30 ` Vivek Goyal
2012-11-02 15:42 ` Matthew Garrett
[not found] ` <20121102154248.GA7681-1xO5oi07KQx4cg9Nei1l7Q@public.gmane.org>
2012-11-02 15:52 ` Vivek Goyal
2012-11-02 16:22 ` Jiri Kosina
2012-11-02 18:30 ` Vivek Goyal
2012-11-02 16:35 ` Shuah Khan
[not found] ` <20121031150201.GA12394-1xO5oi07KQx4cg9Nei1l7Q@public.gmane.org>
2012-10-31 15:05 ` Shea Levy
[not found] ` <50913E24.1010009-yfkUTty7RcRWk0Htik3J/w@public.gmane.org>
2012-10-31 15:09 ` Matthew Garrett
2012-11-06 12:51 ` Jiri Kosina
[not found] ` <alpine.LNX.2.00.1211061350100.24253-ztGlSCb7Y1iN3ZZ/Hiejyg@public.gmane.org>
2012-11-06 13:16 ` Matthew Garrett [this message]
[not found] ` <20121029174131.GC7580-1xO5oi07KQx4cg9Nei1l7Q@public.gmane.org>
2012-10-31 17:28 ` Takashi Iwai
[not found] ` <s5hobjia6vj.wl%tiwai-l3A5Bk7waGM@public.gmane.org>
2012-10-31 17:37 ` Matthew Garrett
2012-10-31 17:44 ` Alan Cox
2012-10-31 17:44 ` Matthew Garrett
2012-10-31 18:53 ` Takashi Iwai
2012-11-01 4:21 ` joeyli
[not found] ` <1351743715.21227.95.camel-ONCj+Eqt86TasUa73XJKwA@public.gmane.org>
2012-11-01 13:18 ` Alan Cox
[not found] ` <20121101131849.752df6fd-38n7/U1jhRXW96NNrWNlrekiAK3p4hvP@public.gmane.org>
2012-11-05 17:13 ` Takashi Iwai
2012-11-05 17:18 ` [PATCH RFC 0/4] Add firmware signature file check Takashi Iwai
2012-11-05 17:19 ` [PATCH RFC 1/4] scripts/sign-file: Allow specifying hash algorithm via -a option Takashi Iwai
2012-11-05 17:19 ` [PATCH RFC 2/4] scripts/sign-file: Support firmware signing Takashi Iwai
2012-11-05 17:20 ` [PATCH RFC 3/4] firmware: Add a signature check Takashi Iwai
2012-11-05 17:20 ` [PATCH RFC 4/4] firmware: Install signature files automatically Takashi Iwai
2012-11-05 18:12 ` [PATCH RFC 0/4] Add firmware signature file check Takashi Iwai
[not found] ` <s5hhap49den.wl%tiwai-l3A5Bk7waGM@public.gmane.org>
2012-11-05 20:43 ` Josh Boyer
2012-11-06 6:46 ` Takashi Iwai
2012-11-06 9:20 ` Alan Cox
2012-11-06 10:05 ` Takashi Iwai
2012-11-06 0:01 ` David Howells
2012-11-06 0:05 ` David Howells
[not found] ` <5839.1352160112-S6HVgzuS8uM4Awkfq6JHfwNdhmdF6hFW@public.gmane.org>
2012-11-06 7:01 ` Takashi Iwai
2012-11-06 2:30 ` Ming Lei
2012-11-06 5:46 ` lee joey
[not found] ` <CACVXFVN8qPTgiYKXaeKFJXLXMjLE=+=8Vev2otD3v1VMk+Ez_w-JsoAwUIsXosN+BqQ9rBEUg@public.gmane.org>
2012-11-06 7:03 ` Takashi Iwai
2012-11-06 7:16 ` Ming Lei
2012-11-06 7:32 ` Takashi Iwai
[not found] ` <s5h4nl3i3u6.wl%tiwai-l3A5Bk7waGM@public.gmane.org>
2012-11-06 8:04 ` Ming Lei
2012-11-06 8:18 ` Takashi Iwai
2012-11-06 10:04 ` Ming Lei
2012-11-06 10:17 ` Takashi Iwai
[not found] ` <s5h4nl39gt9.wl%tiwai-l3A5Bk7waGM@public.gmane.org>
2012-11-06 10:40 ` Ming Lei
2012-11-06 10:53 ` Takashi Iwai
2012-11-06 11:03 ` Ming Lei
2012-11-06 11:15 ` Alan Cox
[not found] ` <CAGB3EUTrSMDhja9Gu3h7nuZX+H2_owp8MnUNwbZuCW=_GuawqQ@mail.gmail.com>
[not found] ` <CAGB3EUTrSMDhja9Gu3h7nuZX+H2_owp8MnUNwbZuCW=_GuawqQ-JsoAwUIsXosN+BqQ9rBEUg@public.gmane.org>
2012-11-06 7:06 ` Takashi Iwai
2012-11-06 7:30 ` Ming Lei
2012-11-08 17:35 ` [PATCH RFC v2 " Takashi Iwai
2012-11-08 17:35 ` [PATCH RFC v2 1/4] firmware: Add the firmware signing support to scripts/sign-file Takashi Iwai
2012-11-23 6:51 ` joeyli
2012-11-08 17:35 ` [PATCH RFC v2 2/4] firmware: Add -a option " Takashi Iwai
[not found] ` <1352396109-3989-3-git-send-email-tiwai-l3A5Bk7waGM@public.gmane.org>
2012-11-23 6:51 ` joeyli
2012-11-08 17:35 ` [PATCH RFC v2 3/4] firmware: Add support for signature checks Takashi Iwai
[not found] ` <1352396109-3989-4-git-send-email-tiwai-l3A5Bk7waGM@public.gmane.org>
2012-11-23 6:56 ` joeyli
2012-11-23 7:34 ` Takashi Iwai
[not found] ` <1352396109-3989-1-git-send-email-tiwai-l3A5Bk7waGM@public.gmane.org>
2012-11-08 17:35 ` [PATCH RFC v2 4/4] firmware: Install firmware signature files automatically Takashi Iwai
[not found] ` <1352396109-3989-5-git-send-email-tiwai-l3A5Bk7waGM@public.gmane.org>
2012-11-23 6:52 ` joeyli
[not found] ` <1348152065-31353-8-git-send-email-mjg@redhat.com>
[not found] ` <20120920163237.GA11077@kroah.com>
[not found] ` <20120925130818.GE18546@hansolo.jdub.homelinux.org>
[not found] ` <20120925130818.GE18546-dHPIJuKSOV01V+h/cAXI7w8O6CCKKCg3HZ5vskTnxNA@public.gmane.org>
2012-10-29 9:00 ` [PATCH V3 07/10] Secure boot: Add a dummy kernel parameter that will switch on Secure Boot mode joeyli
2012-10-30 17:48 ` Josh Boyer
2012-10-30 19:27 ` joeyli
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20121106131634.GA1818@srcf.ucam.org \
--to=mjg-h+wxahxf7alqt0dzr+alfa@public.gmane.org \
--cc=James.Bottomley-d9PhHud1JfjCXq6kfMZ53/egYHeGw8Jk@public.gmane.org \
--cc=jkosina-AlSwsSmVLrQ@public.gmane.org \
--cc=linux-efi-u79uwXL29TY76Z2rM5mHXA@public.gmane.org \
--cc=linux-kernel-u79uwXL29TY76Z2rM5mHXA@public.gmane.org \
--cc=linux-security-module-u79uwXL29TY76Z2rM5mHXA@public.gmane.org \
--cc=shea-yfkUTty7RcRWk0Htik3J/w@public.gmane.org \
--cc=vgoyal-H+wXaHxf7aLQT0dZR+AlfA@public.gmane.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions for how to clone and mirror all data and code used for this inbox; as well as URLs for NNTP newsgroup(s).