Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

SUSE Liberty Linux 7 #450

Open
8 tasks done
jsegitz opened this issue Nov 12, 2024 · 2 comments
Open
8 tasks done

SUSE Liberty Linux 7 #450

jsegitz opened this issue Nov 12, 2024 · 2 comments
Labels
2 reviews needed Needs 2 (additional) successful reviews before being accepted Accredited review needed Needs a successful review by an accredited reviewer contacts verified OK Contact verification is complete here (or in an earlier submission)

Comments

@jsegitz
Copy link

jsegitz commented Nov 12, 2024

Confirm the following are included in your repo, checking each box:

  • completed README.md file with the necessary information
  • shim.efi to be signed
  • public portion of your certificate(s) embedded in shim (the file passed to VENDOR_CERT_FILE)
  • binaries, for which hashes are added to vendor_db ( if you use vendor_db and have hashes allow-listed )
  • any extra patches to shim via your own git tree or as files
  • any extra patches to grub via your own git tree or as files
  • build logs
  • a Dockerfile to reproduce the build of the provided shim EFI binaries

What is the link to your tag in a repo cloned from rhboot/shim-review?


https://github.com/jsegitz/shim-review-nonfork/tree/SUSE-SLL7-x64-ia32-20241112


What is the SHA256 hash of your final SHIM binary?


Output from sha256sum:

$ sha256sum shimia32.efi

7620c859572a45524f36ef89bedaa05b05f0f3a9daefca4566b19516cef4ae9c ./shimia32.efi

$ sha256sum shimx64.efi

36b17db9300b8e90c11e86ec646b5b3975bfaf834ec10ecb2954bd49136fa8c1 ./shimx64.efi

Output from pesign:

$ pesign --hash --padding --in=shimia32.efi

hash: 800377346f8461fa5f85a41aebc1c41f4dab86f7356f3b43f82277f26a4c622d

$ pesign --hash --padding --in=shimx64.efi

hash: 8ed0ca1a25fd7bf38f03a9cdb350673f3dc62ea9e18daee365c9024df381abf1


What is the link to your previous shim review request (if any, otherwise N/A)?


#183


If no security contacts have changed since verification, what is the link to your request, where they've been verified (if any, otherwise N/A)?


#419

@jsegitz
Copy link
Author

jsegitz commented Nov 12, 2024

The repository isn't a direct for fork because LFS doesn't work for forks.

@jsegitz jsegitz changed the title SUSE Liberty Linux 9 SUSE Liberty Linux 7 Nov 12, 2024
@steve-mcintyre steve-mcintyre added the contacts verified OK Contact verification is complete here (or in an earlier submission) label Nov 12, 2024
@steve-mcintyre
Copy link
Collaborator

Contact verification already completed previously

@steve-mcintyre steve-mcintyre added 2 reviews needed Needs 2 (additional) successful reviews before being accepted Accredited review needed Needs a successful review by an accredited reviewer labels Nov 13, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
2 reviews needed Needs 2 (additional) successful reviews before being accepted Accredited review needed Needs a successful review by an accredited reviewer contacts verified OK Contact verification is complete here (or in an earlier submission)
Projects
None yet
Development

No branches or pull requests

2 participants