On August 9, 2021 3:40 AM, Marvin Häuser wrote: > Subject: [PATCH] SecurityPkg/DxeImageVerificationLib: Always lookup SHA-256 > hash in dbx > > REF: https://bugzilla.tianocore.org/show_bug.cgi?id=3461 > > The UEFI specification prohibits loading any UEFI image of which a matching > SHA-256 hash is contained in "dbx" (UEFI 2.9, 32.5.3.3 "Authorization > Process", > 3.A). Currently, this is only explicitly checked when the image is unsigned > and > otherwise the hash algorithms of the certificates are used. > > Align with the UEFI specification by specifically looking up the > SHA-256 hash of the image in "dbx". > > Cc: Jiewen Yao <jiewen....@intel.com> > Cc: Jian J Wang <jian.j.w...@intel.com> > Cc: Min Xu <min.m...@intel.com> > Cc: Vitaly Cheptsov <vit9...@protonmail.com> > Signed-off-by: Marvin Häuser <mhaeu...@posteo.de> > --- It seems there are 3 patches sent from Marvin Häuser and I suppose they're in one patch-set, right? Please follow the link below to send out patch-set for review. https://github.com/tianocore/tianocore.github.io/wiki/Laszlo's-unkempt-git-guide-for-edk2-contributors-and-maintainers For example, if there are 3 commits in one patch-set, then the subject of the commits looks like: [PATCH 0/4] This is the cover letter [PATCH 1/4] This is patch 1
Otherwise the reviewers are confused by the patches. Thanks! Xu, Min -=-=-=-=-=-=-=-=-=-=-=- Groups.io Links: You receive all messages sent to this group. View/Reply Online (#78909): https://edk2.groups.io/g/devel/message/78909 Mute This Topic: https://groups.io/mt/84754063/21656 Group Owner: devel+ow...@edk2.groups.io Unsubscribe: https://edk2.groups.io/g/devel/unsub [arch...@mail-archive.com] -=-=-=-=-=-=-=-=-=-=-=-