0)Open

0.1) Does other community knows what UEFI is doing for PQC?
Yes. Linux -> Peter/James/Doug feedback. DMTF RedFish WG -> Jiewen feedback. 
TCG PC Client WG -> Jiewen feedback.

0.2) We are reaching OpenSSL community for Composite Signature support.
Current TLS is 3.5 used in EDK2.
The next LTS plan is 4.2 - April 2027. (See 
https://openssl-library.org/roadmap/)

1) Backlog review

https://github.com/orgs/tianocore/projects/10/views/1

No new issue.

2) Old issue refresh

2.1) Image Validation Result Table - 
https://github.com/tianocore/edk2/issues/12916
*AR: Joey* to just add new IVRT table without touching IEIT. The IEIT removal 
is already handled.

2.2) IEIT removal - https://github.com/tianocore/edk2/issues/12688
Looks good.

2.3) multiple signature format - 
https://github.com/jyao1/UEFI-Specification-Release/pull/1
*AR: Jiewen* change PKCS#7 to CMS.

3) Some idea for image verification

https://github.com/microsoft/mu_basecore/pull/1809
https://github.com/Javagedes/mu_basecore/tree/personal/joeyvagedes/securitypkg-image-validation/SecurityPkg/Test/ShellTest/ImageValidationTestApp#all-tests

Some feedback:
1) Add SHA1 digest test. Expectation is to ignore. E.g. SHA1 in DBX is ignored.
2) Consider it as a list to validate IVRT table in each case.

Thank you
Yao, Jiewen


-=-=-=-=-=-=-=-=-=-=-=-
Groups.io Links: You receive all messages sent to this group.
View/Reply Online (#122066): https://edk2.groups.io/g/devel/message/122066
Mute This Topic: https://groups.io/mt/120622241/21656
Group Owner: [email protected]
Unsubscribe: https://edk2.groups.io/g/devel/unsub [[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-


Reply via email to