I would try those certs  on another platform such as OVMF or even nt32pkg as
described in the paper Brian referenced earlier.

I believe only the DER formatted ones will  work

 

Good luck

Lee

 

From: baban devkate [mailto:baban...@gmail.com] 
Sent: Monday, July 22, 2013 8:54 PM
To: Rosenbaum, Lee G
Cc: Richardson, Brian; edk2-devel@lists.sourceforge.net
Subject: Re: [edk2] How to load self signed secure boot keys on ASUS P8H61-M
LX2 R2.0?

 

to Lee

 

thanks Lee,

 

I tried both PEM and DER encoded keys/certificates.

 

Any test keys/certificate which worked on ASUS, if nay?

  <https://mail.google.com/mail/images/cleardot.gif> 

        
9:18 AM (1 minute ago)

  <https://mail.google.com/mail/images/cleardot.gif> 

          <https://mail.google.com/mail/images/cleardot.gif> 

  <https://mail.google.com/mail/images/cleardot.gif> 



to Brian

  <https://mail.google.com/mail/images/cleardot.gif> 

Thanks Brian,

 

I used this document also for this experiment.

 

As you said, It may be format of the certificate used by ASUS.

 

I raised ticket with ASUS, but they are telling get in touch with openssl or
MSFT. Don't know how to proceed:(

 

Any other pointer?

 

On Tue, Jul 23, 2013 at 4:46 AM, Rosenbaum, Lee G
<lee.g.rosenb...@intel.com> wrote:

Are you using a .pem cert file?  Try with a DER format instead  i.e. a .cer
file

 

From: Richardson, Brian [mailto:brian.richard...@intel.com] 
Sent: Monday, July 22, 2013 3:59 PM
To: baban devkate; edk2-devel@lists.sourceforge.net
Subject: Re: [edk2] How to load self signed secure boot keys on ASUS P8H61-M
LX2 R2.0?

 

Baban: 

 

We have collected some guidelines in this document . "Signing UEFI
Applications and Drivers for UEFI Secure Boot"

http://sourceforge.net/projects/edk2/files/General%20Documentation/SigningUe
fiImages%20-v1dot0.pdf/download 

 

The problem may be the format of the certificate. Check and see if ASUS has
any guidance on what certificate format they use in setup.

 

Thanks ... br

---

Brian Richardson -- brian.richard...@intel.com -- Twitter: intel_brian

 

From: baban devkate [mailto:baban...@gmail.com] 
Sent: Monday, July 22, 2013 9:04 AM
To: edk2-devel@lists.sourceforge.net
Subject: [edk2] How to load self signed secure boot keys on ASUS P8H61-M LX2
R2.0?

 

Hello,

 

Unable to load cer/der/crt certificates generated using Openssl/makecert in
db, KEK and PK  on ASUS P8H61-M LX2 R2.0 system.

 

Any insertion is failing with 'failed!' error.

 

Any pointers will be great help.

 

Thanks,

Baban

 

Attachment: smime.p7s
Description: S/MIME cryptographic signature

------------------------------------------------------------------------------
See everything from the browser to the database with AppDynamics
Get end-to-end visibility with application monitoring from AppDynamics
Isolate bottlenecks and diagnose root cause in seconds.
Start your free trial of AppDynamics Pro today!
http://pubads.g.doubleclick.net/gampad/clk?id=48808831&iu=/4140/ostg.clktrk
_______________________________________________
edk2-devel mailing list
edk2-devel@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/edk2-devel

Reply via email to