Re: [edk2] Authentication status for signed FVs extracted in PEI

2015-11-11 Thread Cohen, Eugene
> >Eugene > >-Original Message- >From: Kinney, Michael D [mailto:michael.d.kin...@intel.com] >Sent: Tuesday, November 10, 2015 12:54 PM >To: Cohen, Eugene <eug...@hp.com>; Gao, Liming <liming....@intel.com>; >Zeng, Star <star.z...@intel.com>;

Re: [edk2] Authentication status for signed FVs extracted in PEI

2015-11-10 Thread Cohen, Eugene
Cohen, Eugene <eug...@hp.com>; edk2-devel@lists.01.org Subject: RE: [edk2] Authentication status for signed FVs extracted in PEI Eugene: Another idea is to update FV HOB to include authentication status instead of adding FV HOB3. The consumer code can check FV HOB Length to know whe

Re: [edk2] Authentication status for signed FVs extracted in PEI

2015-11-10 Thread Kinney, Michael D
Behalf Of Cohen, >Eugene >Sent: Tuesday, November 10, 2015 7:12 AM >To: Gao, Liming; Zeng, Star; edk2-devel@lists.01.org >Subject: Re: [edk2] Authentication status for signed FVs extracted in PEI > >Liming and Star, > >Thanks for the suggestion for extending the FV HOB.

Re: [edk2] Authentication status for signed FVs extracted in PEI

2015-11-10 Thread Cohen, Eugene
ao, Liming <liming@intel.com>; Zeng, Star <star.z...@intel.com>; edk2-devel@lists.01.org; Kinney, Michael D <michael.d.kin...@intel.com> Subject: RE: [edk2] Authentication status for signed FVs extracted in PEI Eugene, I believe the current behavior is that only

Re: [edk2] Authentication status for signed FVs extracted in PEI

2015-11-10 Thread Zeng, Star
ay, November 9, 2015 9:03 PM To: edk2-devel@lists.01.org Subject: Re: [edk2] Authentication status for signed FVs extracted in PEI I raised this as an issue with PIWG. In the meantime feel free to provide some historical context for why this hasn't been an issue in other implementations. Tha

Re: [edk2] Authentication status for signed FVs extracted in PEI

2015-11-10 Thread Gao, Liming
@lists.01.org] On Behalf Of Zeng, > Star > Sent: Tuesday, November 10, 2015 6:19 PM > To: Cohen, Eugene; edk2-devel@lists.01.org > Subject: Re: [edk2] Authentication status for signed FVs extracted in PEI > > On 2015/11/9 21:57, Cohen, Eugene wrote: > > Star, > > &g

Re: [edk2] Authentication status for signed FVs extracted in PEI

2015-11-09 Thread Cohen, Eugene
To: edk2-devel@lists.01.org Subject: Re: [edk2] Authentication status for signed FVs extracted in PEI I raised this as an issue with PIWG. In the meantime feel free to provide some historical context for why this hasn't been an issue in other implementations. Thanks, Eugene -Original Me

Re: [edk2] Authentication status for signed FVs extracted in PEI

2015-11-09 Thread Zeng, Star
-devel@lists.01.org Subject: Re: [edk2] Authentication status for signed FVs extracted in PEI I raised this as an issue with PIWG. In the meantime feel free to provide some historical context for why this hasn't been an issue in other implementations. Thanks, Eugene -Original Message

Re: [edk2] Authentication status for signed FVs extracted in PEI

2015-11-09 Thread Cohen, Eugene
: Friday, November 06, 2015 5:49 PM To: edk2-devel@lists.01.org Cc: Thompson, Mark L. (Boise IPG) <mark.l.thomp...@hp.com> Subject: Re: [edk2] Authentication status for signed FVs extracted in PEI [Corrected the typos with a new version - proofreading is a good thing] I'm confused about som

Re: [edk2] Authentication status for signed FVs extracted in PEI

2015-11-06 Thread Cohen, Eugene
-devel-boun...@lists.01.org] On Behalf Of Cohen, Eugene Sent: Friday, November 06, 2015 11:12 AM To: edk2-devel@lists.01.org Cc: Thompson, Mark L. (Boise IPG) <mark.l.thomp...@hp.com> Subject: [edk2] Authentication status for signed FVs extracted in PEI I'm confused about something and hop

[edk2] Authentication status for signed FVs extracted in PEI

2015-11-06 Thread Cohen, Eugene
I'm confused about something and hope I can help some help understanding this. If we have a signed FV that is extracted in PEI it doesn't look like the AuthenticationStatus gets propagated to DXE. The hob doesn't store authentication status and the core products FVB with AuthenticationStatus