Re: [PATCH 0/3] integrity: Load certs from EFI MOK config table

2020-09-04 Thread Lenny Szubowicz
On 8/26/20 7:55 AM, Mimi Zohar wrote: Hi Lenny, On Tue, 2020-08-25 at 23:44 -0400, Lenny Szubowicz wrote: Because of system-specific EFI firmware limitations, EFI volatile variables may not be capable of holding the required contents of the Machine Owner Key (MOK) certificate store. Therefore,

Re: [PATCH 0/3] integrity: Load certs from EFI MOK config table

2020-08-26 Thread Mimi Zohar
Hi Lenny, On Tue, 2020-08-25 at 23:44 -0400, Lenny Szubowicz wrote: > Because of system-specific EFI firmware limitations, > EFI volatile variables may not be capable of holding the > required contents of the Machine Owner Key (MOK) certificate > store. Therefore, an EFI boot loader may pass the

[PATCH 0/3] integrity: Load certs from EFI MOK config table

2020-08-25 Thread Lenny Szubowicz
Because of system-specific EFI firmware limitations, EFI volatile variables may not be capable of holding the required contents of the Machine Owner Key (MOK) certificate store. Therefore, an EFI boot loader may pass the MOK certs via a EFI configuration table created specifically for this purpose