Re: [RFC] efi_loader: improve firmware capsule authentication

2021-05-09 Thread AKASHI Takahiro
On Fri, May 07, 2021 at 08:47:28PM +0200, Heinrich Schuchardt wrote: > On 5/7/21 6:29 AM, AKASHI Takahiro wrote: > > Heinrich, > > > > On Mon, Apr 26, 2021 at 11:44:59AM +0900, AKASHI Takahiro wrote: > > > Heinrich, > > > > > > Do you have any comments? > > > # not only on this issue, but also

Re: [RFC] efi_loader: improve firmware capsule authentication

2021-05-07 Thread Heinrich Schuchardt
On 5/7/21 6:29 AM, AKASHI Takahiro wrote: Heinrich, On Mon, Apr 26, 2021 at 11:44:59AM +0900, AKASHI Takahiro wrote: Heinrich, Do you have any comments? # not only on this issue, but also other issues that I pointed out # in the initial RFC. Ping? -Takahiro Akashi I would prefer if you

Re: [RFC] efi_loader: improve firmware capsule authentication

2021-05-06 Thread AKASHI Takahiro
Heinrich, On Mon, Apr 26, 2021 at 11:44:59AM +0900, AKASHI Takahiro wrote: > Heinrich, > > Do you have any comments? > # not only on this issue, but also other issues that I pointed out > # in the initial RFC. Ping? -Takahiro Akashi > On Fri, Apr 23, 2021 at 02:38:09PM +0530, Sughosh Ganu

Re: [RFC] efi_loader: improve firmware capsule authentication

2021-04-25 Thread AKASHI Takahiro
Heinrich, Do you have any comments? # not only on this issue, but also other issues that I pointed out # in the initial RFC. On Fri, Apr 23, 2021 at 02:38:09PM +0530, Sughosh Ganu wrote: > Takahiro, > > On Fri, 23 Apr 2021 at 12:30, AKASHI Takahiro > wrote: > > > Sughosh, > > > > On Fri, Apr

Re: [RFC] efi_loader: improve firmware capsule authentication

2021-04-23 Thread Sughosh Ganu
Takahiro, On Fri, 23 Apr 2021 at 12:30, AKASHI Takahiro wrote: > Sughosh, > > On Fri, Apr 23, 2021 at 11:55:04AM +0530, Sughosh Ganu wrote: > > Takahiro, > > > > On Fri, 23 Apr 2021 at 11:17, AKASHI Takahiro < > takahiro.aka...@linaro.org> > > wrote: > > > > > Heinrich, > > > > > > I'm

Re: [RFC] efi_loader: improve firmware capsule authentication

2021-04-23 Thread Ilias Apalodimas
On Fri, Apr 23, 2021 at 04:50:21PM +0900, AKASHI Takahiro wrote: > On Fri, Apr 23, 2021 at 10:21:52AM +0300, Ilias Apalodimas wrote: > > Akashi-san > > > > [...] > > > 7) Pytest is broken > > >Due to your and Ilias' recent patches, existing pytests for > > >secure boot as well as capsule

Re: [RFC] efi_loader: improve firmware capsule authentication

2021-04-23 Thread AKASHI Takahiro
On Fri, Apr 23, 2021 at 10:21:52AM +0300, Ilias Apalodimas wrote: > Akashi-san > > [...] > > 7) Pytest is broken > >Due to your and Ilias' recent patches, existing pytests for > >secure boot as well as capsule update are now broken. > >I'm not sure why you have not yet noticed. > >

Re: [RFC] efi_loader: improve firmware capsule authentication

2021-04-23 Thread Ilias Apalodimas
Akashi-san [...] > 7) Pytest is broken >Due to your and Ilias' recent patches, existing pytests for >secure boot as well as capsule update are now broken. >I'm not sure why you have not yet noticed. >Presumably, Travis CI now skips those tests? I can have a look on that. Any idea

Re: [RFC] efi_loader: improve firmware capsule authentication

2021-04-23 Thread AKASHI Takahiro
Sughosh, On Fri, Apr 23, 2021 at 11:55:04AM +0530, Sughosh Ganu wrote: > Takahiro, > > On Fri, 23 Apr 2021 at 11:17, AKASHI Takahiro > wrote: > > > Heinrich, > > > > I'm currently thinking of improving capsule authentication > > that Sughosh has made, particularly around mkeficapsule command:

Re: [RFC] efi_loader: improve firmware capsule authentication

2021-04-23 Thread Sughosh Ganu
Takahiro, On Fri, 23 Apr 2021 at 11:17, AKASHI Takahiro wrote: > Heinrich, > > I'm currently thinking of improving capsule authentication > that Sughosh has made, particularly around mkeficapsule command: > > 1) Add a signing feature to the command >This will allow us to create a *signed*

[RFC] efi_loader: improve firmware capsule authentication

2021-04-22 Thread AKASHI Takahiro
Heinrich, I'm currently thinking of improving capsule authentication that Sughosh has made, particularly around mkeficapsule command: 1) Add a signing feature to the command This will allow us to create a *signed* capsule file solely with mkeficapsule. We will no longer rely on EDK2's