Re: [U-Boot] EFIBootGuard for CIP and SecureBoot

2019-05-01 Thread Peter Jones
On Sat, Apr 27, 2019 at 09:56:08AM +0200, Alexander Graf wrote: > > >>> UEFI gets a bad rap at being complicated, but I think the U-Boot work > >>> has shown that implementing the core UEFI ABI doesn't require much code > >>> and isn't the complicated mess they everyone fears it to be. > >>

Re: [U-Boot] EFIBootGuard for CIP and SecureBoot

2019-04-27 Thread Alexander Graf
On 26.04.19 15:46, Heinrich Schuchardt wrote: > > On 4/26/19 1:21 PM, Jan Kiszka wrote: >> On 26.04.19 12:21, Grant Likely wrote: >>> On 26/04/2019 10:49, Jan Kiszka wrote: On 26.04.19 11:07, Francois Ozog wrote: >>> [...] > Here are the guiding principles of our efforts : > 0) we

Re: [U-Boot] EFIBootGuard for CIP and SecureBoot

2019-04-26 Thread Heinrich Schuchardt
On 4/26/19 1:21 PM, Jan Kiszka wrote: > On 26.04.19 12:21, Grant Likely wrote: >> On 26/04/2019 10:49, Jan Kiszka wrote: >>> On 26.04.19 11:07, Francois Ozog wrote: >> [...] Here are the guiding principles of our efforts : 0) we want a cross architecture (x86/Arm/...), cross vendor and

Re: [U-Boot] EFIBootGuard for CIP and SecureBoot

2019-04-26 Thread Francois Ozog
On Fri, 26 Apr 2019 at 11:49, Jan Kiszka wrote: > On 26.04.19 11:07, Francois Ozog wrote: > > On Fri, 26 Apr 2019 at 10:30, Christian Storm > > wrote: > >> > >> Hi, > >> > > Background: during the last Linaro connect in Bangkok I was told > > that Linaro Edge (LEDGE) were working on a

Re: [U-Boot] EFIBootGuard for CIP and SecureBoot

2019-04-26 Thread Jan Kiszka
On 26.04.19 12:21, Grant Likely wrote: On 26/04/2019 10:49, Jan Kiszka wrote: On 26.04.19 11:07, Francois Ozog wrote: [...] Here are the guiding principles of our efforts : 0) we want a cross architecture (x86/Arm/...), cross vendor and cross processor model update solution 1) untrusted world

Re: [U-Boot] EFIBootGuard for CIP and SecureBoot

2019-04-26 Thread Francois Ozog
- team-le...@linaro.org as it is now a public discussion On Fri, 26 Apr 2019 at 12:21, Grant Likely wrote: > On 26/04/2019 10:49, Jan Kiszka wrote: > > On 26.04.19 11:07, Francois Ozog wrote: > [...] > >> Here are the guiding principles of our efforts : > >> 0) we want a cross architecture

Re: [U-Boot] EFIBootGuard for CIP and SecureBoot

2019-04-26 Thread Christian Storm
Hi, > > > Background: during the last Linaro connect in Bangkok I was told > > > that Linaro Edge (LEDGE) were working on a secure software update > > > mechanism based on UEFI capsules that would flash firmware updates > > > from a UEFI application, instead of using a Linux agent such as > > >

Re: [U-Boot] EFIBootGuard for CIP and SecureBoot

2019-04-26 Thread Francois Ozog
On Fri, 26 Apr 2019 at 10:30, Christian Storm wrote: > > Hi, > > > > > Background: during the last Linaro connect in Bangkok I was told > > > > that Linaro Edge (LEDGE) were working on a secure software update > > > > mechanism based on UEFI capsules that would flash firmware updates > > > > from

Re: [U-Boot] EFIBootGuard for CIP and SecureBoot

2019-04-26 Thread daniel.sangorrin
Hi Jan, Francois: Grant: thanks! > From: Jan Kiszka > On 24.04.19 03:23, daniel.sangor...@toshiba.co.jp wrote: > > Hello Francois, Jan, Christian, and all > > EFI Boot Guard is now shipped in quite a few devices, to my knowledge not > > only at > > Sorry for the late reply, I was waiting for

Re: [U-Boot] EFIBootGuard for CIP and SecureBoot

2019-04-26 Thread Grant Likely
On 26/04/2019 10:49, Jan Kiszka wrote: > On 26.04.19 11:07, Francois Ozog wrote: [...] >> Here are the guiding principles of our efforts : >> 0) we want a cross architecture (x86/Arm/...), cross vendor and cross >> processor model update solution >> 1) untrusted world cannot update trusted world >

Re: [U-Boot] EFIBootGuard for CIP and SecureBoot

2019-04-26 Thread Jan Kiszka
On 26.04.19 11:07, Francois Ozog wrote: On Fri, 26 Apr 2019 at 10:30, Christian Storm wrote: Hi, Background: during the last Linaro connect in Bangkok I was told that Linaro Edge (LEDGE) were working on a secure software update mechanism based on UEFI capsules that would flash firmware

Re: [U-Boot] EFIBootGuard for CIP and SecureBoot

2019-04-24 Thread Grant Likely
On 24/04/2019 02:23, daniel.sangor...@toshiba.co.jp wrote: > Hello Francois, Jan, Christian, and all > > Sorry for the late reply, I was waiting for the administrator of the Boot > Architecture mailing list to accept my subscription request, but it seems it > will take a bit more time. I will

Re: [U-Boot] EFIBootGuard for CIP and SecureBoot

2019-04-24 Thread Jan Kiszka
[prolonging the CCs with the efibootguard mailing list] On 24.04.19 03:23, daniel.sangor...@toshiba.co.jp wrote: Hello Francois, Jan, Christian, and all EFI Boot Guard is now shipped in quite a few devices, to my knowledge not only at Sorry for the late reply, I was waiting for the

Re: [U-Boot] EFIBootGuard for CIP and SecureBoot

2019-04-23 Thread daniel.sangorrin
Hello Francois, Jan, Christian, and all Sorry for the late reply, I was waiting for the administrator of the Boot Architecture mailing list to accept my subscription request, but it seems it will take a bit more time. I will send this reply and hope it will not be blocked. I have also added