Re: [Xen-devel] [Xen-users] UEFI Secure Boot Xen 4.9

2017-10-13 Thread Daniel Kiper
On Thu, Oct 12, 2017 at 05:03:13PM +, Bill Jacobs (billjac) wrote: > Hi > What is the status of creating a shim to abstract secure boot > signing for Xen (to leverage MSFT 3rd party, e.g)? xen.efi works with shim itself out of the box. If you wish to use shim and GRUB2 to load Xen you have to

Re: [Xen-devel] [Xen-users] UEFI Secure Boot Xen 4.9

2017-10-12 Thread Bill Jacobs (billjac)
Hi What is the status of creating a shim to abstract secure boot signing for Xen (to leverage MSFT 3rd party, e.g)? Thanks -Bill > -Original Message- > From: Daniel Kiper [mailto:daniel.ki...@oracle.com] > Sent: Tuesday, May 16, 2017 4:05 AM > To: Bill Jacobs (billjac)

Re: [Xen-devel] [Xen-users] UEFI Secure Boot Xen 4.9

2017-09-19 Thread Daniel Kiper
On Mon, Sep 18, 2017 at 11:24:15AM -0400, Tamas K Lengyel wrote: > On Tue, Sep 5, 2017 at 12:26 PM, Tamas K Lengyel > wrote: > > On Mon, Sep 4, 2017 at 6:40 AM, Daniel Kiper > > wrote: > >> On Wed, Aug 30, 2017 at 10:16:23AM -0600, Tamas K

Re: [Xen-devel] [Xen-users] UEFI Secure Boot Xen 4.9

2017-09-18 Thread Tamas K Lengyel
On Tue, Sep 5, 2017 at 12:26 PM, Tamas K Lengyel wrote: > On Mon, Sep 4, 2017 at 6:40 AM, Daniel Kiper wrote: >> On Wed, Aug 30, 2017 at 10:16:23AM -0600, Tamas K Lengyel wrote: >>> On Tue, Aug 29, 2017 at 2:01 PM, Daniel Kiper

Re: [Xen-devel] [Xen-users] UEFI Secure Boot Xen 4.9

2017-09-05 Thread Tamas K Lengyel
On Mon, Sep 4, 2017 at 6:40 AM, Daniel Kiper wrote: > On Wed, Aug 30, 2017 at 10:16:23AM -0600, Tamas K Lengyel wrote: >> On Tue, Aug 29, 2017 at 2:01 PM, Daniel Kiper >> wrote: >> > Hey Tamas, >> > >> > Sorry for late reply. I was on vacation.

Re: [Xen-devel] [Xen-users] UEFI Secure Boot Xen 4.9

2017-09-04 Thread Daniel Kiper
On Wed, Aug 30, 2017 at 10:16:23AM -0600, Tamas K Lengyel wrote: > On Tue, Aug 29, 2017 at 2:01 PM, Daniel Kiper wrote: > > Hey Tamas, > > > > Sorry for late reply. I was on vacation. > > > > On Tue, Aug 22, 2017 at 09:01:06PM -0600, Tamas K Lengyel wrote: > >> On Tue,

Re: [Xen-devel] [Xen-users] UEFI Secure Boot Xen 4.9

2017-08-30 Thread Tamas K Lengyel
On Tue, Aug 29, 2017 at 2:01 PM, Daniel Kiper wrote: > Hey Tamas, > > Sorry for late reply. I was on vacation. > > On Tue, Aug 22, 2017 at 09:01:06PM -0600, Tamas K Lengyel wrote: >> On Tue, May 16, 2017 at 5:04 AM, Daniel Kiper >> wrote: > >

Re: [Xen-devel] [Xen-users] UEFI Secure Boot Xen 4.9

2017-08-29 Thread Daniel Kiper
Hey Tamas, Sorry for late reply. I was on vacation. On Tue, Aug 22, 2017 at 09:01:06PM -0600, Tamas K Lengyel wrote: > On Tue, May 16, 2017 at 5:04 AM, Daniel Kiper wrote: [...] > > UEFI will verify shim secure boot signature then shim will verify GRUB2 > > signature

Re: [Xen-devel] [Xen-users] UEFI Secure Boot Xen 4.9

2017-08-22 Thread Tamas K Lengyel
On Tue, May 16, 2017 at 5:04 AM, Daniel Kiper wrote: > On Mon, May 15, 2017 at 07:09:54PM +, Bill Jacobs (billjac) wrote: >> > -Original Message- >> > From: Daniel Kiper [mailto:daniel.ki...@oracle.com] >> > Sent: Monday, May 15, 2017 6:13 AM >> > To: Bill

Re: [Xen-devel] [Xen-users] UEFI Secure Boot Xen 4.9

2017-05-16 Thread Daniel Kiper
On Mon, May 15, 2017 at 07:09:54PM +, Bill Jacobs (billjac) wrote: > > -Original Message- > > From: Daniel Kiper [mailto:daniel.ki...@oracle.com] > > Sent: Monday, May 15, 2017 6:13 AM > > To: Bill Jacobs (billjac) ; george.dun...@citrix.com > > Cc:

Re: [Xen-devel] [Xen-users] UEFI Secure Boot Xen 4.9

2017-05-15 Thread Bill Jacobs (billjac)
> -Original Message- > From: Daniel Kiper [mailto:daniel.ki...@oracle.com] > Sent: Monday, May 15, 2017 6:13 AM > To: Bill Jacobs (billjac) ; george.dun...@citrix.com > Cc: xen-devel@lists.xen.org; xen-us...@lists.xen.org > Subject: Re: [Xen-users] UEFI Secure Boot Xen

Re: [Xen-devel] [Xen-users] UEFI Secure Boot Xen 4.9

2017-05-15 Thread Daniel Kiper
Hey, CC-ing Xen-devel to spread some knowledge about the issue. On Mon, May 15, 2017 at 10:42:23AM +0100, George Dunlap wrote: > On Wed, May 10, 2017 at 11:36 PM, Bill Jacobs (billjac) > wrote: > > Hi all > > > > I gather that with 4.9, UEFI secure boot of Xen should be