** Description changed:

+ [Impact]
+ Re-enabling Secure Boot after DKMS packages are no longer needed is useful to 
benefit from the extra security afforded by having all bits of the bootloader 
and kernel signed by a proper key.
+ 
+ [Test Case]
+ (on a system with SHIM validation disabled)
+ 1- Remove all dkms modules
+ 2- Attempt to run 'sudo update-secureboot-policy --enable'
+ 3- Observe the behavior.
+ 
+ With the fixed update-secureboot-policy script, you should be prompted
+ to re-enable shim validation; which is otherwise skipped with no output
+ with previous versions of the script in shim-signed.
+ 
+ [Regression Potential]
+ Possible regression from this update would be changes to expected behavior of 
the update-secureboot-policy script; such as being unable to correctly 
recognize the current state of Secure Boot and shim validation, or incorrectly 
returning before prompting for the password required to toggle shim validation 
when the shim validation state make sense to be changed (ie. prompting to 
enable when it is disabled only, prompting to disable only if it's currently 
enabled). Any change in proper prompting in a debconf non-interactive context 
could also be a regression from this update.
+ 
+ ---
+ 
  If I have disabled secureboot on my system via update-secureboot-policy
  due to the presence of dkms modules, but subsequently remove these dkms
  modules because I decide I don't like not having secureboot, I cannot
  re-enable SB by running 'update-secureboot-policy --enable'.
  
  I think either the check for /var/lib/dkms should only apply when
  update-secureboot-policy is called without arguments, or this check
  should be encoded in the shim-signed postinst so that manual calls from
  the commandline DWIM.

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1673904

Title:
  update-secureboot-policy --enable does not work after dkms modules
  removed

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/shim-signed/+bug/1673904/+subscriptions

-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to