On Mon, May 24, 2021 at 11:30:09PM -0000, VINAY RAJESH wrote:
> What about the scenario where the signers are different for kernel and
> grub? For example, if the kernel is signed using a self signed cert and
> loaded using MOK.

> I am trying to do that right now but the kernel fails to load when
> signed with a MOK key.

In that case, yes, the key in mok used for signing the kernel is supposed to
be measured in addition to the key used for signing grub.  But it sounds
like you're not getting to that point yet, if your kernel fails to load.

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1929454

Title:
  Bios measurements do not contain measurements for the kernel binary
  and kernel signer cert.

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/shim-signed/+bug/1929454/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to