Skip to content

[Documentation]: Add instructions for signing the files (via signtool, etc.) #233

@miketheitguy

Description

@miketheitguy

Request Description

This might be out of scope here, but either a script or some documentation on signing the secure boot files could be useful.

I've been evaluating using this repo and scripts to:

  • Manually update my systems to avoid CVE-2023-24932. Basically to accelerate the enforcement phase for CVE-2023-24932 of our systems out of the box. This includes the entire mitigation process as automated signed files (custom PK/KEK)
  • Custom Secure Boot Key integration (PK + KEK + DB)
  • I'll include the vendor keys as-needed

So having some sort of end-to-end process to do all of this would be fantastic :)

My plan is to integrate this into an entire pipeline for our systems.

Are you going to make the change?

I will make the change

Do you need maintainer feedback?

No maintainer feedback needed

Anything else?

No response

Metadata

Metadata

Assignees

Labels

state:needs-triageNeeds to triaged to determine next stepstype:documentationImprovements or additions to documentation

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions