-
Notifications
You must be signed in to change notification settings - Fork 52
Closed
Labels
state:needs-triageNeeds to triaged to determine next stepsNeeds to triaged to determine next stepstype:documentationImprovements or additions to documentationImprovements or additions to documentation
Description
Request Description
This might be out of scope here, but either a script or some documentation on signing the secure boot files could be useful.
I've been evaluating using this repo and scripts to:
- Manually update my systems to avoid CVE-2023-24932. Basically to accelerate the enforcement phase for CVE-2023-24932 of our systems out of the box. This includes the entire mitigation process as automated signed files (custom PK/KEK)
- Custom Secure Boot Key integration (PK + KEK + DB)
- I'll include the vendor keys as-needed
So having some sort of end-to-end process to do all of this would be fantastic :)
My plan is to integrate this into an entire pipeline for our systems.
Are you going to make the change?
I will make the change
Do you need maintainer feedback?
No maintainer feedback needed
Anything else?
No response
Metadata
Metadata
Assignees
Labels
state:needs-triageNeeds to triaged to determine next stepsNeeds to triaged to determine next stepstype:documentationImprovements or additions to documentationImprovements or additions to documentation