Re: BootGuard policy decoder?
Maciej Pijanowski <[email protected]>
| Newsgroups | gmane.linux.bios |
|---|---|
| Message-ID | <[email protected]> |
On 3/17/24 20:00, Christian Walter wrote: > > Hi, > > I checked the M720q image with the Convered Security Suite: Even > though it has a BPM and KM FIT entry (which is necessary for > Bootguard), both have the size 0, and I am not able to extract those > properly. KM's normally have a __KEYM__ string in it - I can not find > those in the M720Q image. > > All that would lead me to the assumption that at least the image I > checked for the M720Q does not have Bootguard enabled - but I could be > wrong ;) > > Chris > > On 3/17/24 02:03, mr gadha via coreboot wrote: >> I have a Lenovo m710q and also a m720q (b360 south bridge) According to the tool, looks like neither have BootGuard enabled. >> >> However inteltool didn’t identify (by name) the northbridges. Not yet sure if this is a bad omen… >> >> I don’t have a serial port or SOIC clip, but was thinking of getting them. >> >> Does anyone ever use the existing PEI code and boot coreboot with that? Or is going all the way on a new platform practical ? I have m920q, it does not have IBG enabled. I have sent some patches [1]. I expect the m720q will be similar to the m920q, in the same way as the m700 is similar to m900. The main (only?) difference is the PCH. [1] https://review.coreboot.org/c/coreboot/+/80609 >> >> >>> On Mar 15, 2024, at 11:46 PM, Nicholas Chin<[email protected]> wrote: >>> >>> On 2024-03-15 22:24, mr gadha via coreboot wrote: >>>> Are there any known tools for decoding the BootGuard policy? >>>> I’m new to coreboot but have a system that I was interested in investigating adding support for it. >>> Hello! Welcome to coreboot! We look forward to any future contributions from you. There is the util/intelmetool utility in coreboot's source, which has a -b flag which is supposed to indicate the bootguard status. There's also some instructions for using it here:https://felixsinger.github.io/bootguard-status/ >>> >>> There's also a tool called MEInfo, which is an official tool from Intel and thus should be the most reliably accurate way of determining the BootGuard configuration. It is not supposed to be publicly available, but may or may not be possible to find on the internet anyway ;). >>> >>> By the way, which system are you looking into? >>> >>>> The flash image has BootGuard signatures, but at least some parts of the UEFI area of the flash are modifiable (variables, logo, etc). I’m wondering if the DXE area is even protected at all… >>>> Or does one just abandon any attempt as soon as a BootGuard header is seen? >>> The presence of BootGuard signatures in the ROM does not necessarily mean BootGuard is actually enabled in the chipset, so no need to abandon an attempt immediately upon seeing that. >>> >>> Cheers, >>> Nicholas >>> _______________________________________________ >>> coreboot mailing list [email protected] >>> To unsubscribe send an email [email protected] >> _______________________________________________ >> coreboot mailing list [email protected] >> To unsubscribe send an email [email protected] > -- > *Christian Walter* > *Head of Firmware Development / Cyber Security * > > > > 9elements GmbH, Kortumstraße 19-21, 44787 Bochum, Germany > Email: [email protected] > Phone: _+49 234 68 94 188 <tel:+492346894188>_ > Mobile: _+49 176 70845047 <tel:+4917670845047>_ > > Sitz der Gesellschaft: Bochum > Handelsregister: Amtsgericht Bochum, HRB 17519 > Geschäftsführung: Sebastian Deutsch, Eray Basar > > Datenschutzhinweise nach Art. 13 DSGVO <https://9elements.com/privacy> > > _______________________________________________ > coreboot mailing list -- [email protected] > To unsubscribe send an email to [email protected] -- Maciej Pijanowski Engineering Manager GPG: 9963C36AAC3B2B46 https://3mdeb.com | @3mdeb_com _______________________________________________ coreboot mailing list -- [email protected] To unsubscribe send an email to [email protected]
OpenPGP_0x9963C36AAC3B2B46.asc
(application/pgp-keys, 3.1 KB)
-----BEGIN PGP PUBLIC KEY BLOCK----- xsFNBF4qlhoBEADgl4uab157tPQOtWEBaEyHzMllmAumP+XQokz180AXQY8Pxrbx Kqso4UTZYbGXza3AL9R0Trk5TJMmjRf3DJMBx79kbdVo1nF/jGihz0QJwjR+KI5S SA+veuPGeSckF1Liv3cKkS+meiRdc+hsUzT4Qx7buQSj+1tTlG7WHanUTHJp9nE2 iKnf5RSy4TeEcfJcBOZOkcjgAY5aHXbNITpfhRZAlhaXe+0uafumfMX9QYqOyv2D FeT0xwQphBwe/UzEADZxXTcSSMlpA+AaRAHGYo8OucZBxIHxKPb/s5ISVf+tT3do dDoxvODfOaprFMIuoxznpiARLYJARvvRIRypcL1ye9Lln4lKIgpk0iqXoG9swRrD Vch81yPpw04YAtqXGdVZ4GhXpS2OOAAqXuF0lXU0kTcI6tSEDiuJy9NMQa1A10vf HkaIL4BmdH9QZuBrym6KR+B9dkkobRie1AJuyM0V6kSbtN7C3+OABbyTUQ1IILDO wPusTh+0moI8FoC3O17PoFP+cvoy7jB7oanicWZamg24jurVmF5Z2cs/+0zzrnyf TCHP71IviWCodWR+qm0vbDbPzMfsGc8fmxpSiKL9x3xJgfeykkOfD1//gnuZw+2F NaK14wJPs8UpxRPlCce3R0YnpEsBKI1vlpRXMgJPiTXGmC7tdwkx2CT9TQARAQAB zS9NYWNpZWogUGlqYW5vd3NraSA8bWFjaWVqLnBpamFub3dza2lAM21kZWIuY29t PsLBjgQTAQgAOBYhBKdmyJVpiVwLhtWY0Jljw2qsOytGBQJeKpYaAhsDBQsJCAcC BhUKCQgLAgQWAgMBAh4BAheAAAoJEJljw2qsOytGt+UP/0q68qgYQwilMM5v1Zte Xovb8FRoYPEmH53XCUyOKWV4JgtAfm0SrxvZE+wTJYTrjwcm9NKpxdjRmPIkUcH3 m0CJFUN71sez50OZbmNh/Yy1lu25Tst520RMEPXVv7IBmytL28rhUK47bIh9z+Mp WxctGeB2SVIWJfNUOifI3k14YKiyEXoExGVLTH/QrMvTfCm9rkky3kid6OSrqqC9 uVCO5R889g6jo7J3Gqe2IUxxIZ5BOyL/+Z8AMKIqWy8nmQ35wgy44f0jiFLUQNC2 rdbS9/JEPZtQZjZ2TBCPsC8UQcAZLBT2iQYx9VD/2vr6aHQUTZ5qvmJKPMo96pP+ +TKn8oClOqjmZfOdsh6zDTUnlENDCsbRHEJIWWzofywyOqDUhZXhCNbzE0fsMAt3 rY4PbPnuD0dmcfbFeasltBjYS704e+Uig/o/UTcVAJmypreB68eJbLjGElGheGyY FuluXi6VGM4uGNGElbl7lbKfKVml0sgULXl9f+4eML8TKOHKNUhMWqnkx5WSbOxO BiSEW+gBFZHMrkhspP3RXj9ESYpJ2irxrJzPQCFMF7D5kXm9OSrBRDFA+yYxZSj0 p6pFVBGDdIlZ/qJcfh5azoSNI0KKbUvGDJ0mnM7OmehAafGNo/eLwwQeAJOnw8yQ nIDUutZHZ9Z1v3WBFtslO5i+zsFNBF4qlhoBEACzCtn7Eh+SNFP5kQUI2QvyiIxL plFtLYr8Mmnk+c/TyXIvyttmRRNqC1eo5jwui36HIlK/EVlQ3khNgm3FP9YbASbu +eDXWGrXd6CkYWkmO8VdB1L8e9ml+tzqsKtm31vjxBrvV7RzzFumA14pOfuSkeZE ZxZAy0fdjp5JeeiUd5LIdZrqZatKtGV4R2KBgfXE0LxHeSo6Q3PdJ2vmkGEL9AOV ESP4e6KCj7NS7drzEvy5LqvqPt56qK+tlFzQEvNwObTXjF+DbNzf5ooyrcDl6xOq +Xt0ReK0VPe/fVZ/gSFF2kwXt2LLOR/UFcKHS+pfEYwwy2kkfz8NLV/So8M0fk1Z c82S8a8726WPQW23UKJz9UtVLG1V8tTVfavfl9pFW1KBkToexPruTsR9rxDB/BFS 7hYxcn70GqInWGPR8ca58m+8mtDJuPcE4u/UeQy1zj20Gb0fSXhgfUt0bKnYJPMQ HAdtsEw9vWZswSUDpZvtvYjViRdBePfo+NPO2TLXA9l4ZYZM8d2lkvI+wz7HpvqS VmQ/56/xvwBHHuckVJyeYbT02tLt2hyXoL5j5Ql7sBOHIeMvwJ8QJVTJXDXGXqM/ 9aSVGbnXROXetf4a8rmedxdruFReRffmPBiQhJYWNrJxfzhvS/gA17uKqfK2eCym HVahCtIaZPCC5ZjOWQARAQABwsF2BBgBCAAgFiEEp2bIlWmJXAuG1ZjQmWPDaqw7 K0YFAl4qlhoCGwwACgkQmWPDaqw7K0YgWQ/+OuLUmvZYQdRvIEpK4C95vJ1khVJQ HtotKcRUbQpTrEtGxj8/he8L/La53/SsHhXuwNRw7imeyDHOlAUxN6CnQiwjI6FW 8ocb8GkPFw8fsZ9Lne4ZMr/y5WFM/iGleZtAl7Kul5ddVQMmGrqGPaD+ldY5B3NC h8AmZSzeFzx6PO7eqUZ23yLvJOLkY7PauDmTMaXYy0JwndjhTiQKEkzSki9cOeC0 5n+kWcLcA8i/WI7rMOYyR5+2yIcQF37fFr6nFSvWSDmklITQdSUOP39LSIkltDci b2DNdCni+Vyz7T5rkQiX5k3HYeav/odiio3PhjtEDWNEhMtYHcmOpTftRRZasZPe xAWzDg3VzEZqtdLi9nJB26mg+1CmU5v0VCCV37Q8zhAAFg134+7A5sItCkr46Hy8 zNOWxcx+drgVDVmOqrvxQV24JXWFKhROPlMxXEcrdYwyEa62aAzTA6t/kQy1vSZS RcdXXlQd49rtohphFcRgH7pXgOOClNy5X3mn2sYg4nfaxq88LPsjXsagf3nd0ZCS KmjEiGJg5MzrsMYdfNdhm42QhhkgsvrVoUDO+1DwQqvUYPCdyRHyfWAEnKKHTuNK 1lYISSDrWxhhR0bmwki5Lz3NKC1jgXlOLZGF4GOR4+UZoRlUCJcx9hgyZll4XNRs wMDsCZKkPKx8jYw= =0QS1 -----END PGP PUBLIC KEY BLOCK-----
OpenPGP_signature.asc
(application/pgp-signature, 840 B)
-----BEGIN PGP SIGNATURE----- wsF5BAABCAAjFiEEp2bIlWmJXAuG1ZjQmWPDaqw7K0YFAmX6pgQFAwAAAAAACgkQmWPDaqw7K0Zm cBAAqeVOzMSwTskD99jEbnQkZWJke2XPoZvjI05060WbTIxsjK1GbIRmQyWEThE8EHqUVGwrvHr8 cbviKju+RNojC6UpzvklkKn9hgsHXLDwUc1SWMjvKk+GV6mpKYaqPXytuMQp2nQbOKDd3+Ua6o8+ nQCUFN+H0vAMThImeGk6G9zJ74kYK+r5sLcGQJli6lR9iq9kcFF1pGXfrYaBxuGzvGkLqs2WBAQU +9IeZI+iJKsFkO1D26L5Q3JjULh4nszRmq0KeTPZG3H0WDohmzM8uJyUSwDScr8sVlJ2Nals+0vr YU8fbvhEvnDXtALMJFTtUnHrb4nT9XOC/88iYurEdP2j5oPzczjFlViTQPk9WAYYym/umKaLn89K 8A/WxIYky95vCnjXT1IB0VieqXH9NHNr1fjvjnfWVV0lM49n29q7hGa07PdVFMqbn0zbf1/8Bqzy s45O8GbG1tw053LSFoNqr99/1fY5oUw7KdfTofjNCAiu9QFtq8GPUucCs5FwiQ0IS7tBN5XGV6mf fiknShrH/z09RHKykf0231zY9HW8ypeXyAdd8UJF8dj1l2Bqe5tzDZAwuQCpc0l7iK/rEDXViakY XGjB4QDun0o8oF4VOw5JPoI4hAEzLERWFxXMnXEmv1GGYDfqsz4KK9QpxARpM5oXK29j1WumP0AD fp4= =qqly -----END PGP SIGNATURE-----