Re: Re: [security-announce] Heads up: "BootHole" security issue

Marcus Meissner <[email protected]> Sat, 1 Aug 2020 08:14:13 +0200
Newsgroups gmane.linux.suse.security
Organization SUSE Software Solutions Ger many GmbH, Maxfeldstr. 5, 90409 Nuernberg, Germany , GF: Felix Imendörffer, HRB 36809, AG Nürnber g
Message-ID <[email protected]>
Hi,

On Fri, Jul 31, 2020 at 10:30:47PM +0200, [email protected] wrote:
> Am 30.07.20 um 15:10 schrieb Marcus Meissner:
> >> (......)
> >> will stay unchanged?
> > 
> > Yes, the openSUSE Secure Boot CA will stay unchanged.
> >  
> >> Is the new key available for download somewhere?
> >> I have my own set of PK/KEK and import such keys usually manually.
> > 
> > We still need to generate the new key, we need to wait until the fixed grub2
> > has been checked into openSUSE:Factory first to avoid having it signed by the new key.
> > 
> > I will send it as reply  as soon as its available.
> 
> Out of curiousity, what toolchain do you use to create/handle secure
> boot keys?

The signing itself is done by the open build service in the background.
 
> sbsigntools and efitools have never been part of any official SUSE repo.
> Lucky, the author of these tools has his own repo.

We use the "pesign" toolset, from here https://github.com/rhboot/pesign
 
> My dear, you use M$ Windoze to handle secure boot keys, right?

No, and your tone is uncalled for.

Ciao, Marcus
-- 
To unsubscribe, e-mail: [email protected]
To contact the owner, e-mail: [email protected]