Re: Re: [security-announce] Heads up: "BootHole" security issue
Marcus Meissner <[email protected]> Mon, 3 Aug 2020 16:56:39 +0200
| Newsgroups | gmane.linux.suse.security |
|---|---|
| Organization | SUSE Software Solutions Ger many GmbH, Maxfeldstr. 5, 90409 Nuernberg, Germany , GF: Felix Imendörffer, HRB 36809, AG Nürnber g |
| Message-ID | <[email protected]> |
--dTy3Mrz/UPE2dbVg Content-Type: multipart/mixed; boundary="IS0zKkzwUGydFO0o" Content-Disposition: inline --IS0zKkzwUGydFO0o Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Content-Transfer-Encoding: quoted-printable On Sun, Aug 02, 2020 at 08:30:26AM +0200, Marcus Meissner wrote: > On Sat, Aug 01, 2020 at 01:50:56PM -0700, Lew Wolfgang wrote: > > On 07/31/2020 11:14 PM, Marcus Meissner wrote: > > > On Fri, Jul 31, 2020 at 10:30:47PM +0200, [email protected] wro= te: > > > > Am 30.07.20 um 15:10 schrieb Marcus Meissner: > > > > > > (......) > > > > > > will stay unchanged? > > > > > Yes, the openSUSE Secure Boot CA will stay unchanged. > > > > > > Is the new key available for download somewhere? > > > > > > I have my own set of PK/KEK and import such keys usually manual= ly. > > > > > We still need to generate the new key, we need to wait until the = fixed grub2 > > > > > has been checked into openSUSE:Factory first to avoid having it s= igned by the new key. > > > > >=20 > > > > > I will send it as reply as soon as its available. > > > > Out of curiousity, what toolchain do you use to create/handle secure > > > > boot keys? > > > The signing itself is done by the open build service in the backgroun= d. > > > > sbsigntools and efitools have never been part of any official SUSE = repo. > > > > Lucky, the author of these tools has his own repo. > > > We use the "pesign" toolset, from here https://github.com/rhboot/pesi= gn > >=20 > > Ars Technica is reporting boot failures after the BootHole patch is > > installed > > on Red Hat, CentOS, Ubuntu, Debian and maybe others. > >=20 > > https://arstechnica.com/gadgets/2020/07/red-hat-and-centos-systems-aren= t-booting-due-to-boothole-patches/ >=20 > As far as I understand they backported a buggy optional patch. >=20 > We only backported mandatory patches from the patchset. > =20 > > Did the openSUSE patch get delayed because of the key id issue mentioned > > here: > >=20 > > https://lists.opensuse.org/opensuse-security/2020-07/msg00001.html >=20 > Yes.=20 >=20 > We need to make sure that the buggy insecure old grub2 is not built with = the new key. >=20 > As the fixed grub2 package is now checked into factory, we will create a = new signing key,=20 > and then start delivering updates, both Tumbleweed and also for Leap. Update: The openSUSE signing key was rotated today. - tumbleweed is already rebuilding all secure boot relevant packages for th= eir next snapshot. - leap maintenance we pushed grub2 to QA, also 15.1 kernel. ... More packag= es will follow in the next days. The replacement of shim will only happen after we fixed everything. (Tumble= weed earlier than Leap ;) Ciao, Marcus --IS0zKkzwUGydFO0o Content-Type: application/x-x509-ca-cert Content-Disposition: attachment; filename="opensuse-new-signing-cert-202007.crt" Content-Transfer-Encoding: quoted-printable -----BEGIN CERTIFICATE-----=0AMIIElTCCA32gAwIBAgIJAPq+2L9Aml5jMA0GCSqGSIb3D= QEBCwUAMIGBMSAwHgYD=0AVQQDDBdvcGVuU1VTRSBTZWN1cmUgQm9vdCBDQTELMAkGA1UEBhMCR= EUxEjAQBgNV=0ABAcMCU51cmVtYmVyZzEZMBcGA1UECgwQb3BlblNVU0UgUHJvamVjdDEhMB8GC= SqG=0ASIb3DQEJARYSYnVpbGRAb3BlbnN1c2Uub3JnMB4XDTIwMDgwMzEyMzUzOVoXDTMw=0AMD= YxMjEyMzUzOVowgYYxJTAjBgNVBAMMHG9wZW5TVVNFIFNlY3VyZSBCb290IFNp=0AZ25rZXkxCz= AJBgNVBAYTAkRFMRIwEAYDVQQHDAlOdXJlbWJlcmcxGTAXBgNVBAoM=0AEG9wZW5TVVNFIFByb2= plY3QxITAfBgkqhkiG9w0BCQEWEmJ1aWxkQG9wZW5zdXNl=0ALm9yZzCCASIwDQYJKoZIhvcNAQ= EBBQADggEPADCCAQoCggEBAKVKfWLm7OvwYpDO=0A4s0qzbUDWG2GTlxFOkZe4XaFsjxAnmuXZT= Vm1SJ3N12zSdRH60YMqcns7yuISYQz=0A0K79shGDOfktO8iqxSE0JdUvhEFnJUECaXYAq+ioiS= wkm7QQWhHAUE3htshJeMt4=0ASK4dTGmTQNQBKCZ3xQTTHi1sOl8wYt0QdhkucqvgDUyPaxHrI4= LV1OV9R3XjGclG=0AZD6QEkXLhVcir2yLIA9G1qPZDXpNbrdfSx3GDEnSsD+GS0D/k5oe32w1KG= MnEM/S=0AfYrY1nsP6/k0hVO1KH9WJWV/DUoyO/4U75C6swg7SVTxyigT3s92/UV4N9Es5kZv= =0AaHhsuncCAwEAAaOCAQcwggEDMAwGA1UdEwEB/wQCMAAwHQYDVR0OBBYEFMi9x6wa=0AHYWWY= hf9k+v8FPSiALgUMIGuBgNVHSMEgaYwgaOAFGhCYA3iLExHfpW+I9/qlRPl=0AlxdioYGHpIGEM= IGBMSAwHgYDVQQDDBdvcGVuU1VTRSBTZWN1cmUgQm9vdCBDQTEL=0AMAkGA1UEBhMCREUxEjAQB= gNVBAcMCU51cmVtYmVyZzEZMBcGA1UECgwQb3BlblNV=0AU0UgUHJvamVjdDEhMB8GCSqGSIb3D= QEJARYSYnVpbGRAb3BlbnN1c2Uub3JnggEB=0AMA4GA1UdDwEB/wQEAwIHgDATBgNVHSUEDDAKB= ggrBgEFBQcDAzANBgkqhkiG9w0B=0AAQsFAAOCAQEAS1NWAHYBV1uaK7wE6c+Xz8t4c2hgTkFR4= E0iVZ+2aTz8OFzztQZq=0ACyZ9QYgSpApmvwmgFEQog6UUzw2f19W7qhIskDHfhBmK2uQtazHZ/= Pd8oXyHrbgK=0ATVh7GDc9OjrZe2wg03Q0N/KVUHD5lKYXY4rfAqKdc1XKfo7t8GIu+TnWDLXWV= I40=0AoDIXwSmg+JOZFXpf9cxZ2zENZnsaH0KTKNk6bNq8wjum4W54Tgk7UbDE6roJp5C3=0A7c= Ut/j+dL00gyFK66PFR1wXflZFtKixxVbMOLa13ZldsuNs0ye6whPqIKZ9ev4M4=0ArjWQD5k14U= i+48/MDJt4Nc2Sm1LYrdXJMw=3D=3D=0A-----END CERTIFICATE-----=0A --IS0zKkzwUGydFO0o-- --dTy3Mrz/UPE2dbVg Content-Type: application/pgp-signature; name="signature.asc" Content-Description: Digital signature -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEfEr9Ydiq51cHlqUXIgnWkC+WnJUFAl8oJX8ACgkQIgnWkC+W nJXcog//Tmh0+SyGiwaFha6N5khPOuXzeFZVO3FU6cT1UGLu5ZoHDLo+5m7yLhzo 2YTQNg9kKM1WjCbbqTgmbna6jUpaccg3QMgbJ5I2yfOAl22rLnAsSIul/+x8vCRX qZH1JEbcszc8JOqtC9xDWJGRRrBxwY+OG/BzUHSp8kF2xVwVYHq7G0AF3Hr8fF4D ld+VFBKK/yrVskSxUtSPjvEy8WrA36jrvfx2HSa7aZDa4yOKP44zlV43ubqOURRf fmVQ7Q1lVpHhbEG8PU36aXMfj1uNXhDyhfLZpkrMpRSS5xnmhhhwM/JLNLoGc+yz 8DNv/a8AYW4tscAelS7A1tHUQM217hXUCRMlrvEe5uzPgTot2f18nkgDh90DdabV iHXJ/H40H/4RCePoODr4N9kVyoAo0iMudaNbZ75COJLhuxJuzucDGtvckiq+z9SD p4pHei8EL6L8CTqZuUP6NlqyCK9Mye9PI/o6qAUbi/2LL5iVbAAEHCH6fxa6e+rL Uran5o7oJeBH6s6xj8EYB9rIwhH/fBHxt/KtzWMJJzTir4Sm1LcoizdKG3fnBkAV 4QqvjxrxbQ/o9lYA/o9OJ99Ly+dk7DqsV7GAFNuxzMtUbyR+cwXMigBd6jzoAWfd 5k20MGMuVeiH4Oc8XxwALFqVG+wtTOngIAMeWck+Lz3CgfpmpAs= =tbDN -----END PGP SIGNATURE----- --dTy3Mrz/UPE2dbVg-- -- To unsubscribe, e-mail: [email protected] To contact the owner, e-mail: [email protected]