Re: Re: [security-announce] Heads up: "BootHole" security issue

Marcus Meissner <[email protected]> Mon, 3 Aug 2020 16:56:39 +0200
Newsgroups gmane.linux.suse.security
Organization SUSE Software Solutions Ger many GmbH, Maxfeldstr. 5, 90409 Nuernberg, Germany , GF: Felix Imendörffer, HRB 36809, AG Nürnber g
Message-ID <[email protected]>
--dTy3Mrz/UPE2dbVg
Content-Type: multipart/mixed; boundary="IS0zKkzwUGydFO0o"
Content-Disposition: inline


--IS0zKkzwUGydFO0o
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

On Sun, Aug 02, 2020 at 08:30:26AM +0200, Marcus Meissner wrote:
> On Sat, Aug 01, 2020 at 01:50:56PM -0700, Lew Wolfgang wrote:
> > On 07/31/2020 11:14 PM, Marcus Meissner wrote:
> > > On Fri, Jul 31, 2020 at 10:30:47PM +0200, [email protected] wro=
te:
> > > > Am 30.07.20 um 15:10 schrieb Marcus Meissner:
> > > > > > (......)
> > > > > > will stay unchanged?
> > > > > Yes, the openSUSE Secure Boot CA will stay unchanged.
> > > > > > Is the new key available for download somewhere?
> > > > > > I have my own set of PK/KEK and import such keys usually manual=
ly.
> > > > > We still need to generate the new key, we need to wait until the =
fixed grub2
> > > > > has been checked into openSUSE:Factory first to avoid having it s=
igned by the new key.
> > > > >=20
> > > > > I will send it as reply  as soon as its available.
> > > > Out of curiousity, what toolchain do you use to create/handle secure
> > > > boot keys?
> > > The signing itself is done by the open build service in the backgroun=
d.
> > > > sbsigntools and efitools have never been part of any official SUSE =
repo.
> > > > Lucky, the author of these tools has his own repo.
> > > We use the "pesign" toolset, from here https://github.com/rhboot/pesi=
gn
> >=20
> > Ars Technica is reporting boot failures after the BootHole patch is
> > installed
> > on Red Hat, CentOS, Ubuntu, Debian and maybe others.
> >=20
> > https://arstechnica.com/gadgets/2020/07/red-hat-and-centos-systems-aren=
t-booting-due-to-boothole-patches/
>=20
> As far as I understand they backported a buggy optional patch.
>=20
> We only backported mandatory patches from the patchset.
> =20
> > Did the openSUSE patch get delayed because of the key id issue mentioned
> > here:
> >=20
> > https://lists.opensuse.org/opensuse-security/2020-07/msg00001.html
>=20
> Yes.=20
>=20
> We need to make sure that the buggy insecure old grub2 is not built with =
the new key.
>=20
> As the fixed grub2 package is now checked into factory, we will create a =
new signing key,=20
> and then start delivering updates, both Tumbleweed and also for Leap.

Update:

The openSUSE signing key was rotated today.

- tumbleweed is already rebuilding all secure boot relevant packages for th=
eir next snapshot.

- leap maintenance we pushed grub2 to QA, also 15.1 kernel. ... More packag=
es will follow
  in the next days.


The replacement of shim will only happen after we fixed everything. (Tumble=
weed earlier than Leap ;)

Ciao, Marcus

--IS0zKkzwUGydFO0o
Content-Type: application/x-x509-ca-cert
Content-Disposition: attachment; filename="opensuse-new-signing-cert-202007.crt"
Content-Transfer-Encoding: quoted-printable

-----BEGIN CERTIFICATE-----=0AMIIElTCCA32gAwIBAgIJAPq+2L9Aml5jMA0GCSqGSIb3D=
QEBCwUAMIGBMSAwHgYD=0AVQQDDBdvcGVuU1VTRSBTZWN1cmUgQm9vdCBDQTELMAkGA1UEBhMCR=
EUxEjAQBgNV=0ABAcMCU51cmVtYmVyZzEZMBcGA1UECgwQb3BlblNVU0UgUHJvamVjdDEhMB8GC=
SqG=0ASIb3DQEJARYSYnVpbGRAb3BlbnN1c2Uub3JnMB4XDTIwMDgwMzEyMzUzOVoXDTMw=0AMD=
YxMjEyMzUzOVowgYYxJTAjBgNVBAMMHG9wZW5TVVNFIFNlY3VyZSBCb290IFNp=0AZ25rZXkxCz=
AJBgNVBAYTAkRFMRIwEAYDVQQHDAlOdXJlbWJlcmcxGTAXBgNVBAoM=0AEG9wZW5TVVNFIFByb2=
plY3QxITAfBgkqhkiG9w0BCQEWEmJ1aWxkQG9wZW5zdXNl=0ALm9yZzCCASIwDQYJKoZIhvcNAQ=
EBBQADggEPADCCAQoCggEBAKVKfWLm7OvwYpDO=0A4s0qzbUDWG2GTlxFOkZe4XaFsjxAnmuXZT=
Vm1SJ3N12zSdRH60YMqcns7yuISYQz=0A0K79shGDOfktO8iqxSE0JdUvhEFnJUECaXYAq+ioiS=
wkm7QQWhHAUE3htshJeMt4=0ASK4dTGmTQNQBKCZ3xQTTHi1sOl8wYt0QdhkucqvgDUyPaxHrI4=
LV1OV9R3XjGclG=0AZD6QEkXLhVcir2yLIA9G1qPZDXpNbrdfSx3GDEnSsD+GS0D/k5oe32w1KG=
MnEM/S=0AfYrY1nsP6/k0hVO1KH9WJWV/DUoyO/4U75C6swg7SVTxyigT3s92/UV4N9Es5kZv=
=0AaHhsuncCAwEAAaOCAQcwggEDMAwGA1UdEwEB/wQCMAAwHQYDVR0OBBYEFMi9x6wa=0AHYWWY=
hf9k+v8FPSiALgUMIGuBgNVHSMEgaYwgaOAFGhCYA3iLExHfpW+I9/qlRPl=0AlxdioYGHpIGEM=
IGBMSAwHgYDVQQDDBdvcGVuU1VTRSBTZWN1cmUgQm9vdCBDQTEL=0AMAkGA1UEBhMCREUxEjAQB=
gNVBAcMCU51cmVtYmVyZzEZMBcGA1UECgwQb3BlblNV=0AU0UgUHJvamVjdDEhMB8GCSqGSIb3D=
QEJARYSYnVpbGRAb3BlbnN1c2Uub3JnggEB=0AMA4GA1UdDwEB/wQEAwIHgDATBgNVHSUEDDAKB=
ggrBgEFBQcDAzANBgkqhkiG9w0B=0AAQsFAAOCAQEAS1NWAHYBV1uaK7wE6c+Xz8t4c2hgTkFR4=
E0iVZ+2aTz8OFzztQZq=0ACyZ9QYgSpApmvwmgFEQog6UUzw2f19W7qhIskDHfhBmK2uQtazHZ/=
Pd8oXyHrbgK=0ATVh7GDc9OjrZe2wg03Q0N/KVUHD5lKYXY4rfAqKdc1XKfo7t8GIu+TnWDLXWV=
I40=0AoDIXwSmg+JOZFXpf9cxZ2zENZnsaH0KTKNk6bNq8wjum4W54Tgk7UbDE6roJp5C3=0A7c=
Ut/j+dL00gyFK66PFR1wXflZFtKixxVbMOLa13ZldsuNs0ye6whPqIKZ9ev4M4=0ArjWQD5k14U=
i+48/MDJt4Nc2Sm1LYrdXJMw=3D=3D=0A-----END CERTIFICATE-----=0A
--IS0zKkzwUGydFO0o--

--dTy3Mrz/UPE2dbVg
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: Digital signature

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEfEr9Ydiq51cHlqUXIgnWkC+WnJUFAl8oJX8ACgkQIgnWkC+W
nJXcog//Tmh0+SyGiwaFha6N5khPOuXzeFZVO3FU6cT1UGLu5ZoHDLo+5m7yLhzo
2YTQNg9kKM1WjCbbqTgmbna6jUpaccg3QMgbJ5I2yfOAl22rLnAsSIul/+x8vCRX
qZH1JEbcszc8JOqtC9xDWJGRRrBxwY+OG/BzUHSp8kF2xVwVYHq7G0AF3Hr8fF4D
ld+VFBKK/yrVskSxUtSPjvEy8WrA36jrvfx2HSa7aZDa4yOKP44zlV43ubqOURRf
fmVQ7Q1lVpHhbEG8PU36aXMfj1uNXhDyhfLZpkrMpRSS5xnmhhhwM/JLNLoGc+yz
8DNv/a8AYW4tscAelS7A1tHUQM217hXUCRMlrvEe5uzPgTot2f18nkgDh90DdabV
iHXJ/H40H/4RCePoODr4N9kVyoAo0iMudaNbZ75COJLhuxJuzucDGtvckiq+z9SD
p4pHei8EL6L8CTqZuUP6NlqyCK9Mye9PI/o6qAUbi/2LL5iVbAAEHCH6fxa6e+rL
Uran5o7oJeBH6s6xj8EYB9rIwhH/fBHxt/KtzWMJJzTir4Sm1LcoizdKG3fnBkAV
4QqvjxrxbQ/o9lYA/o9OJ99Ly+dk7DqsV7GAFNuxzMtUbyR+cwXMigBd6jzoAWfd
5k20MGMuVeiH4Oc8XxwALFqVG+wtTOngIAMeWck+Lz3CgfpmpAs=
=tbDN
-----END PGP SIGNATURE-----

--dTy3Mrz/UPE2dbVg--
-- 
To unsubscribe, e-mail: [email protected]
To contact the owner, e-mail: [email protected]