-
Notifications
You must be signed in to change notification settings - Fork 130
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Shim 15.7 for Pop OS (system76-shim-x86_64-20230131) #313
Comments
@julian-klode I realized that I do not have NX support enabled (#307). Is it preferred if I add a patch on top of 15.7 or preferred if I use the current master branch of shim in order to enable it? When will there be a new release of shim that enables it by default? |
Can I please get a response on this? |
May be you could add a patch named NX.patch like this: https://github.com/opsi-org/shim-review/tree/opsi-shim-x86_64-20230109 |
A patch works. |
Thanks, I will do that. |
Picking up in this now, apologies for the delay. :-( I've just sent you mails for contact verification - please read and follow the instructions there. |
Thank you @steve-mcintyre, I realize that I still need to pick the NX patch |
|
|
Review of Shim 15.7 for Pop OS (system76-shim-x86_64-20230131)OK
Issues / queries / outstanding
|
Contact verification complete! |
Thank you for the review, I'll work through the items remaining. If systemd-boot will be an issue, I can try to utilize grub and specify that in the next version I build. The certificate that is embedded is used directly to sign binaries. I'd be happy to build a new one with a shorter revocation time. |
I think the signing of systemd-boot we should discuss on the up coming meeting. Ubuntu got a submission accepted with systemd-boot, but we currently have no fixed guidelines for that. To make it easier to review for us you can:
Regarding the certificate. The most common thing to do is to embed a 20-30 years CA certificate and then generate other certs to sign the components with a shorter lifespan. |
systemd-boot is now allowed. Can you either create a new submission for 15.8 or update this one to 15.8? |
I will do a new submission with the latest shim when I have time. Closing this one in the meantime. |
Confirm the following are included in your repo, checking each box:
What is the link to your tag in a repo cloned from rhboot/shim-review?
https://github.com/system76/shim-review/tree/system76-shim-x86_64-20230131
What is the SHA256 hash of your final SHIM binary?
c2f68d9214792d6e76901a287f01a8befea760ca1ec82b13f2b3c9f19bda52a4
What is the link to your previous shim review request (if any, otherwise N/A)?
N/A
The text was updated successfully, but these errors were encountered: