Skip to content

UEFI Secure Boot variables protection not yet tested #1478

@miczyg1

Description

@miczyg1

Managing UEFI Secure Boot variables using OS tools like efitools does not work as intended. According to Debian manpages it should be possible to remove PK if owning the private key enrolled currently as PK: https://manpages.debian.org/testing/efitools/efi-updatevar.1.en.html

However, for some reason it does not want to pass:

Image

One may say that the protection works, but to the extent that nothing can be done once PK is enrolled.

It will have to be investigated and eventually fixed in the next phase of Sovereign Boot Provisioning Wizard project.

Metadata

Metadata

Assignees

No one assigned

    Labels

    SovereignBootIssues related to Sovereign Boot and Sovereign Boot Provisioning Wizard

    Type

    No type

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions