Bug 4816

Summary: [UPDATE REQUEST] grub2-2.00-66, shim-0.8-1, shim-unsigned-0.8-2
Product: [ROSA-based products] ROSA Fresh Reporter: Konstantin Vlasov <konstantin.vlasov>
Component: Packages from MainAssignee: ROSA Linux Bugs <bugs>
Status: VERIFIED FIXED QA Contact: ROSA Linux Bugs <bugs>
Severity: normal    
Priority: Normal CC: v.potapov
Version: FreshFlags: v.potapov: qa_verified+
konstantin.vlasov: published+
Target Milestone: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Platform: --- ROSA Vulnerability identifier:
RPM Package: ISO-related:
Bad POT generating: Upstream:

Description Konstantin Vlasov 2014-12-20 19:59:53 MSK
To support SecureBoot, shim and grub2 packages were updated.
Comment 1 Konstantin Vlasov 2014-12-20 20:28:00 MSK
grub2:
https://abf.rosalinux.ru/build_lists/2378415
https://abf.rosalinux.ru/build_lists/2378416

Advisory: EFI binaries are signed with ROSA private key to allow booting in Secure Boot mode.


shim-unsigned:
https://abf.rosalinux.ru/build_lists/2378417
https://abf.rosalinux.ru/build_lists/2378418

Adsivory: EFI binaries are signed with ROSA private key, so that shim was ready for signing by UEFI trusted authority and other EFI binaries could be loaded in Secure Boot mode via authority-signed shim.


shim (x86_64 only):
https://abf.rosalinux.ru/build_lists/2378301

Advisory: Latest shim version signed by Microsoft to allow booting in Secure Boot mode and accepting EFI binaries signed by ROSA private key.


P.S. The projects grub2 and shim-unsigned were moved from the 'import' group to private account 'signer' to implement secure signing of EFI binaries.
Comment 3 Vladimir Potapov 2014-12-22 13:51:43 MSK
 grub2-2.00-66
http://abf-downloads.rosalinux.ru/rosa2014.1/container/2378415/i586/main/release/
http://abf-downloads.rosalinux.ru/rosa2014.1/container/2378416/x86_64/main/release/

 shim-unsigned-0.8-2
http://abf-downloads.rosalinux.ru/rosa2014.1/container/2378417/i586/main/release/
http://abf-downloads.rosalinux.ru/rosa2014.1/container/2378418/x86_64/main/release/

shim-0.8-1
http://abf-downloads.rosalinux.ru/rosa2014.1/container/2378301/x86_64/main/release/
************************ Advisory *************************
grub2: EFI binaries are signed with ROSA private key to allow booting in Secure Boot mode.
shim-unsigned: EFI binaries are signed with ROSA private key, so that shim was ready for signing by UEFI trusted authority and other EFI binaries could be loaded in Secure Boot mode via authority-signed shim.
shim: Latest shim version signed by Microsoft to allow booting in Secure Boot mode and accepting EFI binaries signed by ROSA private key.
************************************************************
QA Verified