We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Confirm the following are included in your repo, checking each box:
https://github.com/steve-mcintyre/shim-review/tree/debian-10-shim-amd64-i386-20230209
56799038b33ba75a9fb1aa3bf46439b4b2b60f82778e34b31c6e6c1fd4bf5424 shimia32.efi 2634ad3f55012e35f469b9346ee21c7930d981c0e34833675317154492a611c2 shimx64.efi
#267, #268, #269 (15.6, accepted, but never signed due to issues with submission) #184, #185 (15.4, accepted and signed)
Very similar to #315 and #316
The text was updated successfully, but these errors were encountered:
Disclaimer: I am not a not an authorized reviewer
Hashes
2634ad3f55012e35f469b9346ee21c7930d981c0e34833675317154492a611c2 /shim/shimx64.efi 2634ad3f55012e35f469b9346ee21c7930d981c0e34833675317154492a611c2 /shim-review/shimx64.efi 56799038b33ba75a9fb1aa3bf46439b4b2b60f82778e34b31c6e6c1fd4bf5424 /shim/shimia32.efi 56799038b33ba75a9fb1aa3bf46439b4b2b60f82778e34b31c6e6c1fd4bf5424 /shim-review/shimia32.efi
SBAT
sbat,1,SBAT Version,sbat,1,https://github.com/rhboot/shim/blob/main/SBAT.md shim,3,UEFI shim,shim,1,https://github.com/rhboot/shim shim.debian,1,Debian,shim,15.7,https://tracker.debian.org/pkg/shim
Upstream 15.7 Shim is used with the following patches:
debian.grub
SBAT entries are matching the provided one
Embedded certificate matches the organization (has not changed since last review)
Keys are kept in an HSM, root CA sharded between Debian's sysadmin team
Shim launches GRUB and fwupd
grub
Kernel has lockdown and stated patches applied
LGTM!
Sorry, something went wrong.
Signed binaries returned, closing
No branches or pull requests
Confirm the following are included in your repo, checking each box:
What is the link to your tag in a repo cloned from rhboot/shim-review?
https://github.com/steve-mcintyre/shim-review/tree/debian-10-shim-amd64-i386-20230209
What is the SHA256 hash of your final SHIM binary?
56799038b33ba75a9fb1aa3bf46439b4b2b60f82778e34b31c6e6c1fd4bf5424 shimia32.efi
2634ad3f55012e35f469b9346ee21c7930d981c0e34833675317154492a611c2 shimx64.efi
What is the link to your previous shim review request (if any, otherwise N/A)?
#267, #268, #269 (15.6, accepted, but never signed due to issues with submission)
#184, #185 (15.4, accepted and signed)
Very similar to #315 and #316
The text was updated successfully, but these errors were encountered: