all lists on lists.proxmox.com
 help / color / mirror / Atom feed
* [pve-devel] [PATCH-SERIES RESEND edk2-firmware 0/6] partially fix #6985: pre-enroll Microsoft UEFI CA 2023 keys
@ 2025-11-07  8:54 Fiona Ebner
  2025-11-07  8:54 ` [pve-devel] [PATCH edk2-firmware 1/6] update edk2 to edk2-stable202505 tag and refresh patches Fiona Ebner
                   ` (5 more replies)
  0 siblings, 6 replies; 7+ messages in thread
From: Fiona Ebner @ 2025-11-07  8:54 UTC (permalink / raw)
  To: pve-devel

Re-sent with --transfer-encoding=base64. Also available at my staff
repo now: staff/f.ebner/pve-edk2-firmware, branch fix-6985

This fixes the issue with the Microsoft UEFI CA 2011 expiring in June
2026 for new EFI disks. What still needs to be done is giving users a
way for (or automatically) enrolling the new keys to existing EFI
disks. I will look at that part of the issue in the coming days.

To update an existing EFI disk, it should be enough to do something
like:
virt-fw-vars --inplace vm-103-disk-0.raw --distro-keys ms-uefi

AFAICS, virt-fw-vars can only deal with raw images, so we can use FUSE
exports of differently formatted EFI disks which requires [0].

[0]: https://lore.proxmox.com/pve-devel/20251020141335.124077-1-f.ebner@proxmox.com/


pve-edk2-firmware:

Fiona Ebner (6):
  update edk2 to edk2-stable202505 tag and refresh patches
  d/patches: pick up CVE fix from Debian tag debian/2025.05-1
  d/rules: pick up some improvements from Debian
  Use virt-firmware to enroll default keys.
  Initialize the Secure Boot dbx in *.ms.fd with the latest revocations
  partially fix #6985: pre-enroll Microsoft UEFI CA 2023 keys

 debian/DBXUpdate-2025-02-24.arm64.bin         | Bin 0 -> 4613 bytes
 debian/DBXUpdate-2025-10-16.amd64.bin         | Bin 0 -> 24053 bytes
 debian/control                                |   1 +
 debian/edk2-vars-generator.py                 | 140 ----
 ...nrollDefaultKeys-with-Microsoft-2023.patch | 613 ++++++++++++++++++
 ...tLib-Fix-split-lock-violation-from-M.patch |  10 +-
 ...CpuDxeSmm-Safe-handling-of-IDT-regis.patch |  45 ++
 debian/patches/series                         |   2 +
 debian/rules                                  |  99 +--
 debian/source/include-binaries                |   2 +
 edk2                                          |   2 +-
 11 files changed, 721 insertions(+), 193 deletions(-)
 create mode 100644 debian/DBXUpdate-2025-02-24.arm64.bin
 create mode 100644 debian/DBXUpdate-2025-10-16.amd64.bin
 delete mode 100755 debian/edk2-vars-generator.py
 create mode 100644 debian/patches/OvmfPkg-Expand-EnrollDefaultKeys-with-Microsoft-2023.patch
 create mode 100644 debian/patches/UefiCpuPkg-PiSmmCpuDxeSmm-Safe-handling-of-IDT-regis.patch


Summary over all repositories:
  11 files changed, 721 insertions(+), 193 deletions(-)

-- 
Generated by git-murpp 0.5.0
_______________________________________________
pve-devel mailing list
pve-devel@lists.proxmox.com
https://lists.proxmox.com/cgi-bin/mailman/listinfo/pve-devel


^ permalink raw reply	[flat|nested] 7+ messages in thread

end of thread, other threads:[~2025-11-07  8:55 UTC | newest]

Thread overview: 7+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2025-11-07  8:54 [pve-devel] [PATCH-SERIES RESEND edk2-firmware 0/6] partially fix #6985: pre-enroll Microsoft UEFI CA 2023 keys Fiona Ebner
2025-11-07  8:54 ` [pve-devel] [PATCH edk2-firmware 1/6] update edk2 to edk2-stable202505 tag and refresh patches Fiona Ebner
2025-11-07  8:54 ` [pve-devel] [PATCH edk2-firmware 2/6] d/patches: pick up CVE fix from Debian tag debian/2025.05-1 Fiona Ebner
2025-11-07  8:54 ` [pve-devel] [PATCH edk2-firmware 3/6] d/rules: pick up some improvements from Debian Fiona Ebner
2025-11-07  8:54 ` [pve-devel] [PATCH edk2-firmware 4/6] Use virt-firmware to enroll default keys Fiona Ebner
2025-11-07  8:54 ` [pve-devel] [PATCH edk2-firmware 5/6] Initialize the Secure Boot dbx in *.ms.fd with the latest revocations Fiona Ebner
2025-11-07  8:54 ` [pve-devel] [PATCH edk2-firmware 6/6] partially fix #6985: pre-enroll Microsoft UEFI CA 2023 keys Fiona Ebner

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.
Service provided by Proxmox Server Solutions GmbH | Privacy | Legal