uki: add .mokkeys section - #226
Draft
andrewdunndev wants to merge 1 commit into
Draft
Conversation
Registers the .mokkeys section: one or more X.509 certificates for kernel module signature verification, each wrapped in its own EFI_SIGNATURE_LIST structure, the structures concatenated, written by ukify. The entry is appended at the end of the section list, as the note above it requires, so PCR 11 measurements of existing UKIs are unaffected. What the stub does with the section beyond making it available to the kernel is a separate matter and not addressed here.
Member
|
What's the use case for this exactly? If one already has access to a key that can sign and verify a UKI, then by definition the same key can be used for everything else too |
Member
|
@bluca See the proposal on the systemd repo. |
Member
|
Yeah that makes no sense either and doesn't really explain anything. Why can't the key used to sign the image be used to sign the modules? |
andrewdunndev
marked this pull request as draft
September 3, 2026 16:28
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Companion to systemd/systemd#43638, which adds the section to ukify and systemd-measure.