Poettering: Brave new trusted boot world
Poettering: Brave new trusted boot world
Posted Oct 3, 2023 20:08 UTC (Tue) by mjg59 (subscriber, #23239)In reply to: Poettering: Brave new trusted boot world by kreijack
Parent article: Poettering: Brave new trusted boot world
How? If anything is signed with a different cert chain (even if it's a shim signed with the Microsoft key, it will then measure the vendor cert before booting the second stage) then the PCR 7 measurement will be different and you won't be able to unseal the material.
> From the points above it seems to me that the PCR11 signature of an UKI file, is secure only in a strongly constrained environment, i.e. where it is possible to be sure that all 'bootloader chain' is secure.
The alternative is to seal to PCRs 0-5+11. This doesn't rely on any sort of secure boot chain but does increase fragility over firmware updates or some security-relevant configuration changes.
