[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[Xen-devel] Booting signed xen.efi through shim



Hi all,
for the last couple weeks I've been poking around the options
available to get Xen booted on a Secureboot enabled box. My goal is to
extend the chain of trust to the dom0 kernel. According to
https://wiki.xenproject.org/wiki/Xen_EFI this is something that's
supposed to be supported out-of-the-box right now via the shim
protocol. However, when I try to boot a signed xen.efi (4.10 unstable
head) through shim I get the error "Section 6 is inside image header"
and shim refuses to load Xen. OTOH I had been able to boot a
custom-compiled grub2 from the shim no problem with Secureboot
enabled. The signed xen.efi also boots fine with Secureboot enabled if
booted directly as an EFI application (but then no dom0 verification
is done AFAIU). Does anyone have any pointers on what's going on with
booting through the shim?

Thanks,
Tamas

_______________________________________________
Xen-devel mailing list
Xen-devel@xxxxxxxxxxxxx
https://lists.xen.org/xen-devel

 


Rackspace

Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.