Regarding Signing Linux kernel with Microsoft secure boot keys for UEFI
Sorry, added the subject .. On Fri 6 Jul, 2018, 11:22 AM inventsekar, <inventsekar@gmail.com> wrote:
Dear All,....
so I was reading on Quora....
https://www.quora.com/What-are-some-features-that-Linus-Torvalds-dismissed-f...
Signing Linux kernel with Microsoft secure boot keys for UEFI. That was suggested by RedHat developers and Linus flipped them off in his character... I went to that link and read two three times, but I could not understand.
Could you explain this above issue, on a newbies perspective.
Best regards, sekar
Hi All... I am not sure if its a bad question... (i thought for few days about "can i ask this or not") If its a bad question, please accept la apologizes.. if admins wishes, this three email can/should be deleted. Thanks again... Have a great weekend. Best regards Sekar On Fri 6 Jul, 2018, 11:23 AM inventsekar, <inventsekar@gmail.com> wrote:
Sorry, added the subject ..
On Fri 6 Jul, 2018, 11:22 AM inventsekar, <inventsekar@gmail.com> wrote:
Dear All,....
so I was reading on Quora....
https://www.quora.com/What-are-some-features-that-Linus-Torvalds-dismissed-f...
Signing Linux kernel with Microsoft secure boot keys for UEFI. That was suggested by RedHat developers and Linus flipped them off in his character... I went to that link and read two three times, but I could not understand.
Could you explain this above issue, on a newbies perspective.
Best regards, sekar
On Sun, Jul 8, 2018 at 1:17 AM, inventsekar <inventsekar@gmail.com> wrote:
... I am not sure if its a bad question... (i thought for few days about "can i ask this or not")
If its a bad question, please accept la apologizes.. if admins wishes, this three email can/should be deleted.
My guess is, no one bothered watching the youtube video. But it is just speculation on my part. Maybe you can list the items you would like explained. Jeff
Thx for the reply... I got it... Its not a youtube video i was refering... I was asking about this... https://arstechnica.com/information-technology/2013/02/linus-torvalds-i-will... I read this page few times but I am unable to understand what's Linus's idea..Why he disagree ... whether the Linux kernel should include code that makes it easier to boot Linux on Windows PCs. This goes back to Microsoft requiring <http://arstechnica.com/information-technology/2012/01/windows-8s-locked-boot...> that PCs designed to run Windows 8 use UEFI firmware with the Secure Boot feature enabled On Sun 8 Jul, 2018, 11:16 AM Jeffrey Walton, <noloader@gmail.com> wrote:
On Sun, Jul 8, 2018 at 1:17 AM, inventsekar <inventsekar@gmail.com> wrote:
... I am not sure if its a bad question... (i thought for few days about "can i ask this or not")
If its a bad question, please accept la apologizes.. if admins wishes, this three email can/should be deleted.
My guess is, no one bothered watching the youtube video. But it is just speculation on my part.
Maybe you can list the items you would like explained.
Jeff
On 7/8/18, inventsekar <inventsekar@gmail.com> wrote:
Thx for the reply... I got it... Its not a youtube video i was refering... I was asking about this...
https://arstechnica.com/information-technology/2013/02/linus-torvalds-i-will...
I read this page few times but I am unable to understand what's Linus's idea..Why he disagree ... whether the Linux kernel should include code that makes it easier to boot Linux on Windows PCs. This goes back to Microsoft requiring <http://arstechnica.com/information-technology/2012/01/windows-8s-locked-boot...> that PCs designed to run Windows 8 use UEFI firmware with the Secure Boot feature enabled
On Sun 8 Jul, 2018, 11:16 AM Jeffrey Walton, <noloader@gmail.com> wrote:
On Sun, Jul 8, 2018 at 1:17 AM, inventsekar <inventsekar@gmail.com> wrote:
... I am not sure if its a bad question... (i thought for few days about "can i ask this or not")
If its a bad question, please accept la apologizes.. if admins wishes, this three email can/should be deleted.
My guess is, no one bothered watching the youtube video. But it is just speculation on my part.
Maybe you can list the items you would like explained.
I'm just thinking out loud with respect to the context here and *not* the links... Is it about purity... and the word "tainted"? I've encountered the word "tainted" as it has been advocated (against) regarding Linux over the years, but it was finally visually thrown right in my face by my Debian Stretch Stable several times a couple weeks ago. I've been trying to build a module for a dialup modem that is the "scourge" of many a poverty level user around the Internet. I can't find the resulting warning/advisement message now, but it was my Debian copy's version of, "WHAT ARE YOU DOING?! THAT'S GOING TO TAINT THIS INSTALL! *smh*" Linux is very serious about to taint or don't to taint. :D Cindy :) -- Cindy-Sue Causey Talking Rock, Pickens County, Georgia, USA * runs with duct tape *
On Sun, Jul 8, 2018 at 8:35 AM, Cindy-Sue Causey <butterflybytes@gmail.com> wrote:
... I'm just thinking out loud with respect to the context here and *not* the links... Is it about purity... and the word "tainted"?
I've encountered the word "tainted" as it has been advocated (against) regarding Linux over the years, but it was finally visually thrown right in my face by my Debian Stretch Stable several times a couple weeks ago. I've been trying to build a module for a dialup modem that is the "scourge" of many a poverty level user around the Internet.
I can't find the resulting warning/advisement message now, but it was my Debian copy's version of, "WHAT ARE YOU DOING?! THAT'S GOING TO TAINT THIS INSTALL! *smh*"
There used to be a workaround: https://lwn.net/Articles/82305/ Jeff
On 08/07/2018 06:51, inventsekar wrote:
Thx for the reply... I got it... Its not a youtube video i was refering... I was asking about this...
https://arstechnica.com/information-technology/2013/02/linus-torvalds-i-will...
I read this page few times but I am unable to understand what's Linus's idea..Why he disagree ... whether the Linux kernel should include code that makes it easier to boot Linux on Windows PCs. This goes back to Microsoft requiring <http://arstechnica.com/information-technology/2012/01/windows-8s-locked-boot...> that PCs designed to run Windows 8 use UEFI firmware with the Secure Boot feature enabled
On Sun 8 Jul, 2018, 11:16 AM Jeffrey Walton, <noloader@gmail.com <mailto:noloader@gmail.com>> wrote:
On Sun, Jul 8, 2018 at 1:17 AM, inventsekar <inventsekar@gmail.com <mailto:inventsekar@gmail.com>> wrote: > ... > I am not sure if its a bad question... (i thought for few days about "can i > ask this or not") > > If its a bad question, please accept la apologizes.. if admins wishes, this > three email can/should be deleted.
My guess is, no one bothered watching the youtube video. But it is just speculation on my part.
Maybe you can list the items you would like explained.
Jeff
There are major security issues with the trust of the embedded key, if the private key part of that key gets compromised, there is no coming back. Also, why should Canonical trust Redhat's key, or Novell (SUSE), maybe the debian devs. It is a very very bad idea to have a PE binary which contains a redhat public key that is microsoft signed. This request is suggesting embedding 2 proprietary things into the Linux Kernel just so microsoft can control the x86 market. Ewan
On Sun, 08 Jul 2018 11:21:08 +0530, inventsekar said:
I read this page few times but I am unable to understand what's Linus's idea..Why he disagree ... whether the Linux kernel should include code that makes it easier to boot Linux on Windows PCs.
The issue is "trusted boot", and it doesn't actually make it easier to boot Linux. The problem is that the obvious way to implement it for a distro requires an intermediate key signed by Microsoft. In other words, you can't do it easily without Microsoft's permission. Although pretty much all UEFI boxes that support secure boot allow installing trusted private keys, it's not something you can do in the middle of an Ubuntu install - it requires dropping down into the BIOS screens and setting a bunch of stuff. So the only way to do it in a distro-friendly manner without involving Microsoft is to have the Linux Foundation or similar non-distro entity create a public/private key pair, and somebody gets *all* the vendors to include that key as well as Mirosoft's key. Dell, Lenovo, Toshiba, And all the others. Because any vendor that doesn't include it will get reports on the web "Trusted boot of Linux on Zen-Cheap doesn't work." Which, of course, most hardware manufacturers don't give a rat's tail about, because if they did, they'd fix their buggy BIOS that create pages on the web "suspend doesn't work on Zen-Cheap". (In actual practice, what happened was that somebody got Microsoft to sign an intermediate UEFI blob that allows bootstrapping a Linux kernel, and distros have included that blob. However, just like linux-firmware is packaged separately from the kernel due to the differing license on most firmware (which isn't GPL), that blob has to be distributed separate from the kernel as well.
Hi All.... Thx for your answers ... Great learning... I will reread them and understand better slowly and thoroughly. On Sun 8 Jul, 2018, 11:20 PM , <valdis.kletnieks@vt.edu> wrote:
On Sun, 08 Jul 2018 11:21:08 +0530, inventsekar said:
I read this page few times but I am unable to understand what's Linus's idea..Why he disagree ... whether the Linux kernel should include code that makes it easier to boot Linux on Windows PCs.
The issue is "trusted boot", and it doesn't actually make it easier to boot Linux.
The problem is that the obvious way to implement it for a distro requires an intermediate key signed by Microsoft.
In other words, you can't do it easily without Microsoft's permission. Although pretty much all UEFI boxes that support secure boot allow installing trusted private keys, it's not something you can do in the middle of an Ubuntu install - it requires dropping down into the BIOS screens and setting a bunch of stuff.
So the only way to do it in a distro-friendly manner without involving Microsoft is to have the Linux Foundation or similar non-distro entity create a public/private key pair, and somebody gets *all* the vendors to include that key as well as Mirosoft's key. Dell, Lenovo, Toshiba, And all the others. Because any vendor that doesn't include it will get reports on the web "Trusted boot of Linux on Zen-Cheap doesn't work."
Which, of course, most hardware manufacturers don't give a rat's tail about, because if they did, they'd fix their buggy BIOS that create pages on the web "suspend doesn't work on Zen-Cheap".
(In actual practice, what happened was that somebody got Microsoft to sign an intermediate UEFI blob that allows bootstrapping a Linux kernel, and distros have included that blob. However, just like linux-firmware is packaged separately from the kernel due to the differing license on most firmware (which isn't GPL), that blob has to be distributed separate from the kernel as well.
participants (5)
-
Cindy-Sue Causey -
Ewan Marshall -
inventsekar -
Jeffrey Walton -
valdis.kletnieks@vt.edu