Thread (21 messages) flat view 21 messages, 2 authors, 2022-05-15

Re: [PATCH v7] efi: Do not import certificates from UEFI Secure Boot for T2 Macs

From: Mimi Zohar <zohar@linux.ibm.com>
Date: 2022-05-13 15:25:25
Also in: bpf, keyrings, linux-integrity, lkml, netdev, stable

Hi Aditya,

On Fri, 2022-04-15 at 17:02 +0000, Aditya Garg wrote:
From: Aditya Garg <redacted>

On Apple T2 Macs, when Linux attempts to read the db and dbx efi variables
at early boot to load UEFI Secure Boot certificates, a page fault occurs
in Apple firmware code and EFI runtime services are disabled with the
following logs:
Are there directions for installing Linux on a Mac with Apple firmware
code?  Are you dual booting Linux and Mac, or just Linux?  While in
secure boot mode, without being able to read the keys to verify the
kernel image signature, the signature verification should fail.

Has anyone else tested this patch?

thanks,

Mimi

Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help