secure boot working, permissions for grub.cfg looking fine.
signature 1
image signature issuers:
- /CN=Fedora Secure Boot CA
signature 2
image signature issuers:
- /C=US/ST=Massachusetts/L=Cambridge/O=Red Hat, Inc./OU=Fedora Secure Boot CA 20200709/CN=fedoraca
Is there a way to add a test for the secure boot issue? If not booting a VM with secure boot enabled, maybe just extracting the signatures from shim and validating the certificates of grub efi, it would be a big relief :D
BZ#2030358 CVE-2021-3981 grub2: Incorrect permission in grub.cfg allow unprivileged user to read the file content [fedora-all]
BZ#2030940 Booting with grub2-2.06-9.fc35 and UEFI Secure Boot enabled resulted in Error: Verification Failed: (0x1A) Security Violation
This update can be pushed to stable now if the maintainer wishes
This update has been submitted for testing by rharwood.
This update's test gating status has been changed to 'waiting'.
This update's test gating status has been changed to 'failed'.
This update's test gating status has been changed to 'passed'.
This update has been pushed to testing.
Works (UEFI, secure boot, with just Fedora default MOK, T450s).
secure boot working, permissions for grub.cfg looking fine.
Is there a way to add a test for the secure boot issue? If not booting a VM with secure boot enabled, maybe just extracting the signatures from shim and validating the certificates of grub efi, it would be a big relief :D
This update can be pushed to stable now if the maintainer wishes
Works great! LGTM! =)
This update has been submitted for stable by bodhi.
Boots fine!
Secure boot works
This update has been pushed to stable.
WFM