[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [PATCH] Change "efi" to "EFI" in grub-mkrescue for secure boot
From: |
Tobias Powalowski |
Subject: |
Re: [PATCH] Change "efi" to "EFI" in grub-mkrescue for secure boot |
Date: |
Wed, 11 Sep 2024 12:38:31 +0200 |
User-agent: |
Mozilla Thunderbird |
Back in the day I added that commit on the supergrub history because I
wasn't proud enough of the SecureBoot implementation or I messed up in
which branch I was pushing those changes.
Right now the SecureBoot build is turned on on the main supergrub
codebase.
It is based on the Debian binaries and, if I'm being honest, I might
remove it (and suggest people to boot Super Grub2 Disk while
SecureBoot is disabled) in the future because of two main reasons:
- Not being able to keep up with Debian updates in order to avoid
problems with revoked SecureBoot-enabled shims/grubs .
- Nobody seem to be asking for any Fedora / RedHat / SusE, you-name-it
SecureBoot support for Super Grub2 Disk.
Alternatively I could try to embed supergrub scripts onto an official
Debian grub-related package and... just recommend that when you cannot
turn off SecureBoot on your UEFI Firmware.
You want SecureBoot's SuperGrub in SusE ? Just port that package onto
SusE yourself.
Note: In this message: SuperGrub = Super Grub Disk = Super Grub2 Disk .
adrian15
_______________________________________________
Grub-devel mailing list
Grub-devel@gnu.org
https://lists.gnu.org/mailman/listinfo/grub-devel
Sorry to chime in, but it does not matter which distro you have as base.
The shim needs to be signed by Microsoft, any built grub can then be
used afterwards.
With a MOK setup you can pretty boot anything then.
The matter with grub-mkrescue not performing correct might be the case
for me too.
I was not able to use virtualbox on my project until I put the kernel
also to the ISO fs I think,
cause efi fs was not acceptable by virtualbox. (Maybe virtualbox efi
implementation is just too limited, I don't know the exact reason.)
Best regards
tpowa
--
Tobias Powalowski
Arch Linux Developer (tpowa)
https://www.archlinux.org
tpowa@archlinux.org
Archboot Developer
https://archboot.com
St. Martin-Apotheke
Herzog-Georg-Str. 25
89415 Lauingen
https://www.st-martin-apo.de
info@st-martin-apo.de
- Re: [PATCH] Change "efi" to "EFI" in grub-mkrescue for secure boot, (continued)
Re: [PATCH] Change "efi" to "EFI" in grub-mkrescue for secure boot, Askar Safin, 2024/09/14