[Bug 1748983] [NEW] Generate per-machine MOK for dkms signing

Mathieu Trudel-Lapierre mathieu.tl at gmail.com
Mon Feb 12 20:20:49 UTC 2018


Public bug reported:

shim-signed's update-secureboot-policy should allow creating a machine-
owner key, and using this for signing kernel modules built via DKMS. Key
generation and enrolling should be made as easy as possible for users.

** Affects: dkms (Ubuntu)
     Importance: High
     Assignee: Mathieu Trudel-Lapierre (cyphermox)
         Status: In Progress

** Affects: shim-signed (Ubuntu)
     Importance: High
     Assignee: Mathieu Trudel-Lapierre (cyphermox)
         Status: In Progress

** Also affects: dkms (Ubuntu)
   Importance: Undecided
       Status: New

** Changed in: dkms (Ubuntu)
       Status: New => In Progress

** Changed in: shim-signed (Ubuntu)
       Status: New => In Progress

** Changed in: dkms (Ubuntu)
   Importance: Undecided => High

** Changed in: shim-signed (Ubuntu)
   Importance: Undecided => High

** Changed in: dkms (Ubuntu)
     Assignee: (unassigned) => Mathieu Trudel-Lapierre (cyphermox)

** Changed in: shim-signed (Ubuntu)
     Assignee: (unassigned) => Mathieu Trudel-Lapierre (cyphermox)

-- 
You received this bug notification because you are a member of Ubuntu
Foundations Bugs, which is subscribed to shim-signed in Ubuntu.
https://bugs.launchpad.net/bugs/1748983

Title:
  Generate per-machine MOK for dkms signing

Status in dkms package in Ubuntu:
  In Progress
Status in shim-signed package in Ubuntu:
  In Progress

Bug description:
  shim-signed's update-secureboot-policy should allow creating a
  machine-owner key, and using this for signing kernel modules built via
  DKMS. Key generation and enrolling should be made as easy as possible
  for users.

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/dkms/+bug/1748983/+subscriptions



More information about the foundations-bugs mailing list