Post Reply 
 
Thread Rating:
  • 1 Vote(s) - 4 Average
  • 1
  • 2
  • 3
  • 4
  • 5
UEFI SecureBoot support
2014-11-12, 18:39
Post: #3
RE: UEFI Support
(2014-11-12 14:37)mcb30 Wrote:  
(2014-11-11 22:10)mijanek Wrote:  I'd like to ask regarding this ipxe-devel mailing post from Michael Brown, if there is any chance to get the undionly.efi signed.

I was trying to find something new about that but no luck..

I have unfortunately constrain, not allowing me te disable the stupid secure boot (I really didn't found until now good reason for it unless MS makes some $$ with it.)

UEFI code signing now requires an EV code-signing certificate, which I don't currently have. The certificate costs US$500 (for three years). The submission process is tedious and slow, but workable.

It's likely to happen as soon as someone thinks it's worth more than US$500 to get a SecureBoot-signed version of iPXE. By default, UEFI does not apply SecureBoot checks to binaries present in NIC ROMs, which reduces the utility of having a signed version of iPXE; it's only chainloading that would really benefit.

Michael

OK, thanks a lot. I know the constrains with the EV certificate (and know, that Verisign wan'ts 700$ per year for it).
Do you know however it would even pass the certification process at all?

And how is about the wimboot, does this need to be signed then too, or is it something like binary plugin to ipxe? (Microsoft says they sign only .efi files)

(Unfortunatelly I can't access NIC ROM, as I need this for the Tablets e.g. Surface 3 Pro with USB network card, so no chance here. )
Find all posts by this user
Quote this message in a reply
Post Reply 


Messages In This Thread
UEFI SecureBoot support - mijanek - 2014-11-11, 22:10
RE: UEFI Support - mcb30 - 2014-11-12, 14:37
RE: UEFI Support - mijanek - 2014-11-12 18:39
RE: UEFI Support - mcb30 - 2014-11-12, 23:29
RE: UEFI Support - mijanek - 2014-11-13, 11:12
RE: UEFI Support - newUser - 2014-12-01, 14:28
RE: UEFI SecureBoot support - kyor - 2015-02-16, 10:24
RE: UEFI SecureBoot support - kyor - 2015-02-17, 09:33
RE: UEFI SecureBoot support - mijanek - 2015-03-10, 07:22
RE: UEFI SecureBoot support - kyor - 2015-03-10, 07:50
RE: UEFI SecureBoot support - mijanek - 2015-03-10, 08:07
RE: UEFI SecureBoot support - mijanek - 2015-03-10, 12:02



User(s) browsing this thread: 1 Guest(s)