On Fri, Jul 20, 2012 at 4:34 PM, Steve McIntyre wrote:
> Here's a summary of what we discussed in the EFI BoF [1] last week
> (9th July). Thanks to the awesome efforts of the DebConf video team,
> the video of the session is already online [2] in case you missed
> it. I've also attached the Gobby notes that were taken during the
> session. Again, thanks to the people who took part - we had a useful
> discussion.
One thing I don't think anyone has discussed yet is how key
transitions will work, if a distro-specific key is compromised, is the
OS able to update the SB keys?
> Any one binary can only be signed by one key.
Would it be possible/useful to circumvent this limitation by making
copies of the binary and then signing them?
--
bye,
pabs
http://wiki.debian.org/PaulWise
--
To UNSUBSCRIBE, email to debian-devel-REQUEST@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org
Archive: http://lists.debian.org/CAKTje6EGV4vOSw2KeQgJVQqrZsf=R6WY0GZSwUOdQjqewshGm Q@mail.gmail.com
Tue Jul 31 23:30:01 2012
Return-Path: <devel-bounces@lists.fedoraproject.org>
X-Spam-Checker-Version: SpamAssassin 3.3.2 (2011-06-06) on
eagle542.startdedicated.com
X-Spam-Level:
X-Spam-Status: No, score=-2.2 required=5.0 tests=DKIM_ADSP_CUSTOM_MED,
DKIM_SIGNED,FREEMAIL_FROM,RCVD_IN_DNSWL_MED,SPF_PA SS,T_DKIM_INVALID,
T_RP_MATCHES_RCVD autolearn=ham version=3.3.2
X-Original-To: tom@linux-archive.org
Delivered-To: tom-linux-archive.org@eagle542.startdedicated.com
Received: from bastion.fedoraproject.org (bastion01.fedoraproject.org [209.132.181.2])
by eagle542.startdedicated.com (Postfix) with ESMTP id 9AB9F20E008F
for <tom@linux-archive.org>; Tue, 31 Jul 2012 22:42:51 +0200 (CEST)
Received: from lists.fedoraproject.org (collab03.vpn.fedoraproject.org [192.168.1.70])
by bastion01.phx2.fedoraproject.org (Postfix) with ESMTP id E877420EB5;
Tue, 31 Jul 2012 20:42:48 +0000 (UTC)
Received: from collab03.fedoraproject.org (localhost [127.0.0.1])
by lists.fedoraproject.org (Postfix) with ESMTP id 4A472420B1;
Tue, 31 Jul 2012 20:42:48 +0000 (UTC)
X-Original-To: devel@lists.fedoraproject.org
Delivered-To: devel@lists.fedoraproject.org
Received: from smtp-mm01.fedoraproject.org (smtp-mm01.fedoraproject.org
[80.239.156.217])
by lists.fedoraproject.org (Postfix) with ESMTP id 377D940829
for <devel@lists.fedoraproject.org>;
Tue, 31 Jul 2012 20:42:46 +0000 (UTC)
Received: from mail-wi0-f169.google.com (mail-wi0-f169.google.com
[209.85.212.169])
by smtp-mm01.fedoraproject.org (Postfix) with ESMTP id 7C7DBC0079
for <devel@lists.fedoraproject.org>;
Tue, 31 Jul 2012 20:42:45 +0000 (UTC)
Received: by wibhm2 with SMTP id hm2so3901299wib.2
for <devel@lists.fedoraproject.org>;
Tue, 31 Jul 2012 13:42:46 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113;
h=message-id:date:from:user-agent:mime-version:to:subject:references
:in-reply-to:content-type:content-transfer-encoding;
bh=Cv5gAUgVyw8n0mZHu+IuOAVCBCOm6zN07eEMENbuwmk=;
b=miMlDLq4ohmHkPSPQpZe/eiHZMsxUn3j20oMNgjZ9UODFF45qONibB180csCMRCalB
oxxUzNKPsuCVfYDPwrDSs59h4HGPVqVXjtNvDWJlZs8gTSddu6 viiE89sKFzWLf3b/fm
TFER7SiSVzitoMk+QKT4Uk2ILYeEjgYAYHlgKTG8SxkJLKs8ID enUSPPuQKumQwvu/91
Zch2SlmiqxRz6qI/s2UYN3fLfLPsXyrDP6WTDKbnGa7TqKdjiJZ8xJxTXC6+WCPGQa 91
vT2aHLfCfk/waJu+IwrxvmKbhd2jRATnig56ExrAXjBuLOfUGNNtpnLtkgIyy TvdKZSE
eojg==
Received: by 10.180.78.37 with SMTP id y5mr5773983wiw.16.1343767365922;
Tue, 31 Jul 2012 13:42:45 -0700 (PDT)
Received: from localhost.localdomain (85-220-55-128.dsl.dynamic.simnet.is.
[85.220.55.128])
by mx.google.com with ESMTPS id ef5sm2869743wib.3.2012.07.31.13.42.39
(version=TLSv1/SSLv3 cipher=OTHER);
Tue, 31 Jul 2012 13:42:45 -0700 (PDT)
Message-ID: <5018430F.8050202@gmail.com>
Date: Tue, 31 Jul 2012 20:41:51 +0000
From: =?UTF-8?B?IkrDs2hhbm4gQi4gR3XDsG11bmRzc29uIg==?=
<johannbg@gmail.com>
User-Agent: Mozilla/5.0 (X11; Linux x86_64;
rv:14.0) Gecko/20120717 Thunderbird/14.0
MIME-Version: 1.0
To: devel@lists.fedoraproject.org
Subject: Re: F17 PM Test day late

recap
References: <1075597839.2623675.1343741459608.JavaMail.root@re dhat.com>
In-Reply-To: <1075597839.2623675.1343741459608.JavaMail.root@re dhat.com>
X-BeenThere: devel@lists.fedoraproject.org
X-Mailman-Version: 2.1.12
Precedence: list
Reply-To: Development discussions related to Fedora
<devel@lists.fedoraproject.org>
List-Id: Development discussions related to Fedora
<devel.lists.fedoraproject.org>
List-Unsubscribe: <https://admin.fedoraproject.org/mailman/options/devel>,
<mailto:devel-request@lists.fedoraproject.org?subject=unsubscrib e>
List-Archive: <http://lists.fedoraproject.org/pipermail/devel/>
List-Post: <mailto:devel@lists.fedoraproject.org>
List-Help: <mailto:devel-request@lists.fedoraproject.org?subject=help>
List-Subscribe: <https://admin.fedoraproject.org/mailman/listinfo/devel>,
<mailto:devel-request@lists.fedoraproject.org?subject=subscribe>
Content-Transfer-Encoding: base64
Content-Type: text/plain; charset="utf-8"; Format="flowed"
Sender: devel-bounces@lists.fedoraproject.org
Errors-To: devel-bounces@lists.fedoraproject.org
T24gMDcvMzEvMjAxMiAwMTozMCBQTSwgSmFyb3NsYXYgU2thcn ZhZGEgd3JvdGU6Cj4gRHVyaW5n
IHRoZSBldmVudCBpdCBwcm92ZWQgdGhhdCBtYW5hZ2luZyBkb3 plbnMgb2YgYXR0ZW5kYW50cyBi
ZWNvbWUKPiBwYWluIHdpdGggdGhlIGN1cnJlbnQgdGVzdCBkYX kgaW5mcmFzdHJ1Y3R1cmUuIEZv
ciBuZXdjb21lcnMgaXQgd2FzCj4gaGFyZCB0byB1bmRlcnN0YW 5kIGhvdyB0byBmaWxsIHJlc3Vs
dHMgaW50byB3aWtpIChvciB0aGUgY29uY2VwdCBvZgo+IHRoZS B3aWtpIGl0c2VsZikuIEl0IHdh
cyBldmVuIGhhcmRlciBmb3IgcmVtb3RlZXMuIFNldmVyYWwgdG ltZXMgd2UKPiByZWNlaXZlZCBw
bGFpbiB0ZXh0IHJlcG9ydHMgYW5kIHdlIGhhZCB0byB0cmFuc2 ZlciB0aGVtIGludG8gd2lraQo+
IG91cnNlbGYuIEluIHJ1c2ggaG91cnMgdGhlcmUgd2VyZSBzby BtYW55IGNvbmZsaWN0aW5nIGVk
aXRzIGluIHRoZQo+IHdpa2kgdGhhdCB3ZSBoYWQgdG8gdXRpbG l6ZSBvbmUgcGVvcGxlIHdobyB3
b3JrZWQgb25seSBhcyBhIHdpa2kKPiBjb3JyZWN0b3IuIEkgY2 Fubm90IGltYWdpbmUgaG93IHRv
IGhhbmRsZSBlLmcuIGRvdWJsZSBudW1iZXIgb2YKPiBwYXJ0aW NpcGFudHMgd2l0aCB0aGUgY3Vy
cmVudCBzeXN0ZW0uIEkgdGhpbmsgdGhhdCBzb21lIG1vcmUgcm 9idXN0Cj4gYW5kIGludHVpdGl2
ZSBzeXN0ZW0gaXMgbmVlZGVkIHRvIGF0dHJhY3QvaGFuZGxlIG 1vcmUgcGFydGljaXBhbnRzLgo+
IElmIGRlc2lnbmVkIHRoZSByaWdodCB3YXkgaXQgY291bGQgYW xzbyBzaW1wbGlmeSBldmFsdWF0
aW9uIG9mIHJlc3VsdHMKPiBhbmQgY291bGQgZ2l2ZSBhbnN3ZX JzIHRvIHZhcmlvdXMgcXVlcmll
cyBsaWtlICJ3aGF0IEhXIHdvcmtlZCBvbgo+IHdoaWNoIHZlcn Npb24gb2YgRmVkb3JhIi4KCkF0
IHRoZSB0aW1lIHdlIGxvb2tlZCBhdCB2YXJpb3VzIHRlc3Rpbm cgc3lzdGVtIGJ1dCBhbGwgb2Yg
dGhlbSBmZWxsIApzaG9ydCBvbmUgd2F5IG9yIGFub3RoZXIgdG h1cyB3ZSBkZWNpZGUgdG8gc2V0
dGxlIG9uIHNvbWV0aGluZyByZXBvcnRlcnMgCndoZXJlIGZhbW lsaWFyIHdpdGggYXMgYW4gc2hv
cnQgc3RvcCB1bnRpbCB3ZSBmb3VuZCBvciBjYW1lIHVwIHdpdG ggCnNvbWV0aGluZyBiZXR0ZXIg
YW5kIHdlIGhhZCBjb3VwbGUgb2YgaWRlYXMgaG93IHRoYXQgc2 hvdWxkIGxvb2sgbGlrZSAKd2hp
Y2ggd2VsbCBsZXQncyBzYXkgd2FzIHF1aXRlIGRpZmZlcmVudC Bmcm9tIHRoZSB0cmFkaXRpb25h
bCB0Y21zLgoKSW4gYW55IGNhc2UgdGhpcyBkaXNjdXNzaW9uIG FuZCBob3cgaXQgY2FuIGJlIGlt
cHJvdmVkIGJlbG9uZ3Mgb24gdGhlIAotdGVzdCBsaXN0IHdoZX JlIHRoZSBRQSBjb21tdW5pdHkg
cmVzaWRlcy4uLgoKSkJHCgoKLS0gCmRldmVsIG1haWxpbmcgbG lzdApkZXZlbEBsaXN0cy5mZWRv
cmFwcm9qZWN0Lm9yZwpodHRwczovL2FkbWluLmZlZG9yYXByb2 plY3Qub3JnL21haWxtYW4vbGlz
dGluZm8vZGV2ZWw=