Skip to content

PCR 8 dependency unreliable #5

@anedward01

Description

@anedward01

Using PCR 8 can brick devices and cause them to be unusable until manually recovered. PCR 8 is controlled by the GRUB2 bootloader. Whenever the bootloader updated, devices are bricked on the next reboot.

Additionally, when an EFI stub is booted directly, PCR 8 and 9 are empty as they are populated by GRUB2's boot process.

The best course of action is taking a default empty PCR and manually populating the values using different measures. The measurement should be added as a script to the kernel's boot process.

Using the checksum of db.crt and the EFI kernel's verification detail along with a signature list would be a good start. PCR 12 would be a viable PCR to work with.

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions