[Feature]: Publish a single .efiauth2 file for each PostSignedObjects\DBX\SignedByKEK2011\dbx_Arch_Legacy subfolder
Nobody has claimed this yet.
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 48/100
- Issue type
- Feature
- Clarity
- Mostly clear
- Activity status
- Active
- Domain
- operating-systems, security
Research direction
Start by inspecting the PostSignedObjects/DBX/SignedByKEK2011/dbx_Arch_Legacy subfolders and the existing architecture-specific .efiauth2 files. Determine how DBX updates are assembled and published; done means each architecture has one consolidated dbx_${Arch}_Legacy.efiauth2 file in the repository.
Written by the indexing model from the issue text.
Description
Feature Overview
It's inconvenient to end-users for MS to publish multiple .efiauth2 files for each of the SignedByKEK2011 subfolders, because having an unknown number of DBX files requires someone to write an automation script to crawl the GitHub folder.
I thought the point was to have one file which could be downloaded, compared against, or applied to the host. If new EFI hashes are to be published, a new consolidated DBX file should be provided, instead of a set of side by side files.
Solution Overview
In future DBX updates, consolidate the SignedByKEK2011 efiauth2 files into a single file (by architecture) provided in the repro
dbx_${Arch}_Legacy.efiauth2
Alternatives Considered
No response
Urgency
Medium
Are you going to implement the feature request?
No
Do you need maintainer feedback?
No maintainer feedback needed
Anything else?
No response
- Dominant language
- Python
- Stars
- 289
- Forks
- 89
- Avg merge
- 3d 10h
- Merged PRs (30d)
- 7
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from microsoft/secureboot_objects
-
Difficulty 5/5 Over a week Newbie friendliness 35/100
microsoft/secureboot_objects#471 ·
-
state:needs-owner state:needs-triage type:bug urgency:high
Difficulty 4/5 3-5 days Newbie friendliness 55/100
microsoft/secureboot_objects#467 · 3 comments ·
-
state:needs-triage type:feature-request urgency:low
Difficulty 3/5 1-2 days Newbie friendliness 55/100
microsoft/secureboot_objects#466 ·
-
state:needs-owner state:needs-triage type:bug urgency:low
Difficulty 3/5 1-2 days Newbie friendliness 68/100
microsoft/secureboot_objects#424 · 6 comments ·
-
state:needs-maintainer-feedback state:needs-owner state:needs-triage type:feature-request urgency:high
Difficulty 5/5 Over a week Newbie friendliness 20/100
microsoft/secureboot_objects#422 · 14 comments · 2 reactions ·
All issues in microsoft/secureboot_objects
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
syfoud/Simulated_Scepter#172 ·
-
A cancelled tests run makes the coverage comment workflow fail and reports it as a red check on main Openarea: ci bug perceived difficulty: 3
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
Nitjsefnie-Harness-Commons/daedalus#921 · 1 comment ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 86/100
EleutherAI/lm-evaluation-harness#4207 ·
-
Difficulty 1/5 Under an hour Newbie friendliness 92/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
ClickHouse/clickhouse-connect#1057 ·