[Skiboot] [PATCH] libstb/secureboot: Disable secureboot in OPAL by nvram

Stewart Smith stewart at linux.ibm.com
Mon May 28 12:09:47 AEST 2018


Pridhiviraj Paidipeddi <ppaidipe at linux.vnet.ibm.com> writes:
> Currently custom debug petitboot kernels failed to boot on secureboot
> enabled systems as the key verification fails results in enforcing the
> boot. Due to which debugging any problems in petitboot kernel in secure
> boot enabled systems become hard.
> This patch provides a way to disable secureboot in OPAL by using below
> nvram command.
> nvram -p ibm,skiboot --update-config force-secure-mode=false

As mentioned by others, this isn't something I can take for upstream as
it really does bypass the point of secure mode.


-- 
Stewart Smith
OPAL Architect, IBM.



More information about the Skiboot mailing list