[Skiboot] [PATCH] libstb/secureboot: Disable secureboot in OPAL by nvram

ppaidipe ppaidipe at linux.vnet.ibm.com
Mon May 28 16:41:52 AEST 2018


On 2018-05-28 07:39, Stewart Smith wrote:
> Pridhiviraj Paidipeddi <ppaidipe at linux.vnet.ibm.com> writes:
>> Currently custom debug petitboot kernels failed to boot on secureboot
>> enabled systems as the key verification fails results in enforcing the
>> boot. Due to which debugging any problems in petitboot kernel in 
>> secure
>> boot enabled systems become hard.
>> This patch provides a way to disable secureboot in OPAL by using below
>> nvram command.
>> nvram -p ibm,skiboot --update-config force-secure-mode=false
> 
> As mentioned by others, this isn't something I can take for upstream as
> it really does bypass the point of secure mode.

Okay, thanks.



More information about the Skiboot mailing list