Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Generating revocations.efi documentation #662

Open
514amir opened this issue May 28, 2024 · 2 comments
Open

Generating revocations.efi documentation #662

514amir opened this issue May 28, 2024 · 2 comments
Assignees

Comments

@514amir
Copy link

514amir commented May 28, 2024

There is no explicit documentation I can find on how to generate revocations.efi which gets looked for by shim 15.8 at least during a PXE boot. It throws a warning and I'd prefer to not have the warning. I've seen the documentation on updating the revocation list but I am not sure how it applies to revocations.efi

@jsetje jsetje self-assigned this Jun 10, 2024
@jsetje
Copy link
Collaborator

jsetje commented Jun 10, 2024

I have some docs on this coming, although the PXE warning is a pretty special case. If we go looking for the file during PXE and it's not there, which is likely the common case, there will be a warning, since there is not readdir support there.

@christoph-at-unicon
Copy link

I'd like to chime in - users here are quite disturbed about the error message shim shows when booting via PXE.
Can you at least provide an (logically) empty revocations.efi? From reading the source, it has to be a signed EFI file, and if the sections that hold the data are missing, that's not really a problem.
So there's a workaround: Copy an already signed efi program (I abused fbx64.efi) to revocations.efi. But that's not something I really want to do.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants