Hi
This repository aims to deliver our kernel debs for QLI, and we will want to eventually implement UEFI secure boot, where the boot firmware can verify the signature of the ESP boot assets.
Implementation is briefly explained here:
https://wiki.debian.org/SecureBoot
https://wiki.ubuntu.com/UEFI/SecureBoot
we need something similar likely with Debusine signing service as the infra instead of DAK (Debian) and Launchpad (Ubuntu).
We will need security reviews from the Qualcomm security groups in charge of infra and product security.
I'm logging this ticket to capture the need to do some research on the implementation of this to be ready for these conversations with our security groups. I expect us to start researching this in September at the earliest.
Hi
This repository aims to deliver our kernel debs for QLI, and we will want to eventually implement UEFI secure boot, where the boot firmware can verify the signature of the ESP boot assets.
Implementation is briefly explained here:
https://wiki.debian.org/SecureBoot
https://wiki.ubuntu.com/UEFI/SecureBoot
we need something similar likely with Debusine signing service as the infra instead of DAK (Debian) and Launchpad (Ubuntu).
We will need security reviews from the Qualcomm security groups in charge of infra and product security.
I'm logging this ticket to capture the need to do some research on the implementation of this to be ready for these conversations with our security groups. I expect us to start researching this in September at the earliest.