Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

WithSecureBootPolicyProfile should accommodate systems that support timestamp revocation #306

Open
chrisccoulson opened this issue May 31, 2024 · 0 comments

Comments

@chrisccoulson
Copy link
Collaborator

chrisccoulson commented May 31, 2024

WithSecureBootPolicyProfile will generate an incorrect profile on systems that support timestamp revocation (ie, that have a dbt database), not that I've seen any of these devices yet. This is detected explicitly in the new pre-install checks I'm working on, disabling support for WithSecureBootPolicyProfile in this case, but support for dbt should probably be added.

Support for timestamp revocation can be detected from the OsIndicationsSupported global variable, which secboot is already looking at.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant