[Bug 1996069] [NEW] [UBUNTU 20.04] zipl: Add secure boot trailer (s390-tools part)

Launchpad Bug Tracker 1996069 at bugs.launchpad.net
Thu Nov 10 13:17:46 UTC 2022


You have been subscribed to a public bug:

Description:   zipl: Add secure boot trailer

Symptom:       Secure boot of Linux will no longer be possible with an upcoming
               IBM Z firmware update.

Problem:       New IBM Z firmware requires all signed boot images to contain a
               trailing data block with a specific format.

Solution:      Add trailing data block to the zipl stage 3 boot loader image.
Reproduction:  Apply latest firmware, perform IPL with Secure Boot enabled.

Fix:           Available upstream with
Upstream-ID:   5768d55a08e163f718bd87498b9e763687ae7137

Upstream-Description:

              zipl/boot: add secure boot trailer

              This patch enhances the zipl stage3 loader image adding a trailer as
              required for secure boot by future firmware versions.

              Note: with the change in this patch the padding via objcopy command line
              options is replaced by padding via linker script directives with the
              same effect.

              Signed-off-by: Peter Oberparleiter <oberpar at linux.ibm.com>
              Signed-off-by: Jan Hoeppner <hoeppner at linux.ibm.com>


Signed-off-by: Peter Oberparleiter <oberpar at linux.ibm.com>

** Affects: ubuntu-z-systems
     Importance: Undecided
     Assignee: Skipper Bug Screeners (skipper-screen-team)
         Status: New

** Affects: s390-tools (Ubuntu)
     Importance: Undecided
         Status: New


** Tags: architecture-s39064 bugnameltc-200453 severity-high targetmilestone-inin---
-- 
[UBUNTU 20.04] zipl: Add secure boot trailer  (s390-tools part)
https://bugs.launchpad.net/bugs/1996069
You received this bug notification because you are a member of Ubuntu Foundations Bugs, which is subscribed to s390-tools in Ubuntu.



More information about the foundations-bugs mailing list