[Bug 1811496] Re: Make grub-ipxe work under UEFI

Steve Langasek steve.langasek at canonical.com
Mon Feb 4 20:46:44 UTC 2019


As discussed on IRC, we are not going to sign multiple bootloader
implementations with the key because this would increase the attack
surface of UEFI Secure Boot (which is already quite large, but signing
multiple competing bootloader implementations would be an unforced
error).

If there are features missing from grub, that should be addressed as a
bug in grub.

We do publish a signed grub image suitable for netbooting use.
http://archive.ubuntu.com/ubuntu/dists/disco/main/uefi/grub2-amd64/current/grubnetx64.efi.signed

-- 
You received this bug notification because you are a member of Ubuntu
Sponsors Team, which is subscribed to the bug report.
https://bugs.launchpad.net/bugs/1811496

Title:
  Make grub-ipxe work under UEFI

Status in ipxe package in Ubuntu:
  New

Bug description:
  Please update /etc/grub.d/20_ipxe so that:
  1) It uses ipxe.efi under UEFI, so that it works under UEFI as well, and
  2) It loads /boot/boot.ipxe as an initrd if the user provided a custom ipxe script there.

  Snippets - to be ran from /boot/grub/grub.cfg, as it's possible to
  dynamically switch bios/uefi in firmware settings:

  if [ "$grub_platform" = "efi" ]; then
    chainloader /boot/ipxe.efi
  else
    linux16 /boot/ipxe.lkrn
    if [ -f /boot/boot.ipxe ]; then
      initrd16 /boot/boot.ipxe
    fi
  fi

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ipxe/+bug/1811496/+subscriptions



More information about the Ubuntu-sponsors mailing list