integ/security
Li Zhou 0535f5b0ae Debian: shim-unsigned: porting from LAT
This is done for moving packages that are related to secure boot
out of LAT and into integ.

Use shim version: 15+1533136590.3beb971.

Although there was a debian package for shim here, it wasn't
effective because LAT didn't use it (the shim version in use is
12+gitAUTOINC+5202f80c32). So I abandon it and choose a proper
version for this porting.
I choose this version because it should be matched with the grub image.
shim 15.3 introduced and now mandates SBAT.
This means that shim 15.3+ will not launch any EFI binaries
without a .sbat section.

Use tis-shim.der (another format for tis-shim.crt) to verify grub
image's signature.

Test Plan:
 The tests are done with all the changes for this porting,
 which involves efitools/shim/grub2/grub-efi/lat-sdk.sh, because
 they are in a chain for secure boot verification.
 - PASS: secure boot OK on qemu.
 - PASS: secure boot OK on PowerEdge R430 lab.
 - PASS: secure boot NG on qemu/hardware when shim/grub-efi images
         are without the right signatures.

Story: 2009221
Task: 46401

Signed-off-by: Li Zhou <li.zhou@windriver.com>
Change-Id: I2449ac9bbad7635b095a66309f77765a8a01cd1b
2022-09-29 23:47:27 -04:00
..
efitools/debian Debian: efitools: add initial version 2022-09-29 23:46:49 -04:00
keyrings.alt/debian meta_data.yaml: add sha256sum checksum 2022-03-03 14:30:40 +08:00
libtpms/centos Add auto-versioning to starlingx/integ packages 2020-06-24 09:48:28 +08:00
openscap/debian debian: Add missing openscap package 2022-05-24 10:14:51 -04:00
python-keyring Determine the SW_VERSION at run time 2022-04-23 08:36:05 +08:00
shim-signed/centos relocate /pxeboot to /var/pxeboot 2021-12-23 14:29:00 -05:00
shim-unsigned Debian: shim-unsigned: porting from LAT 2022-09-29 23:47:27 -04:00
spectre-meltdown-checker/centos Add auto-versioning to starlingx/integ packages 2020-06-24 09:48:28 +08:00
swtpm Revert "Fix user ownership for /usr/bin/swtpm_setup.sh" 2020-11-04 20:04:28 +00:00
tboot/centos Add auto-versioning to starlingx/integ packages 2020-06-24 09:48:28 +08:00
tpm2-tools Add auto-versioning to starlingx/integ packages 2020-06-24 09:48:28 +08:00
tss2 Add auto-versioning to starlingx/integ packages 2020-06-24 09:48:28 +08:00