LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Virtualization and Cloud
User Name
Password
Linux - Virtualization and Cloud This forum is for the discussion of all topics relating to Linux Virtualization and Linux Cloud platforms. Xen, KVM, OpenVZ, VirtualBox, VMware, Linux-VServer and all other Linux Virtualization platforms are welcome. OpenStack, CloudStack, ownCloud, Cloud Foundry, Eucalyptus, Nimbus, OpenNebula and all other Linux Cloud platforms are welcome. Note that questions relating solely to non-Linux OS's should be asked in the General forum.

Notices


Reply
  Search this Thread
Old 12-22-2022, 12:45 AM   #1
Outabux
Member
 
Registered: Apr 2003
Location: Greenwood Mississippi
Distribution: Debian.
Posts: 241

Rep: Reputation: 30
Secure Boot & Xen


Was able to get Xen to boot(-)ish without Secure Boot enabled in BIOS. However when trying to use Secure Boot enabled, it failed violating policy as indicated by GRUB. I believed it was that the kernel wasn't signed, so...

Code:
hackwrench@debian:/var/lib/shim-signed/mok$ sudo sbsign --key MOK.priv --cert MOK.pem "/boot/xen-4.16-amd64.efi" --output "/boot/xen-4.16-amd64.efi.tmp"
warning: data remaining[2583552 vs 2853007]: gaps between PE/COFF sections?
warning: data remaining[2583552 vs 2853008]: gaps between PE/COFF sections?
Enter PEM pass phrase:
Signing Unsigned original image

hackwrench@debian:/var/lib/shim-signed/mok$ sbverify --list /boot/xen-4.16-amd64.efi
warning: data remaining[2583552 vs 2853007]: gaps between PE/COFF sections?
warning: data remaining[2583552 vs 2853008]: gaps between PE/COFF sections?
No signature table present

hackwrench@debian:/var/lib/shim-signed/mok$ sbverify --list /boot/xen-4.16-amd64.efi.tmp
warning: data remaining[2585088 vs 2854544]: gaps between PE/COFF sections?
signature 1
image signature issuers:
 - /CN=XXXXXXX
image signature certificates:
 - subject: /CN=XXXXXXX
   issuer:  /CN=XXXXXXX

hackwrench@debian:/var/lib/shim-signed/mok$ sudo mv "/boot/xen-4.16-amd64.efi.tmp" "/boot/xen-4.16-amd64.efi"

hackwrench@debian:/var/lib/shim-signed/mok$ sbverify --list /boot/xen-4.16-amd64.efi
warning: data remaining[2585088 vs 2854544]: gaps between PE/COFF sections?
signature 1
image signature issuers:
 - /CN=XXXXXXX
image signature certificates:
 - subject: /CN=XXXXXXX
   issuer:  /CN=XXXXXXX
got the same results.

EVGA Z590 Dark, 11900KF, Dual 3090 GPUs.

Research hasn't rewarded effort with a solution. All I can seem to find about it online are You-Tube videos of seminars and such. Researching the warning received pretty much just says to ignore them.

Any additional info needed? Any ideas besides disabling Secure Boot altogether?
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
LXer: Learning Xen: Converting Existing Non-Xen Hypervisor Images for Use in Xen LXer Syndicated Linux News 0 08-24-2013 10:00 AM
LXer: Managing Xen With Xen-Tools, Xen-Shell, And Argo LXer Syndicated Linux News 0 11-05-2006 12:21 PM
LXer: Managing Xen With Xen-Tools, Xen-Shell, And Argo LXer Syndicated Linux News 0 10-21-2006 11:33 PM
Phục hồi dữ liệu bị mất???, cứ pollsite General 1 06-27-2005 12:39 PM
Gotta love those ٱٱٱٱٱٱٱ&# iLLuSionZ Linux - General 5 11-18-2003 07:14 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Virtualization and Cloud

All times are GMT -5. The time now is 02:33 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration