f0315b4ed4
This fix prevents loading of unsigned ubuntu kernel in UEFI secure boot environment when image is created using 'iso' element. 'iso' element uses 'linux' and 'initrd' modules of grub2 to load kernel and initrd respectively. The grub2 implementation of Ubuntu can load unsigned kernel when these modules are used. Ubuntu has Grub2 modules 'linuxefi' and 'initrdefi' which exits boot process if unsigned kernel is used in UEFI secure boot mode. The 'iso' element should use these modules in grub.cfg to prevent loading of unsigned kernel when node is booted in the UEFI secure boot environment. 'linuxefi' and 'initrdefi' works seamlessly when node is booted in normal UEFI boot mode (non-secure). Fedora do not have this issue. This fix has been tested in Fedora environment. It works fine. Closes-Bug: 1443114 Change-Id: If256ba1f7d7c149482d0f37fabcdfa8ed22e3f91 |
||
---|---|---|
.. | ||
100-build-iso |