<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugzilla.yoctoproject.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.6"
          urlbase="https://bugzilla.yoctoproject.org/"
          
          maintainer="it-coreprojects-helpdesk@linuxfoundation.org"
>

    <bug>
          <bug_id>11535</bug_id>
          
          <creation_ts>2017-05-18 17:31:30 +0000</creation_ts>
          <short_desc>RMC: [EFI] Verify data store integrity (secure boot)</short_desc>
          <delta_ts>2020-06-25 08:43:25 +0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>7</classification_id>
          <classification>Build System, Metadata &amp; Runtime</classification>
          <product>BSPs</product>
          <component>bsps-meta-intel</component>
          <version>2.4</version>
          <rep_platform>x86</rep_platform>
          <op_sys>Multiple</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>OBSOLETE</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>Medium</priority>
          <bug_severity>enhancement</bug_severity>
          <target_milestone>Future</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Todor Minchev">todor.minchev</reporter>
          <assigned_to name="Unassigned">unassigned</assigned_to>
          <cc>bluelightning</cc>
    
    <cc>richard.purdie</cc>
    
    <cc>tim.orling</cc>
          
          
          <cf_os>---</cf_os>
          <cf_regression_type>---</cf_regression_type>
          
          <cf_docchange>Yes (doc changes required)</cf_docchange>

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>73351</commentid>
    <comment_count>0</comment_count>
    <who name="Todor Minchev">todor.minchev</who>
    <bug_when>2017-05-18 17:31:30 +0000</bug_when>
    <thetext>When running in secure boot mode, RMC.efi has to verify the integrity of the data store. This involves generating and MD5 hash over the contents of the data store and comparing it to the MD5 has stored in the RMC.efi PE header (last field in data directories).

https://en.wikipedia.org/wiki/Portable_Executable#/media/File:Portable_Executable_32_bit_Structure_in_SVG_fixed.svg

If the system is running in secure boot mode and the two hashes do not match the boot process should be terminated with an appropriate message to the user.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>87613</commentid>
    <comment_count>1</comment_count>
    <who name="Tim Orling">tim.orling</who>
    <bug_when>2020-06-25 08:43:25 +0000</bug_when>
    <thetext>Work on RMC has been discontinued and it is no longer supported.</thetext>
  </long_desc>
      
      

    </bug>

</bugzilla>