Bug 11535

Summary: RMC: [EFI] Verify data store integrity (secure boot)
Product: [Build System, Metadata & Runtime] BSPs Reporter: Todor Minchev <todor.minchev>
Component: bsps-meta-intelAssignee: Unassigned <unassigned>
Status: RESOLVED OBSOLETE QA Contact:
Severity: enhancement    
Priority: Medium CC: bluelightning, richard.purdie, tim.orling
Version: 2.4   
Target Milestone: Future   
Hardware: x86   
OS: Multiple   
Whiteboard:
OS type for building Yocto: --- Type of Regression: ---
Verified: Documentation change: Yes (doc changes required)

Description Todor Minchev 2017-05-18 17:31:30 UTC
When running in secure boot mode, RMC.efi has to verify the integrity of the data store. This involves generating and MD5 hash over the contents of the data store and comparing it to the MD5 has stored in the RMC.efi PE header (last field in data directories).

https://en.wikipedia.org/wiki/Portable_Executable#/media/File:Portable_Executable_32_bit_Structure_in_SVG_fixed.svg

If the system is running in secure boot mode and the two hashes do not match the boot process should be terminated with an appropriate message to the user.
Comment 1 Tim Orling 2020-06-25 08:43:25 UTC
Work on RMC has been discontinued and it is no longer supported.