Bug 11535 - RMC: [EFI] Verify data store integrity (secure boot)
Summary: RMC: [EFI] Verify data store integrity (secure boot)
Status: RESOLVED OBSOLETE
Alias: None
Product: BSPs
Classification: Build System, Metadata & Runtime
Component: bsps-meta-intel (show other bugs)
Version: 2.4
Hardware: x86 Multiple
: Medium enhancement
Target Milestone: Future
Assignee: Unassigned
QA Contact:
URL:
Whiteboard:
Depends on:
Blocks:
 
Reported: 2017-05-18 17:31 UTC by Todor Minchev
Modified: 2020-06-25 08:43 UTC (History)
3 users (show)

See Also:
OS type for building Yocto: ---
Type of Regression: ---
Verified:
Documentation change: Yes (doc changes required)


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Todor Minchev 2017-05-18 17:31:30 UTC
When running in secure boot mode, RMC.efi has to verify the integrity of the data store. This involves generating and MD5 hash over the contents of the data store and comparing it to the MD5 has stored in the RMC.efi PE header (last field in data directories).

https://en.wikipedia.org/wiki/Portable_Executable#/media/File:Portable_Executable_32_bit_Structure_in_SVG_fixed.svg

If the system is running in secure boot mode and the two hashes do not match the boot process should be terminated with an appropriate message to the user.
Comment 1 Tim Orling 2020-06-25 08:43:25 UTC
Work on RMC has been discontinued and it is no longer supported.