Skip to content

Comments

efi/preinstall: Add the Microsoft 2023 option ROM UEFI CA#507

Merged
chrisccoulson merged 1 commit intocanonical:masterfrom
chrisccoulson:preinstall-add-ms-option-rom-uefi-ca
Feb 13, 2026
Merged

efi/preinstall: Add the Microsoft 2023 option ROM UEFI CA#507
chrisccoulson merged 1 commit intocanonical:masterfrom
chrisccoulson:preinstall-add-ms-option-rom-uefi-ca

Conversation

@chrisccoulson
Copy link
Collaborator

The 2023 UEFI CAs have been split into one that is used to sign boot
code, and one that is used to sign option ROMs. Although what they sign
isn't audit-able, knowing this allows us to optimise PCR selection a
bit:

  • Because the 2023 UEFI CA is only used to sign boot code, we can mark
    it trusted for signing drivers, which means its use doesn't require us
    to lock policies to PCR2.
  • Because the 2023 option ROM UEFI CA is only used to sign option ROMs,
    we can mark it trusted for signing boot code, which means its use
    doesn't require us to lock policies to PCR4.

Fixes: FR-12523

The 2023 UEFI CAs have been split into one that is used to sign boot
code, and one that is used to sign option ROMs. Although what they sign
isn't audit-able, knowing this allows us to optimise PCR selection a
bit:
- Because the 2023 UEFI CA is only used to sign boot code, we can mark
  it trusted for signing drivers, which means its use doesn't require us
  to lock policies to PCR2.
- Because the 2023 option ROM UEFI CA is only used to sign option ROMs,
  we can mark it trusted for signing boot code, which means its use
  doesn't require us to lock policies to PCR4.

Fixes: FR-12523
Copy link
Collaborator

@pedronis pedronis left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

thanks

@chrisccoulson chrisccoulson merged commit e6bd4a4 into canonical:master Feb 13, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants