You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Use either Microsoft or Mosby's UEFI VendorGUID when adding certificates
* Mosby derived the ESL GUID from the certificate fingerprint, which means that each of the
Microsoft certificates added to the KEK or DB were referenced under their own unique GUID,
which had nothing to do with the originator of the certificate (Microsoft).
* Outside of not trying to go with UEFI best practices, this is also problematic with tools
like fwupdmgr, that try to resolve the VendorGuid to known vendors when reporting back to
the user.
* So we now make sure that we don't derive the GUID from the data, but instead use a proper
VendorGUID when none is defined, which will be Microsoft's for the DB and KEK certs, and
our own for the PK and additional DB cert.
* Closes#15.
0 commit comments