diff options
author | California Sullivan <california.l.sullivan@intel.com> | 2017-08-28 15:18:59 -0700 |
---|---|---|
committer | Saul Wold <sgw@linux.intel.com> | 2017-08-30 14:25:24 -0700 |
commit | 7465f7fc99d11f469382bacae514ccfc5006dbe1 (patch) | |
tree | deaa3e1e79fe7f35b2e45e1b6cc2b4710978e7ef /common/recipes-core/ovmf/ovmf-shell-image-enrollkeys.bb | |
parent | b03fee437831c35d7064241703704045d7aa3820 (diff) | |
download | meta-intel-7465f7fc99d11f469382bacae514ccfc5006dbe1.tar.gz |
ovmf: add secureboot bits from refkit
This patch adds a couple secureboot elements to ovmf that originated
from refkit. It includes a patch that adds a certificate to the ovmf's
enrolled keys, and an image recipe which calls the enrollkeys app.
Original work by Mikko Ylinen and Patrick Ohly.
Signed-off-by: California Sullivan <california.l.sullivan@intel.com>
Signed-off-by: Saul Wold <sgw@linux.intel.com>
Diffstat (limited to 'common/recipes-core/ovmf/ovmf-shell-image-enrollkeys.bb')
-rw-r--r-- | common/recipes-core/ovmf/ovmf-shell-image-enrollkeys.bb | 13 |
1 files changed, 13 insertions, 0 deletions
diff --git a/common/recipes-core/ovmf/ovmf-shell-image-enrollkeys.bb b/common/recipes-core/ovmf/ovmf-shell-image-enrollkeys.bb new file mode 100644 index 00000000..b20f6e58 --- /dev/null +++ b/common/recipes-core/ovmf/ovmf-shell-image-enrollkeys.bb | |||
@@ -0,0 +1,13 @@ | |||
1 | require recipes-core/ovmf/ovmf-shell-image.bb | ||
2 | |||
3 | WKS_SEARCH_PATH_append = ":${COREBASE}/meta/recipes-core/ovmf" | ||
4 | |||
5 | QB_DRIVE_TYPE = "/dev/vd" | ||
6 | |||
7 | do_image_append() { | ||
8 | cat > ${IMAGE_ROOTFS}/startup.nsh << EOF | ||
9 | EnrollDefaultKeys | ||
10 | reset | ||
11 | EOF | ||
12 | |||
13 | } | ||