-
Notifications
You must be signed in to change notification settings - Fork 144
Open
Labels
Accredited review neededNeeds a successful review by an accredited reviewerNeeds a successful review by an accredited reviewercontacts verified OKContact verification is complete here (or in an earlier submission)Contact verification is complete here (or in an earlier submission)easy to reviewThis submission might be a good place to start for an inexperienced reviewerThis submission might be a good place to start for an inexperienced reviewer
Description
Confirm the following are included in your repo, checking each box:
- completed README.md file with the necessary information
- shim.efi to be signed
- public portion of your certificate(s) embedded in shim (the file passed to VENDOR_CERT_FILE)
- binaries, for which hashes are added to vendor_db ( if you use vendor_db and have hashes allow-listed )
- any extra patches to shim via your own git tree or as files
- any extra patches to grub via your own git tree or as files
- build logs
- a Dockerfile to reproduce the build of the provided shim EFI binaries
What is the link to your tag in a repo cloned from rhboot/shim-review?
https://github.com/vathpela/shim-review/tree/fedora-aa64-20250818
What is the SHA256 hash of your final SHIM binary?
$ sha256sum shimaa64.efi
2150f40827596da0ceec0c8e899f1ef1d3220dd58c52fb91991ec0faaa6f7744 shimaa64.efi
$ pesign -h -P -i shimaa64.efi
b133efe85567e402e1aae1fd5ac11ec2f74d82bd4cacbd1a860522092b5b11cb shimaa64.efi
What is the link to your previous shim review request (if any, otherwise N/A)?
#386 (fedora for x86_64)
If no security contacts have changed since verification, what is the link to your request, where they've been verified (if any, otherwise N/A)?
Same security contacts as before.
Metadata
Metadata
Assignees
Labels
Accredited review neededNeeds a successful review by an accredited reviewerNeeds a successful review by an accredited reviewercontacts verified OKContact verification is complete here (or in an earlier submission)Contact verification is complete here (or in an earlier submission)easy to reviewThis submission might be a good place to start for an inexperienced reviewerThis submission might be a good place to start for an inexperienced reviewer