Skip to content

Secure Boot booting files with custom PK fails due to "Access Denied" #1729

@philipanda

Description

@philipanda

Component

Dasharo firmware

Device

NovaCustom V56 14th Gen

Dasharo version

v1.0.0-rc10

Dasharo Tools Suite version

na

Test case ID

SBO

Brief summary

All sb_test_data "hello-dasharo" binaries fail to boot due to "Access Denied", no matter whether signed correctly, signed with a wrong key, or not signed at all.

Might be an issue with https://github.com/Dasharo/osfv-test-data/, but using sbverify on the certificates and binaries created there works fine

How reproducible

100%

How to reproduce

Create the test files using instructions from osfv-test-data/secure-boot/README

Expected behavior

all tests pass - with custom keys the hello-dasharo-signed-good.efi boots, but hello-dasharo-signed-bad.efi and hello-dasharo.efi don't.

Actual behavior

None boots, all due to "Access Denied"

Screenshots

No response

Additional context

No response

Solutions you've tried

Verifying the file signatures using sbverify

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions