[RFE] Support UEFI secure boot in iRMC drivers

Bug #1694649 reported by Tuan
12
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Ironic
Fix Released
Wishlist
Tuan
python-scciclient
Fix Released
Undecided
Tuan

Bug Description

Some of the Ironic drivers support UEFI secure boot deploy such as ilo drivers [1]. It would be nice to support this feature in iRMC drivers to make sure that baremetal boots using only software, images that is signed by Admin/End user. This RFE proposes to support UEFI secure boot in baremetal provisioning for iRMC drivers.

[1] https://blueprints.launchpad.net/ironic/+spec/uefi-secure-boot

Tuan (tuanla)
tags: added: uefi
Dmitry Tantsur (divius)
Changed in ironic:
status: New → Confirmed
importance: Undecided → Wishlist
Changed in ironic:
assignee: nobody → Tuan (tuanla)
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix proposed to ironic (master)

Fix proposed to branch: master
Review: https://review.openstack.org/480477

Changed in ironic:
status: Confirmed → In Progress
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix merged to python-scciclient (master)

Reviewed: https://review.openstack.org/469408
Committed: https://git.openstack.org/cgit/openstack/python-scciclient/commit/?id=77c2246190225a2a20bbdf2c76aeb9e2a02c5507
Submitter: Jenkins
Branch: master

commit 77c2246190225a2a20bbdf2c76aeb9e2a02c5507
Author: Luong Anh Tuan <email address hidden>
Date: Wed May 31 17:10:40 2017 +0700

    Implements get and set for secure boot mode

    The python-scciclient don't have APIs to support uefi secure boot.
    This patch implements two functions get_secure_boot_mode and
    set_secure_boot_mode for python-scciclient. This patch add common
    functions to support uefi secure boot on iRMC drivers.

    Change-Id: I45edb202623fefffd8947c3e32f99ceb77e59534
    Partial-Bug: #1694649

Tuan (tuanla)
Changed in python-scciclient:
assignee: nobody → Tuan (tuanla)
status: New → Fix Released
Dmitry Tantsur (divius)
tags: added: rfe-approved
removed: rfe
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix merged to ironic (master)

Reviewed: https://review.openstack.org/480477
Committed: https://git.openstack.org/cgit/openstack/ironic/commit/?id=802c86ef045a007adad7f087082928550268b623
Submitter: Jenkins
Branch: master

commit 802c86ef045a007adad7f087082928550268b623
Author: Luong Anh Tuan <email address hidden>
Date: Wed Jul 5 15:21:09 2017 +0700

    Secure boot support for irmc-pxe driver

    This patch adds secure boot support for irmc-pxe boot interface as
    follows:
    - Implement secure boot support for irmc-pxe boot interface
    - Update version of python-scciclient supporting secure boot
    - Update irmc-pxe driver documentation

    Change-Id: Ie82ff07421d23b5c0d26e2d2fbde33fc9f8e3c42
    Partial-Bug: #1694649

Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix proposed to ironic (master)

Fix proposed to branch: master
Review: https://review.openstack.org/507780

Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix merged to ironic (master)

Reviewed: https://review.openstack.org/507780
Committed: https://git.openstack.org/cgit/openstack/ironic/commit/?id=4de908587a35b0c594ba4ed2d599c9f51d465cd8
Submitter: Zuul
Branch: master

commit 4de908587a35b0c594ba4ed2d599c9f51d465cd8
Author: Luong Anh Tuan <email address hidden>
Date: Wed Sep 27 15:02:37 2017 +0700

    Secure boot support for irmc-virtual-media driver

    This patch adds secure boot support for irmc-virtual-media boot interface as
    follows:
    - Implement secure boot support for irmc-virtual-media boot interface
    - Update irmc driver documentation

    Change-Id: I13961aaf6e26591f724d5f52d0a503c71eb6824a
    Closes-Bug: #1694649

Changed in ironic:
status: In Progress → Fix Released
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix included in openstack/ironic 9.2.0

This issue was fixed in the openstack/ironic 9.2.0 release.

To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.