Remove 'Extended Security Profile' from installer menu

Bug #1839134 reported by Greg Waines
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
StarlingX
Fix Released
Medium
Kristine Bujold

Bug Description

Brief Description
-----------------
The 'Extended Security Profile' in StarlingX historically included trusted boot (txtboot) support and IMA support. Trusted boot (txtboot) is broken in load and we have decided not to fix it for STX 2.0, and IMA has not been tested in load and likely is broken due to filesystems we have added and removed and again likely have no time to fix it.

However, the 'Extended Security Profile' still shows as an installer menu option in load.

I would recommend that the option be removed for STX2.0 .

Severity
--------
<Minor: System/Feature is usable with minor issue>

Steps to Reproduce
------------------
Install

Expected Behavior
------------------
Need to remove menu for choosing security profile.

Actual Behavior
----------------
Installer menus still present the menu to choose security profile, even though the 'Extended Security Profile' is broken in STX2.0 .

Reproducibility
---------------
100% reproducible

System Configuration
--------------------
All configurations.

Branch/Pull Time/Commit
-----------------------
All loads.

Last Pass
---------
NA

Timestamp/Logs
--------------
NA

Test Activity
-------------
Evaluation

Revision history for this message
Frank Miller (sensfan22) wrote :

Assigning to Kristine to implement this change before stx.2.0 final compile.

Changed in starlingx:
status: New → Triaged
importance: Undecided → Medium
assignee: nobody → Kristine Bujold (kbujold)
tags: added: stx.2.0 stx.config
Changed in starlingx:
status: Triaged → In Progress
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix proposed to metal (master)

Fix proposed to branch: master
Review: https://review.opendev.org/677226

Ghada Khalil (gkhalil)
summary: - Remove 'Extended Security Profile' from installer menu for stx2.0
+ Remove 'Extended Security Profile' from installer menu
Revision history for this message
Ghada Khalil (gkhalil) wrote :

As per agreement with the community, moving all unresolved medium priority bugs from stx.2.0 to stx.3.0

tags: added: stx.3.0
removed: stx.2.0
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix merged to metal (master)

Reviewed: https://review.opendev.org/677226
Committed: https://git.openstack.org/cgit/starlingx/metal/commit/?id=5072a6a8705f88bce5081c5051c8f1ccab8b2e0e
Submitter: Zuul
Branch: master

commit 5072a6a8705f88bce5081c5051c8f1ccab8b2e0e
Author: Kristine Bujold <email address hidden>
Date: Mon Aug 19 10:53:34 2019 -0400

    Remove Extended Security Profile selections

    Remove 'Extended Security Profile' from the BIOS and UEFI installer
    menus.

    Closes-Bug: 1839134

    Change-Id: Iaf2b97c9772e010f3f32e35e1b13a47059ae07e8
    Signed-off-by: Kristine Bujold <email address hidden>

Changed in starlingx:
status: In Progress → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.