------- Comment on attachment From <email address hidden> 2020-04-03 03:05 EDT-------
Hi Seth,
Thanks, that was extremely helpful.
Nayna noticed that I was overly keen to lock things down - I should only lock down in Secure mode: if a system is in Trusted mode only I shouldn't lock it down. This now matches the UEFI behaviour: (AFAICT) measurements are made unconditionally but lockdown only occurs in Secure Boot mode.
------- Comment on attachment From <email address hidden> 2020-04-03 03:05 EDT-------
Hi Seth,
Thanks, that was extremely helpful.
Nayna noticed that I was overly keen to lock things down - I should only lock down in Secure mode: if a system is in Trusted mode only I shouldn't lock it down. This now matches the UEFI behaviour: (AFAICT) measurements are made unconditionally but lockdown only occurs in Secure Boot mode.
I have updated patch 1/2.
Kind regards,
Daniel