Comment 24 for bug 1904906

Revision history for this message
bugproxy (bugproxy) wrote : Comment bridged from LTC Bugzilla

------- Comment From <email address hidden> 2021-02-16 20:13 EDT-------
I retested this with my pseries secure boot setup. I built the key from the PPA into grub and signed grub with the testing key which I built into SLOF.

I was then able to boot 5.11.0-9-generic in secure boot mode and without secure boot under P8 KVM.

The kernel correctly detected secure boot mode and entered lockdown.

Lockdown appears to work as expected, I can't open /dev/mem for example.

In summary, I don't see anything from booting with secure boot on or off that would prevent you promoting 5.11 for hirsute.

Kind regards,
Daniel