Comment 6 for bug 1797011

Revision history for this message
Mathieu Trudel-Lapierre (cyphermox) wrote :

Verification-done for mokutil 0.3.0+1538710437.fb6250f-0ubuntu2~18.04.1 on bionic:

I have verified that timeout, export, and reset / toggle-validation features in mokutil all work, as a verification for the new features and smoketesting for the existing features already in use.

When using timeout, export, reset and toggle-validation, mokutil correctly writes the variables in the firmware that cause the system to boot next into MokManager to process the requests.

ubuntu@lucky-moth:~$ apt-cache policy mokutil
mokutil:
  Installed: 0.3.0+1538710437.fb6250f-0ubuntu2~18.04.1
  Candidate: 0.3.0+1538710437.fb6250f-0ubuntu2~18.04.1
  Version table:
 *** 0.3.0+1538710437.fb6250f-0ubuntu2~18.04.1 501
         -1 http://archive.ubuntu.com/ubuntu bionic-proposed/main amd64 Packages
        100 /var/lib/dpkg/status
     0.3.0-0ubuntu5 500
        500 http://archive.ubuntu.com/ubuntu bionic/main amd64 Packages

ubuntu@lucky-moth:~$ sudo mokutil --export --kek
ubuntu@lucky-moth:~$ openssl x509 -inform DER -in KEK-0001.der -text -noout
Certificate:
    Data:
        Version: 1 (0x0)
        Serial Number:
            94:cb:af:49:cd:56:a7:d8
    Signature Algorithm: sha256WithRSAEncryption
        Issuer: CN = Ubuntu OVMF Secure Boot (PK/KEK key), emailAddress = <email address hidden>
        Validity
            Not Before: Jun 20 21:48:46 2018 GMT
            Not After : Jun 17 21:48:46 2028 GMT
        Subject: CN = Ubuntu OVMF Secure Boot (PK/KEK key), emailAddress = <email address hidden>
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (2048 bit)
                Modulus:
[...]