Felix Singer has submitted this change. ( https://review.coreboot.org/c/coreboot/+/79684?usp=email )
Change subject: payloads/iPXE: Hook up TRUST_CMD switch ......................................................................
payloads/iPXE: Hook up TRUST_CMD switch
Change-Id: Ia4f5d4140eeb8625c5ee41e38f048658db28a199 Signed-off-by: Maciej Pijanowski maciej.pijanowski@3mdeb.com Reviewed-on: https://review.coreboot.org/c/coreboot/+/79684 Reviewed-by: Felix Singer service+coreboot-gerrit@felixsinger.de Tested-by: build bot (Jenkins) no-reply@coreboot.org --- M payloads/external/Makefile.mk M payloads/external/iPXE/Kconfig M payloads/external/iPXE/Makefile 3 files changed, 13 insertions(+), 0 deletions(-)
Approvals: build bot (Jenkins): Verified Felix Singer: Looks good to me, approved
diff --git a/payloads/external/Makefile.mk b/payloads/external/Makefile.mk index c227402..d497cf8 100644 --- a/payloads/external/Makefile.mk +++ b/payloads/external/Makefile.mk @@ -381,6 +381,7 @@ CONFIG_HAS_SCRIPT=$(CONFIG_IPXE_ADD_SCRIPT) \ CONFIG_IPXE_NO_PROMPT=$(CONFIG_IPXE_NO_PROMPT) \ CONFIG_IPXE_HAS_HTTPS=$(CONFIG_IPXE_HAS_HTTPS) \ + CONFIG_PXE_TRUST_CMD=$(CONFIG_PXE_TRUST_CMD) \ MFLAGS= MAKEFLAGS=
# LinuxBoot diff --git a/payloads/external/iPXE/Kconfig b/payloads/external/iPXE/Kconfig index 2ad39a1..02dce27 100644 --- a/payloads/external/iPXE/Kconfig +++ b/payloads/external/iPXE/Kconfig @@ -108,7 +108,16 @@ Enable HTTPS protocol, which allows you to encrypt all communication with a web server and to verify the server's identity
+config PXE_TRUST_CMD + bool "Enable TRUST commands" + default y + help + Enable imgverify and imgtrust commands, which allow you to verify + digital signature of file prior loading it, and restrict to loading + trusted files only. + endif # BUILD_IPXE + endmenu
endif # PXE diff --git a/payloads/external/iPXE/Makefile b/payloads/external/iPXE/Makefile index 6f5525b..91074fe 100644 --- a/payloads/external/iPXE/Makefile +++ b/payloads/external/iPXE/Makefile @@ -52,6 +52,9 @@ ifeq ($(CONFIG_IPXE_HAS_HTTPS),y) sed -i'' 's|.*DOWNLOAD_PROTO_HTTPS|#define DOWNLOAD_PROTO_HTTPS|g' "$(project_dir)/src/config/general.h" endif +ifeq ($(CONFIG_PXE_TRUST_CMD),y) + sed -i'' 's|.*IMAGE_TRUST_CMD|#define IMAGE_TRUST_CMD|g' "$(project_dir)/src/config/general.h" +endif
build: config $(CONFIG_SCRIPT) ifeq ($(CONFIG_HAS_SCRIPT),y)