Conversation

Currently shopping for ideas and opinons on how `sbctl` should approach the revocation list in Secure Boot (`dbx`).

https://github.com/Foxboron/sbctl/issues/23

Feel free to come with ideas but trying to keep things simple is the goal here.

1
2
0
@Foxboron what would be the time window to give feedback? would need to first get familiar with the tool
1
0
0

@jarkko
Im not rushing this at all so probably a couple of weeks :)

1
0
1
@Foxboron Do you think sbctl could be inducted as part of core systemd? It feels like a good fit.

I just discovered this tool (you don't have time follow everything that is going on).
1
0
0

@jarkko
I don't think a Go codebase belongs in systemd.

1
0
0
@Foxboron I need to play with this tool. I've just used the tool based on what particular distro has as "defacto" such as sbsign, pesign and even scripts/sign-file. I suppose the goal here is to provide "full coverage" over those?

Does this also substitute mokutil?
2
0
0
@Foxboron Considering golang, I just thought that I ask straight from the source: https://mastodon.social/@pid_eins/113976019033445668
0
0
0

@jarkko

Fwiw, systemd implements a sbsign component with keyring caching of secrets.

However sbctl intends to be a key management utility + signing.

I have plans for MOK support.

0
0
1