Gentoo Archives: gentoo-user

From: "Rick \\\"Zero_Chaos\\\" Farina" <zerochaos@g.o>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] Re: GPT-UEFI-fstab questions
Date: Thu, 14 Nov 2013 22:13:43
Message-Id: 52854B1E.8050602@gentoo.org
In Reply to: [gentoo-user] Re: GPT-UEFI-fstab questions by James
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA1
3
4 On 11/14/2013 03:32 PM, James wrote:
5 > Rick "Zero_Chaos" Farina <zerochaos <at> gentoo.org> writes:
6 >
7 >>> timeout=5
8 >>> menuentry 'Pentoo' {
9 >>> insmod efi_gop
10 >>> insmod efi_uga
11 >>> insmod part_msdos
12 >>> insmod part_gpt
13 >>> root=(hd0,2)
14 >>> linux /boot/kernel-genkernel-x86_64-3.9.9-pentoo root=/dev/ram0
15 >>> real_root= video= console=tty1 ro
16 >>> initrd /boot/initramfs-genkernel-x86_64-3.9.9-pentoo
17 >>> }
18 >
19 >> I would like to note that in pentoo-installer grub2 is marked
20 >> experimental and I honestly don't expect it to work at all.
21 >
22 >> I am beyond happy to accept patches that fix that, I currently lack time
23 >> and substantial motivation to work on such things. grub1 works.
24 >
25 >> Thanks,
26 >> Zero
27 >
28 > Ahhhhhhhhhhh, you guys do exist; NICE piece of work! Sure, I'll figure it
29
30 We do, we have an irc channel on freenode, a bug tracker on googlecode,
31 and I do a lot of talks at hacker cons.
32
33 > out and drop you a line. It'd be much easier on me if you activated my
34 > request for a dev account......
35
36 Since I don't recognize your name, clearly you should be around my bug
37 tracker or irc more if you want a dev account ;-)
38 >
39 >
40 > Just for the record, quite a few folks are having troubles with (U)EFI
41 > and it appears that the kernel signature is quite often the culprit,
42 > from my preliminary research [1]. You got any comments about that?
43
44 Yes, disable signature verification. It's not possible to boot a
45 self-signed kernel from someone else unless you also add in their
46 certificate to the UEFI and at that point why even bother to sign the
47 thing? Booting a self-signed kernel is cool, but me handing out signed
48 kernels and saying "add this to your UEFI as a valid cert" is exactly as
49 secure as not signing it at all.
50
51 - -Zero
52 -----BEGIN PGP SIGNATURE-----
53 Version: GnuPG v2.0.22 (GNU/Linux)
54 Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/
55
56 iQIcBAEBAgAGBQJShUseAAoJEKXdFCfdEflK54wQAIrsnnReC3WlwwAb1bU7+ETN
57 w6tn6qM9EHUJ/2XkxwhlGLmijakanjgjpTGXIfnaHIpk74U2vLiqe+qyd8Ws9VbX
58 z8Ny5Qie93uCgxycF6/SxYpIZWtC9mrYb+1F26eoEUVri1I1wIjQiHCoMqFHMbAX
59 EWubNwq58ul8B7aNg6DlZCAAW3JZ2WqeG0O2/CK/iDeitD5c9ocWvMWf4LrA6/uK
60 /mwqOCFlWrjsUeKQYm5wyXwE5NeqY1E+e4G219+JUaiD5GHePcVNIrUbt0pIugNp
61 Oy+ntvvrzk5vqPj6466CrTDoY2VI3QEYot4RIi2aUbYdhzMRlkip1l4TZvmNjpET
62 qVSmlZA1P19uKznnYvyGsPF1BHPoplvmCOg1vKBBPh3Sf9KZqYw9w9loa9uIYZaR
63 F3dslFdZCyYOamFbKMTdko3l595kABCQACm4uwYvL795W7MAjiqnlDaUczLkvCdQ
64 MuR8EWO4gVJR2vkOm1a5zZE6+civeUsDu7acLNtDKc7mOtxfl19Fcmhiux6ooGzW
65 dW5KwQdI0CQY6PQ8OYSj6r5jdpH+Vb7vAkbm1z0QuYwuyEMZEUg3+KcJACEV2cRk
66 wVyHJE0SQR6nMz2SfjpkravsxmAGcW9V88y5bXHYT7qw/VmKwfmuVsBi/oQVy88i
67 tQFXDsmLgKH950j5hvk9
68 =Pnd3
69 -----END PGP SIGNATURE-----