Skip to content

Boot: Microsoft shim-review submission (Path D) #12

Description

@lamco-office

Submit a LamBoot-specific shim binary to rhboot/shim-review for Microsoft UEFI CA signing.

Motivation

Today LamBoot requires MOK enrollment (or a firmware-db cert) for Secure Boot. A shim accepted through shim-review and signed by the Microsoft UEFI CA broadens the trust baseline to Microsoft-signed level and removes the MOK-enrollment step for most users — the difference between a niche retrofit and a drop-in bootloader on stock SB hardware. It would also be the first Rust bootloader accepted through shim-review.

Prerequisites (shim-review checklist)

  • Reproducible build pipeline (Cargo.lock pinning, deterministic build env, SBAT discipline)
  • SBAT entries registered and maintained (generation policy already documented)
  • Public audit trail (signed commits, release notes)
  • Documented security threat model
  • Multiple committed maintainer contacts
  • Update + key-rotation process documented

Timing

Post-v1.0, after the bootloader has had a few months of field deployment to satisfy the stability bar reviewers look for. Tracking issue; sub-tasks filed as each prerequisite is worked.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:bootBootloader main loop, kernel handofftype:enhancementNew feature or requesttype:trackingParent issue grouping related sub-tasks

    Type

    No type

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions