Bug 43469 - Sign kernel modules for UEFI Secure Boot
Sign kernel modules for UEFI Secure Boot
Status: CLOSED FIXED
Product: UCS
Classification: Unclassified
Component: Kernel
UCS 4.2
Other Linux
: P5 normal (vote)
: UCS 4.2
Assigned To: Stefan Gohmann
Janek Walkenhorst
: interim-1
Depends on:
Blocks: 42048
  Show dependency treegraph
 
Reported: 2017-02-01 13:44 CET by Stefan Gohmann
Modified: 2017-04-04 18:29 CEST (History)
0 users

See Also:
What kind of report is it?: Development Internal
What type of bug is this?: ---
Who will be affected by this bug?: ---
How will those affected feel about the bug?: ---
User Pain:
Enterprise Customer affected?:
School Customer affected?:
ISV affected?:
Waiting Support:
Flags outvoted (downgraded) after PO Review:
Ticket number:
Bug group (optional):
Max CVSS v3 score:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Stefan Gohmann univentionstaff 2017-02-01 13:44:46 CET
Currently, the sign modules patch is disabled in our UCS 4.2 kernel build:
 linux/4.2-0-0-ucs/4.9.2-2/50_enable_module_sig.patch.disable

The build failed with the following message:

 dh_installdocs --link-doc=linux-headers-4.9.0-ucs100-common
dh_installdocs: WARNING: --link-doc between architecture all and not all packages breaks binNMUs
  INSTALL arch/x86/crypto/aes-i586.ko
  INSTALL arch/x86/crypto/aes-i586.ko
At main.c:158:
- SSL error:02001002:system library:fopen:No such file or directory: bss_file.c:168
- SSL error:2006D080:BIO routines:BIO_new_file:no such file: bss_file.c:171
sign-file: : No such file or directory
/var/build/temp/tmp.lrkU1tBa0j/linux-4.9.2/scripts/Makefile.modinst:35: recipe for target 'arch/x86/crypto/aes-i586.ko' failed
Comment 1 Stefan Gohmann univentionstaff 2017-02-01 13:46:15 CET
Log file:
 /var/univention/buildsystem2/logs/ucs_4.2-0-0/linux_4.9.2-2A~4.2.0.201702010641.log.bz2
Comment 2 Stefan Gohmann univentionstaff 2017-02-01 13:52:40 CET
It blocks already our preview kernel.
Comment 3 Stefan Gohmann univentionstaff 2017-02-02 10:20:07 CET
I've adjusted the patch: r17147 + r17148
Comment 4 Janek Walkenhorst univentionstaff 2017-02-02 12:47:45 CET
Patch review: OK
Tests: OK
Comment 5 Stefan Gohmann univentionstaff 2017-04-04 18:29:59 CEST
UCS 4.2 has been released:
 https://docs.software-univention.de/release-notes-4.2-0-en.html
 https://docs.software-univention.de/release-notes-4.2-0-de.html

If this error occurs again, please use "Clone This Bug".