Bug 35916 - Sign kernel for UEFI Secure Boot
Sign kernel for UEFI Secure Boot
Status: CLOSED FIXED
Product: UCS
Classification: Unclassified
Component: Kernel
UCS 4.0
Other Linux
: P5 normal (vote)
: UCS 4.0
Assigned To: Janek Walkenhorst
Stefan Gohmann
: interim-3
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2014-09-12 09:41 CEST by Stefan Gohmann
Modified: 2014-11-26 06:54 CET (History)
1 user (show)

See Also:
What kind of report is it?: ---
What type of bug is this?: ---
Who will be affected by this bug?: ---
How will those affected feel about the bug?: ---
User Pain:
Enterprise Customer affected?:
School Customer affected?:
ISV affected?:
Waiting Support:
Flags outvoted (downgraded) after PO Review:
Ticket number:
Bug group (optional):
Max CVSS v3 score:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Stefan Gohmann univentionstaff 2014-09-12 09:41:48 CEST
The kernel has to be signed.
Comment 1 Stefan Gohmann univentionstaff 2014-11-04 08:45:38 CET
grub2: r14014 + r14015 + r14017 + r14018:

Switch back to debian source format 3.0 quilt and adjust the patches. This was necessary so that the new linuxefi patches are used.
Comment 2 Janek Walkenhorst univentionstaff 2014-11-04 13:48:03 CET
univention-kernel-image-signed provides the signed kernel as ".efi.signed".
univention-kernel-image depends on -signed.
Comment 3 Felix Botner univentionstaff 2014-11-07 09:51:48 CET
On i386 i get 

The following packages have unmet dependencies:
 univention-kernel-image : Depends: linux-image-3.16-ucs102-686-pae-signed but it is not installable
Comment 4 Janek Walkenhorst univentionstaff 2014-11-07 18:43:50 CET
(In reply to Felix Botner from comment #3)
> On i386 i get 
> 
> The following packages have unmet dependencies:
>  univention-kernel-image : Depends: linux-image-3.16-ucs102-686-pae-signed
> but it is not installable

linux-image-3.16-ucs83-686-pae is the last "maintained", all later kernel images are in "unmaintained". This is because the latest i386 DVD built is too old.
→ Bug #36527
Comment 5 Stefan Gohmann univentionstaff 2014-11-17 09:13:25 CET
OK, that works.
Comment 6 Stefan Gohmann univentionstaff 2014-11-26 06:54:12 CET
UCS 4.0-0 has been released:
 http://docs.univention.de/release-notes-4.0-0-en.html
 http://docs.univention.de/release-notes-4.0-0-de.html

If this error occurs again, please use "Clone This Bug".