Correction on Secure Boot Article

Posted by tuxchick on Dec 5, 2012 6:05 PM
LXer Feature; By Carla Schroder

LXer Feature: 05-Dec-2012

This is an important correction to "Linux Has Not Won, Microsoft is as Dangerous as Ever, Fie on Secure Boot" that explains correctly how the Platform Key works.

In Linux Has Not Won, Microsoft is as Dangerous as Ever, Fie on Secure Boot I incorrectly described how the Secure Boot Platform Key works. A reader gave me the correct description:

Quoting: The platform key is the firmware vendor's key. Each motherboard will have a platform key controlled by the firmware provider. That key is used to sign the actual SB keys packaged with the system at ship time. Microsoft has no involvement in that at all, except to ask the vendors to sign their key. If the mobo vendor wants to include Microsoft's key, they put it in the list and sign it with the platform key. If they want to include anyone else's key - as well as or instead of Microsoft's key - they put it in the list and sign it with the platform key. The firmware vendor controls the platform key, not Microsoft. The presence of a platform key is an inevitability of any design based around signatures, not a Microsoft plot. The concept that the single platform key controlled by the firmware vendor is used to sign *multiple* OS vendor keys is expressly designed to allow multiple keys to be trusted 'from the factory', precisely the opposite of what you suggest in the article.

This is the only plausible way to design it: it's just the root of the trust chain. There has to be one in any chain of trust. The only possible choices for who should own the trust root are a) the vendor of the firmware and b) the user, and Secure Boot expressly allows for both.


So it is not correct to call it a Windows Platform Key, because there is no such thing. It is important to get this right because it is fundamental to how Secure Boot works.

Return to the LXer Features

Subject Topic Starter Replies Views Last Post
In that scenario, nmset 4 523 Dec 6, 2012 2:28 PM
Linux in general bunker85 0 417 Dec 6, 2012 8:34 AM

You cannot post until you login.

LXer

  Latest Features
ubuuser: The good and bad of Ubuntu 13.04 beta 2
Apr 15, 2013

Scott Ruecker (Phoenix, U.S.): LXer Weekly Roundup for 10-Mar-2013
Mar 11, 2013

Scott Ruecker (Phoenix, U.S.): LXer Weekly Roundup for 03-Mar-2013
Mar 03, 2013

: Ubuntu Touch Developer Preview released
Feb 21, 2013

Scott Ruecker (Phoenix, U.S.): LXer Weekly Roundup for 17-Feb-2013
Feb 18, 2013

Scott Ruecker (Phoenix, U.S.): LXer Weekly Roundup for 03-Feb-2013
Feb 04, 2013

Nick Black, SprezzOS Project Hacker-in-Charge: SprezzOS emerges, promising new-school tech with old-school gumption
Feb 02, 2013

Scott Ruecker (Phoenix, U.S.): LXer Weekly Roundup for 27-Jan-2013
Jan 28, 2013

Scott Ruecker (Phoenix, U.S.): LXer Weekly Roundup for 20-Jan-2013
Jan 21, 2013

ubuuser: Ubuntu releasing smartphone OS has better chance than other platforms
Jan 09, 2013


View all

  Search Features

Search LXer Features:

[ Copyright © LXer | All times are recorded in Central Daylight Time (CDT) ]

[ Contact Us | Privacy Policy | Terms of Service | About us | rss | Mobile ]

Login