Page MenuHomeVyOS Platform

add secure boot support
Closed, ResolvedPublicFEATURE REQUEST

Details

Version
-
Is it a breaking change?
Perfectly compatible
Issue type
Feature (new functionality)

Event Timeline

There are a very large number of changes, so older changes are hidden. Show Older Changes

On systems that do not support SecureBoot, mokutil will exit with code 255. This causes show version to break as the cmd() that launches it raises an error. The mokutil execution through cmd() should catch that return code as normal:

--- a/python/vyos/utils/system.py   2024-10-26 23:23:07.040947969 +0000
+++ b/python/vyos/utils/system.py 2024-10-26 23:23:28.131947969 +0000
@@ -145,5 +145,5 @@
     from vyos.utils.boot import is_uefi_system
     if not is_uefi_system():
         return False
-    tmp = cmd('mokutil --sb-state')
+    tmp = cmd('mokutil --sb-state', expect=[255])
     return bool('enabled' in tmp)
This comment was removed by tuxnet.

SHIM accepted by review-board

syncer changed the task status from Needs testing to In progress.Mar 27 2026, 10:09 PM
syncer raised the priority of this task from Wishlist to Normal.

Hi,

Re "Kernel: T861: add custom VyOS CA to Kernel builds for later module signing". Does this enable me to sign my Realtek .deb package? At the moment I have to create a custom kernel with CONFIG_MODULE_SIG_FORCE disabled for it to load.

If so, could you give me a steer as to how to go about it please.

SteveP

@SteveP no. This would require us to give you HSM access for signing modules, which is not possible.

Compiling a custom kernel is not necessary. Either supply a PR so we can integrate those realtek drivers if needed - which are those? Or disable module signature verification on the Kernel cmdline.

Hi,

That's as I thought so that's fine.

There is nothing special about the driver I'm running. Sometimes I just want to run a newer one before you get around to it. However, the driver does encounter this race condition https://vyos.dev/T6856 and I get around it by loading the driver like this:

dpkg -i --path-exclude=/etc/udev/rules.d/50-usb-realtek-net.rules /opt/vyatta/etc/config/user-data/vyos-drivers-realtek-r8152_$new_mod_ver-1_amd64.deb

SteveP

Added repo to build VyOS custom shim-signed Debian package from repo https://github.com/vyos/shim-signed/ with our own signed SHIM.