Re: [PATCH] Fix kexec forbidding kernels signed with custom platform keys to boot

From: Yannik Sembritzki
Date: Wed Aug 15 2018 - 18:14:56 EST


On 15.08.2018 23:57, Vivek Goyal wrote:
> Aha.., so that's your real problem. You are trying to load VirtualBox
> module and that will not load even if you take ownership of platform
> by adding your key and sign module with that key.
>
> So this patch still will not fix the problem you are facing. It is still
> good to fix the case of kexec/kdump broken on Fedora on secureboot
> machines.

No, I wrote this patch specifically because because of the kexec issue
and would like to seem them merged to fix exactly that :-)

I only replied to the module signing discussion as there were some
ongoing arguments with regard to that. IMO this is resolved with the
patches by Mehmet Kayaalp mentioned by James anyway.

Thanks
Yannik