Generate UKI file for DTS and iPXE #233
Draft
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
@macpijan What do you think about this PR?
We could use it as a first step to creating SB capable image (built from
kas.yml
not separate one).To enable SB when booting via USB we would need couple more changes (add at least shim)
From my testing
grub.cfg
file is used only on EFI platform. When booting on legacy BIOS, old config is used.This PR creates 2 files:
/boot/EFI/DTS/dts.efi
and booted via chainloader commandIt can be signed and deployed to
boot.dasharo.com
via our CI. It would allow booting DTS via iPXE with secure boot enabled (after couple changes indts.ipxe
script).