bk99.de entertain the web since 1997

UEFI Secure Boot: Why signed firmware could lock out Linux

Summary

Shortly before Windows 8, Matthew Garrett explains the key model of UEFI Secure Boot and warns that computers with only OEM and Microsoft keys will no longer boot a generic Linux. According to Garrett’s analysis, signed Linux versions fail because of GPL bootloaders, self-built kernels and the lack of a central signing authority. The assessment: it is too early to panic, but not too early to be concerned.

Ideas

  • Secure Boot only loads programs and drivers signed with a stored key.
  • An operating system with a matching key exchange key may extend the firmware’s allow and deny lists.
  • Without a central signing authority, the key holder alone decides which software boots.
  • Firmware drivers on expansion cards such as graphics cards also need a matching signature.
  • Microsoft requires Secure Boot to be enabled on Windows 8 logo computers running client Windows.
  • In Garrett’s reading, the GPLv3 of GRUB 2 requires the signing keys to be handed over.
  • If the kernel itself becomes the bootloader, every kernel has to be signed too.
  • Whether Secure Boot can be switched off is up to each hardware manufacturer.

Insights

  • Whoever manages the root of trust effectively controls access to the hardware.
  • A security feature can restrict competition without that being its stated purpose.
  • Firmware vendors often deliver only the features their main market demands.

Quotes

  • It's probably not worth panicking yet. But it is worth being concerned. – Matthew Garrett

Facts

  • The firmware keeps an allow list (db) and a deny list (dbx) for signatures and hashes.
  • Windows 8 was released in October 2012 and made Secure Boot the norm on new PCs.
  • Linux distributions today boot via the Microsoft-signed bootloader shim.
  • Machine Owner Keys (MOK) allow owners to enrol their own keys for kernels and modules.

References

Critique

  • Garrett writes as a Linux developer from the distributions’ point of view; the security gain against bootkits is only mentioned in passing.
  • The GPL assessment is one developer’s interpretation and not a legal review.

Remarks

  • After the debate, Microsoft required that Secure Boot can be switched off on x86 logo computers; the opposite applied to ARM devices with Windows RT.
  • The later attacks on faulty implementations are described in Secure Boot in practice.

Recommendations

  • Check with mokutil --sb-state whether Secure Boot is active on a Linux system.
  • Sign self-built kernels and DKMS modules with your own key enrolled via MOK.
  • Before buying hardware, find out whether Secure Boot can be switched off and your own keys can be enrolled.

Read the original article on mjg59

Search the Web Archive