From nobody Sat Sep 26 20:51:01 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1788512147; cv=none; d=zohomail.com; s=zohoarc; b=anBibeOB7paU37D86kpp1cZ+eSQWBDAopGIzPkJRcUe/1ewn1C8sdnrxxegm2RR1Xx4+JRJByC4eBETrgDNJb1c1tTHKR+J084vyP8AUuW/wFeEIeZYH5SaOIObGnKELJpa6k+m2ehHQZd0vB8dhb3eUe4NIWY25uAyFmi+Nveg= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1788512147; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=ndRFpP0p87K/RvBZXrqnssghWsA7AaNs40X5otOIvqw=; b=JVL4PBS2vlQYRNNtJ2jxYgvaXj3Wigu2T0QHsIi82b5NaGfXlnOzPxwXvJj1oIcxQAaOt7XGg86PT/ufvgoZqYjWTLQT497h50y5tUpE6jjS97Su5aJj8f6xwFby/PqlYApmCxbQOUEk6Xa9/Va8uFttbqPtqSYR6bgutxukDXg= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1788512147919378.6661624480033; Fri, 4 Sep 2026 01:55:47 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x2Php-00063t-H0; Fri, 04 Sep 2026 04:55:29 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x2Phj-0005sc-SZ for qemu-devel@nongnu.org; Fri, 04 Sep 2026 04:55:25 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.129.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x2Phi-0007s5-7z for qemu-devel@nongnu.org; Fri, 04 Sep 2026 04:55:23 -0400 Received: from mx-prod-mc-03.mail-002.prod.us-west-2.aws.redhat.com (54.186.198.63 [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-551-cM0UX3JGN8Ok3i2ohWC3hA-1; Fri, 04 Sep 2026 04:55:16 -0400 Received: from mx-prod-int-05.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-05.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.17]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id ED929195399A for ; Fri, 4 Sep 2026 08:55:10 +0000 (UTC) Received: from sirius.home.kraxel.org (unknown [10.44.48.41]) by mx-prod-int-05.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 638D21955F70; Fri, 4 Sep 2026 08:55:10 +0000 (UTC) Received: by sirius.home.kraxel.org (Postfix, from userid 1000) id 20FB61800794; Fri, 04 Sep 2026 10:55:09 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1788512121; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=ndRFpP0p87K/RvBZXrqnssghWsA7AaNs40X5otOIvqw=; b=Rz1QrVvi3990dKMUa24ZTme3M7TPHoyylXtBAWYaxoyf0vyhLHmH4Kx9VQpTY4X68ViQLb meQ4O70coR/oxISbqbN5Rf7XnvoBcLMfQ5MkukoeiUBYodVjQxc30xicoVnzbaL9p+l2fs k58bZ+uw+f9m5C0aJRDKUK3rwPn/mCI= X-MC-Unique: cM0UX3JGN8Ok3i2ohWC3hA-1 X-Mimecast-MFC-AGG-ID: cM0UX3JGN8Ok3i2ohWC3hA_1788512111 From: Gerd Hoffmann To: qemu-devel@nongnu.org Cc: Gerd Hoffmann Subject: [PATCH 1/2] hw/uefi: add require-self-signed-pk config option Date: Fri, 4 Sep 2026 10:55:07 +0200 Message-ID: <20260904085509.2267560-2-kraxel@redhat.com> In-Reply-To: <20260904085509.2267560-1-kraxel@redhat.com> References: <20260904085509.2267560-1-kraxel@redhat.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.0 on 10.30.177.17 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.129.124; envelope-from=kraxel@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: 12 X-Spam_score: 1.2 X-Spam_bar: + X-Spam_report: (1.2 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=0.001, RCVD_IN_SBL_CSS=3.335, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1788512153247154100 Content-Type: text/plain; charset="utf-8" Traditional edk2 behavior is to require a self-signed platform key when enrolling secure boot certificates in setup mode. In 2023 a config option has been added (PcdRequireSelfSignedPk) which allows to relax that requirement, see edk2 commit 566cdfc675fa ("SecurityPkg: limit verification of enrolled PK in setup mode"). This patch adds a similar config option to the qemu uefi variable driver. No functional change, the default value for the new config option maintains existing behavior. Signed-off-by: Gerd Hoffmann --- include/hw/uefi/var-service.h | 1 + hw/uefi/var-service-auth.c | 25 +++++++++++++++---------- hw/uefi/var-service-sysbus.c | 2 ++ 3 files changed, 18 insertions(+), 10 deletions(-) diff --git a/include/hw/uefi/var-service.h b/include/hw/uefi/var-service.h index 7d84025cd58d..7f74b4423381 100644 --- a/include/hw/uefi/var-service.h +++ b/include/hw/uefi/var-service.h @@ -76,6 +76,7 @@ struct uefi_vars_state { int jsonfd; bool force_secure_boot; bool disable_custom_mode; + bool require_self_signed_pk; bool use_pio; =20 /* request + reply capture */ diff --git a/hw/uefi/var-service-auth.c b/hw/uefi/var-service-auth.c index 899444af12df..21fc50f904d5 100644 --- a/hw/uefi/var-service-auth.c +++ b/hw/uefi/var-service-auth.c @@ -201,16 +201,21 @@ static efi_status uefi_vars_check_auth_2_sb(uefi_vars= _state *uv, =20 siglist =3D uefi_vars_find_siglist(uv, var); if (!siglist && setup_mode_is_active(uv) && uefi_vars_is_sb_pk(var)) { - /* check PK is self-signed */ - uefi_variable tmp =3D { - .guid =3D EfiGlobalVariable, - .name =3D (uint16_t *)name_pk, - .name_size =3D sizeof(name_pk), - .attributes =3D sigdb_attrs, - .data =3D data + data_offset, - .data_size =3D va->data_size - data_offset, - }; - return uefi_vars_check_pkcs7_2(&tmp, NULL, NULL, va, data); + /* edk2 config option is PcdRequireSelfSignedPk */ + if (uv->require_self_signed_pk) { + /* check PK is self-signed */ + uefi_variable tmp =3D { + .guid =3D EfiGlobalVariable, + .name =3D (uint16_t *)name_pk, + .name_size =3D sizeof(name_pk), + .attributes =3D sigdb_attrs, + .data =3D data + data_offset, + .data_size =3D va->data_size - data_offset, + }; + return uefi_vars_check_pkcs7_2(&tmp, NULL, NULL, va, data); + } else { + return true; + } } =20 return uefi_vars_check_pkcs7_2(siglist, NULL, NULL, va, data); diff --git a/hw/uefi/var-service-sysbus.c b/hw/uefi/var-service-sysbus.c index 97a96cae6a2b..c4acdea275ad 100644 --- a/hw/uefi/var-service-sysbus.c +++ b/hw/uefi/var-service-sysbus.c @@ -38,6 +38,8 @@ static const Property uefi_vars_sysbus_properties[] =3D { state.force_secure_boot, false), DEFINE_PROP_BOOL("disable-custom-mode", uefi_vars_sysbus_state, state.disable_custom_mode, false), + DEFINE_PROP_BOOL("require-self-signed-pk", uefi_vars_sysbus_state, + state.require_self_signed_pk, true), DEFINE_PROP_BOOL("use-pio", uefi_vars_sysbus_state, state.use_pio, false), }; --=20 2.55.0 From nobody Sat Sep 26 20:51:01 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1788512139; cv=none; d=zohomail.com; s=zohoarc; b=RjZrO6uFZ7VlSdK2fgJxNopIN5IG0VIKl5dImBnQiDrFITNIRJR7ucDZaajjFUpm3d2epWowgOJuMefbqYp8r9hJ6jCDyrv0q/swkd5lHb/Ik6F7DBdW4E0ey5K+v6dDbSUuA5/EC3g1fTsbPh1+CXpGNzYFoypORuE//lirzAM= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1788512139; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=CvKQ0Rf8DcSkT6zU1TL82HUKv7bzlyw1TvOiPJuK8i8=; b=Eb2NJxy8CrCHV13RBrhPcffZKh+BAi6/D9pDUtkIW2K8iINl/OXfHL7Ifuw6Z952EPRtIBj3TmS3kvXdPlAeO+D6Gnp0DJF5S/gns2aod5wdLjoGD0r7lJ3W+N2mDiEJy9JYVNSR4W0kTt9DEpJbiRW0TPJ2h5awzlx00Zk2C2k= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1788512139261780.2021933371592; Fri, 4 Sep 2026 01:55:39 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x2Pho-0005xE-A4; Fri, 04 Sep 2026 04:55:28 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x2Phe-0005oY-NZ for qemu-devel@nongnu.org; Fri, 04 Sep 2026 04:55:20 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.129.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x2Phc-0007rC-Ia for qemu-devel@nongnu.org; Fri, 04 Sep 2026 04:55:17 -0400 Received: from mx-prod-mc-03.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-643-Su-DEaJlNKCJnL-FD-Ezbw-1; Fri, 04 Sep 2026 04:55:13 -0400 Received: from mx-prod-int-06.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-06.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.93]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 502081944D06 for ; Fri, 4 Sep 2026 08:55:12 +0000 (UTC) Received: from sirius.home.kraxel.org (unknown [10.44.48.41]) by mx-prod-int-06.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id E3A17180059E; Fri, 4 Sep 2026 08:55:11 +0000 (UTC) Received: by sirius.home.kraxel.org (Postfix, from userid 1000) id 301D118007B6; Fri, 04 Sep 2026 10:55:09 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1788512114; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=CvKQ0Rf8DcSkT6zU1TL82HUKv7bzlyw1TvOiPJuK8i8=; b=IOxaUdQ1zIQppa8IFUAh+msRXaiD0ecACkxMesB+UE6JiJQCxuq6z3eJGquHdc2eMty1p7 c8r6+DT7LmVHA3TIgzSnFgVskzrsPnAMSiU06I+X187izICVVkAm4quhAoZaQS2ILiSLsU ELLFjToju4O3DaKHAhXQPS/MjgPWABg= X-MC-Unique: Su-DEaJlNKCJnL-FD-Ezbw-1 X-Mimecast-MFC-AGG-ID: Su-DEaJlNKCJnL-FD-Ezbw_1788512112 From: Gerd Hoffmann To: qemu-devel@nongnu.org Cc: Gerd Hoffmann Subject: [PATCH 2/2] hw/uefi: improve default config security Date: Fri, 4 Sep 2026 10:55:08 +0200 Message-ID: <20260904085509.2267560-3-kraxel@redhat.com> In-Reply-To: <20260904085509.2267560-1-kraxel@redhat.com> References: <20260904085509.2267560-1-kraxel@redhat.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.93 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.129.124; envelope-from=kraxel@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: 12 X-Spam_score: 1.2 X-Spam_bar: + X-Spam_report: (1.2 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=0.001, RCVD_IN_SBL_CSS=3.335, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1788512147218158500 Content-Type: text/plain; charset="utf-8" Recent UEFI spec versions do not require a self-signed PK any more. There is no good reason to stick to this requirement, but there is one reason to remove it: It is not needed to enable CustomMode then to enroll secure boot keys which are not self-signed. This commit changes the uefi-vars default configuration to remove the self signed platform key requirement and to disable CustomMode. Little background on CustomMode: This is a special edk2 mode which allows to freely update secure boot variables. This is used by the firmware setup utility to allow the user change the secure boot certificates. The EnrollDefaultKeys.efi utility used to depend on CustomMode too. Typically enabling CustomMode requires the user being physically present. Implementing such a check in a sensible way for a virtual machine is not really possible though. So OVMF doesn't do that and CustomMode can be enabled without that physical presence check. Therefore disabling CustomMode (by the qemu variable service blocking updates of the EFI variable with EFI_WRITE_PROTECTED) is a nice security improvement for secure boot support in virtual machines. User-visible change: Updating secure boot configuration via firmware setup utility does not work by default. Setting the "disable-custom-mode=3Doff" property will re-enable this if needed. Alternatively the variable store can be prepared on the host machine instead of doing it inside the guest. Related edk2 commits: - 3c01a11daae2 ("OvmfPkg: set PcdRequireSelfSignedPk to FALSE"). - 0a7ed7ed3457 ("OvmfPkg/EnrollDefaultKeys: do not require CustomMode") Signed-off-by: Gerd Hoffmann --- hw/uefi/var-service-sysbus.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/hw/uefi/var-service-sysbus.c b/hw/uefi/var-service-sysbus.c index c4acdea275ad..e5e0441e16f7 100644 --- a/hw/uefi/var-service-sysbus.c +++ b/hw/uefi/var-service-sysbus.c @@ -37,9 +37,9 @@ static const Property uefi_vars_sysbus_properties[] =3D { DEFINE_PROP_BOOL("force-secure-boot", uefi_vars_sysbus_state, state.force_secure_boot, false), DEFINE_PROP_BOOL("disable-custom-mode", uefi_vars_sysbus_state, - state.disable_custom_mode, false), + state.disable_custom_mode, true), DEFINE_PROP_BOOL("require-self-signed-pk", uefi_vars_sysbus_state, - state.require_self_signed_pk, true), + state.require_self_signed_pk, false), DEFINE_PROP_BOOL("use-pio", uefi_vars_sysbus_state, state.use_pio, false), }; --=20 2.55.0