]> git.proxmox.com Git - efi-boot-shim.git/commit - SBAT.md
Add Secure Boot Advanced Targeting (SBAT) specification document
authorJan Setje-Eilers <jan.setjeeilers@oracle.com>
Fri, 12 Feb 2021 23:46:36 +0000 (00:46 +0100)
committerPeter Jones <pjones@redhat.com>
Sat, 13 Feb 2021 16:29:18 +0000 (11:29 -0500)
commit4eef10a6b345fad26578c985b8b6ab38ca2025e7
treee91383a6b06e4427f8797a088e51280ea580f2fe
parent6b8ef61a1aa9c69aecb6a22cf79ddece727273e2
Add Secure Boot Advanced Targeting (SBAT) specification document

SBAT is a new Generation Number Based Revocation meant to replace the DBX
Revocation List Files mechanism. It is more flexible and allow to revoke
sets of binaries, instead of having to list all of them as with the DBX.

Metadata that includes the vendor, product family, product, component,
version and generation are added to artifacts in a .sbat section. This
is protected by the digital signature and so it cannot be tampered.

Signed-off-by: Jan Setje-Eilers <jan.setjeeilers@oracle.com>
Signed-off-by: Peter Jones <pjones@redhat.com>
Signed-off-by: Gary Lin <glin@suse.com>
SBAT.md [new file with mode: 0644]