]>
Commit | Line | Data |
---|---|---|
b1163623 | 1 | /** @file\r |
3defea06 | 2 | Enroll default PK, KEK, db, dbx.\r |
b1163623 | 3 | \r |
3defea06 | 4 | Copyright (C) 2014-2019, Red Hat, Inc.\r |
b1163623 | 5 | \r |
3defea06 | 6 | SPDX-License-Identifier: BSD-2-Clause-Patent\r |
b1163623 LE |
7 | **/\r |
8 | #include <Guid/AuthenticatedVariableFormat.h> // gEfiCustomModeEnableGuid\r | |
9 | #include <Guid/GlobalVariable.h> // EFI_SETUP_MODE_NAME\r | |
10 | #include <Guid/ImageAuthentication.h> // EFI_IMAGE_SECURITY_DATABASE\r | |
11 | #include <Library/BaseMemoryLib.h> // CopyGuid()\r | |
12 | #include <Library/DebugLib.h> // ASSERT()\r | |
13 | #include <Library/MemoryAllocationLib.h> // FreePool()\r | |
14 | #include <Library/ShellCEntryLib.h> // ShellAppMain()\r | |
15 | #include <Library/UefiLib.h> // AsciiPrint()\r | |
16 | #include <Library/UefiRuntimeServicesTableLib.h> // gRT\r | |
17 | \r | |
18 | //\r | |
19 | // We'll use the certificate below as both Platform Key and as first Key\r | |
20 | // Exchange Key.\r | |
21 | //\r | |
22 | // "Red Hat Secure Boot (PK/KEK key 1)/emailAddress=secalert@redhat.com"\r | |
23 | // SHA1: fd:fc:7f:3c:7e:f3:e0:57:76:ad:d7:98:78:21:6c:9b:e0:e1:95:97\r | |
24 | //\r | |
32d1440a | 25 | STATIC CONST UINT8 mRedHatPkKek1[] = {\r |
b1163623 LE |
26 | 0x30, 0x82, 0x03, 0xa0, 0x30, 0x82, 0x02, 0x88, 0xa0, 0x03, 0x02, 0x01, 0x02,\r |
27 | 0x02, 0x09, 0x00, 0xfe, 0xf5, 0x88, 0xe8, 0xf3, 0x96, 0xc0, 0xf1, 0x30, 0x0d,\r | |
28 | 0x06, 0x09, 0x2a, 0x86, 0x48, 0x86, 0xf7, 0x0d, 0x01, 0x01, 0x0b, 0x05, 0x00,\r | |
29 | 0x30, 0x51, 0x31, 0x2b, 0x30, 0x29, 0x06, 0x03, 0x55, 0x04, 0x03, 0x13, 0x22,\r | |
30 | 0x52, 0x65, 0x64, 0x20, 0x48, 0x61, 0x74, 0x20, 0x53, 0x65, 0x63, 0x75, 0x72,\r | |
31 | 0x65, 0x20, 0x42, 0x6f, 0x6f, 0x74, 0x20, 0x28, 0x50, 0x4b, 0x2f, 0x4b, 0x45,\r | |
32 | 0x4b, 0x20, 0x6b, 0x65, 0x79, 0x20, 0x31, 0x29, 0x31, 0x22, 0x30, 0x20, 0x06,\r | |
33 | 0x09, 0x2a, 0x86, 0x48, 0x86, 0xf7, 0x0d, 0x01, 0x09, 0x01, 0x16, 0x13, 0x73,\r | |
34 | 0x65, 0x63, 0x61, 0x6c, 0x65, 0x72, 0x74, 0x40, 0x72, 0x65, 0x64, 0x68, 0x61,\r | |
35 | 0x74, 0x2e, 0x63, 0x6f, 0x6d, 0x30, 0x1e, 0x17, 0x0d, 0x31, 0x34, 0x31, 0x30,\r | |
36 | 0x33, 0x31, 0x31, 0x31, 0x31, 0x35, 0x33, 0x37, 0x5a, 0x17, 0x0d, 0x33, 0x37,\r | |
37 | 0x31, 0x30, 0x32, 0x35, 0x31, 0x31, 0x31, 0x35, 0x33, 0x37, 0x5a, 0x30, 0x51,\r | |
38 | 0x31, 0x2b, 0x30, 0x29, 0x06, 0x03, 0x55, 0x04, 0x03, 0x13, 0x22, 0x52, 0x65,\r | |
39 | 0x64, 0x20, 0x48, 0x61, 0x74, 0x20, 0x53, 0x65, 0x63, 0x75, 0x72, 0x65, 0x20,\r | |
40 | 0x42, 0x6f, 0x6f, 0x74, 0x20, 0x28, 0x50, 0x4b, 0x2f, 0x4b, 0x45, 0x4b, 0x20,\r | |
41 | 0x6b, 0x65, 0x79, 0x20, 0x31, 0x29, 0x31, 0x22, 0x30, 0x20, 0x06, 0x09, 0x2a,\r | |
42 | 0x86, 0x48, 0x86, 0xf7, 0x0d, 0x01, 0x09, 0x01, 0x16, 0x13, 0x73, 0x65, 0x63,\r | |
43 | 0x61, 0x6c, 0x65, 0x72, 0x74, 0x40, 0x72, 0x65, 0x64, 0x68, 0x61, 0x74, 0x2e,\r | |
44 | 0x63, 0x6f, 0x6d, 0x30, 0x82, 0x01, 0x22, 0x30, 0x0d, 0x06, 0x09, 0x2a, 0x86,\r | |
45 | 0x48, 0x86, 0xf7, 0x0d, 0x01, 0x01, 0x01, 0x05, 0x00, 0x03, 0x82, 0x01, 0x0f,\r | |
46 | 0x00, 0x30, 0x82, 0x01, 0x0a, 0x02, 0x82, 0x01, 0x01, 0x00, 0x90, 0x1f, 0x84,\r | |
47 | 0x7b, 0x8d, 0xbc, 0xeb, 0x97, 0x26, 0x82, 0x6d, 0x88, 0xab, 0x8a, 0xc9, 0x8c,\r | |
48 | 0x68, 0x70, 0xf9, 0xdf, 0x4b, 0x07, 0xb2, 0x37, 0x83, 0x0b, 0x02, 0xc8, 0x67,\r | |
49 | 0x68, 0x30, 0x9e, 0xe3, 0xf0, 0xf0, 0x99, 0x4a, 0xb8, 0x59, 0x57, 0xc6, 0x41,\r | |
50 | 0xf6, 0x38, 0x8b, 0xfe, 0x66, 0x4c, 0x49, 0xe9, 0x37, 0x37, 0x92, 0x2e, 0x98,\r | |
51 | 0x01, 0x1e, 0x5b, 0x14, 0x50, 0xe6, 0xa8, 0x8d, 0x25, 0x0d, 0xf5, 0x86, 0xe6,\r | |
52 | 0xab, 0x30, 0xcb, 0x40, 0x16, 0xea, 0x8d, 0x8b, 0x16, 0x86, 0x70, 0x43, 0x37,\r | |
53 | 0xf2, 0xce, 0xc0, 0x91, 0xdf, 0x71, 0x14, 0x8e, 0x99, 0x0e, 0x89, 0xb6, 0x4c,\r | |
54 | 0x6d, 0x24, 0x1e, 0x8c, 0xe4, 0x2f, 0x4f, 0x25, 0xd0, 0xba, 0x06, 0xf8, 0xc6,\r | |
55 | 0xe8, 0x19, 0x18, 0x76, 0x73, 0x1d, 0x81, 0x6d, 0xa8, 0xd8, 0x05, 0xcf, 0x3a,\r | |
56 | 0xc8, 0x7b, 0x28, 0xc8, 0x36, 0xa3, 0x16, 0x0d, 0x29, 0x8c, 0x99, 0x9a, 0x68,\r | |
57 | 0xdc, 0xab, 0xc0, 0x4d, 0x8d, 0xbf, 0x5a, 0xbb, 0x2b, 0xa9, 0x39, 0x4b, 0x04,\r | |
58 | 0x97, 0x1c, 0xf9, 0x36, 0xbb, 0xc5, 0x3a, 0x86, 0x04, 0xae, 0xaf, 0xd4, 0x82,\r | |
59 | 0x7b, 0xe0, 0xab, 0xde, 0x49, 0x05, 0x68, 0xfc, 0xf6, 0xae, 0x68, 0x1a, 0x6c,\r | |
60 | 0x90, 0x4d, 0x57, 0x19, 0x3c, 0x64, 0x66, 0x03, 0xf6, 0xc7, 0x52, 0x9b, 0xf7,\r | |
61 | 0x94, 0xcf, 0x93, 0x6a, 0xa1, 0x68, 0xc9, 0xaa, 0xcf, 0x99, 0x6b, 0xbc, 0xaa,\r | |
62 | 0x5e, 0x08, 0xe7, 0x39, 0x1c, 0xf7, 0xf8, 0x0f, 0xba, 0x06, 0x7e, 0xf1, 0xcb,\r | |
63 | 0xe8, 0x76, 0xdd, 0xfe, 0x22, 0xda, 0xad, 0x3a, 0x5e, 0x5b, 0x34, 0xea, 0xb3,\r | |
64 | 0xc9, 0xe0, 0x4d, 0x04, 0x29, 0x7e, 0xb8, 0x60, 0xb9, 0x05, 0xef, 0xb5, 0xd9,\r | |
65 | 0x17, 0x58, 0x56, 0x16, 0x60, 0xb9, 0x30, 0x32, 0xf0, 0x36, 0x4a, 0xc3, 0xf2,\r | |
66 | 0x79, 0x8d, 0x12, 0x40, 0x70, 0xf3, 0x02, 0x03, 0x01, 0x00, 0x01, 0xa3, 0x7b,\r | |
67 | 0x30, 0x79, 0x30, 0x09, 0x06, 0x03, 0x55, 0x1d, 0x13, 0x04, 0x02, 0x30, 0x00,\r | |
68 | 0x30, 0x2c, 0x06, 0x09, 0x60, 0x86, 0x48, 0x01, 0x86, 0xf8, 0x42, 0x01, 0x0d,\r | |
69 | 0x04, 0x1f, 0x16, 0x1d, 0x4f, 0x70, 0x65, 0x6e, 0x53, 0x53, 0x4c, 0x20, 0x47,\r | |
70 | 0x65, 0x6e, 0x65, 0x72, 0x61, 0x74, 0x65, 0x64, 0x20, 0x43, 0x65, 0x72, 0x74,\r | |
71 | 0x69, 0x66, 0x69, 0x63, 0x61, 0x74, 0x65, 0x30, 0x1d, 0x06, 0x03, 0x55, 0x1d,\r | |
72 | 0x0e, 0x04, 0x16, 0x04, 0x14, 0x3c, 0xe9, 0x60, 0xe3, 0xff, 0x19, 0xa1, 0x0a,\r | |
73 | 0x7b, 0xa3, 0x42, 0xf4, 0x8d, 0x42, 0x2e, 0xb4, 0xd5, 0x9c, 0x72, 0xec, 0x30,\r | |
74 | 0x1f, 0x06, 0x03, 0x55, 0x1d, 0x23, 0x04, 0x18, 0x30, 0x16, 0x80, 0x14, 0x3c,\r | |
75 | 0xe9, 0x60, 0xe3, 0xff, 0x19, 0xa1, 0x0a, 0x7b, 0xa3, 0x42, 0xf4, 0x8d, 0x42,\r | |
76 | 0x2e, 0xb4, 0xd5, 0x9c, 0x72, 0xec, 0x30, 0x0d, 0x06, 0x09, 0x2a, 0x86, 0x48,\r | |
77 | 0x86, 0xf7, 0x0d, 0x01, 0x01, 0x0b, 0x05, 0x00, 0x03, 0x82, 0x01, 0x01, 0x00,\r | |
78 | 0x5c, 0x4d, 0x92, 0x88, 0xb4, 0x82, 0x5f, 0x1d, 0xad, 0x8b, 0x11, 0xec, 0xdf,\r | |
79 | 0x06, 0xa6, 0x7a, 0xa5, 0x2b, 0x9f, 0x37, 0x55, 0x0c, 0x8d, 0x6e, 0x05, 0x00,\r | |
80 | 0xad, 0xb7, 0x0c, 0x41, 0x89, 0x69, 0xcf, 0xd6, 0x65, 0x06, 0x9b, 0x51, 0x78,\r | |
81 | 0xd2, 0xad, 0xc7, 0xbf, 0x9c, 0xdc, 0x05, 0x73, 0x7f, 0xe7, 0x1e, 0x39, 0x13,\r | |
82 | 0xb4, 0xea, 0xb6, 0x30, 0x7d, 0x40, 0x75, 0xab, 0x9c, 0x43, 0x0b, 0xdf, 0xb0,\r | |
83 | 0xc2, 0x1b, 0xbf, 0x30, 0xe0, 0xf4, 0xfe, 0xc0, 0xdb, 0x62, 0x21, 0x98, 0xf6,\r | |
84 | 0xc5, 0xaf, 0xde, 0x3b, 0x4f, 0x49, 0x0a, 0xe6, 0x1e, 0xf9, 0x86, 0xb0, 0x3f,\r | |
85 | 0x0d, 0xd6, 0xd4, 0x46, 0x37, 0xdb, 0x54, 0x74, 0x5e, 0xff, 0x11, 0xc2, 0x60,\r | |
86 | 0xc6, 0x70, 0x58, 0xc5, 0x1c, 0x6f, 0xec, 0xb2, 0xd8, 0x6e, 0x6f, 0xc3, 0xbc,\r | |
87 | 0x33, 0x87, 0x38, 0xa4, 0xf3, 0x44, 0x64, 0x9c, 0x34, 0x3b, 0x28, 0x94, 0x26,\r | |
88 | 0x78, 0x27, 0x9f, 0x16, 0x17, 0xe8, 0x3b, 0x69, 0x0a, 0x25, 0xa9, 0x73, 0x36,\r | |
89 | 0x7e, 0x9e, 0x37, 0x5c, 0xec, 0xe8, 0x3f, 0xdb, 0x91, 0xf9, 0x12, 0xb3, 0x3d,\r | |
90 | 0xce, 0xe7, 0xdd, 0x15, 0xc3, 0xae, 0x8c, 0x05, 0x20, 0x61, 0x9b, 0x95, 0xde,\r | |
91 | 0x9b, 0xaf, 0xfa, 0xb1, 0x5c, 0x1c, 0xe5, 0x97, 0xe7, 0xc3, 0x34, 0x11, 0x85,\r | |
92 | 0xf5, 0x8a, 0x27, 0x26, 0xa4, 0x70, 0x36, 0xec, 0x0c, 0xf6, 0x83, 0x3d, 0x90,\r | |
93 | 0xf7, 0x36, 0xf3, 0xf9, 0xf3, 0x15, 0xd4, 0x90, 0x62, 0xbe, 0x53, 0xb4, 0xaf,\r | |
94 | 0xd3, 0x49, 0xaf, 0xef, 0xf4, 0x73, 0xe8, 0x7b, 0x76, 0xe4, 0x44, 0x2a, 0x37,\r | |
95 | 0xba, 0x81, 0xa4, 0x99, 0x0c, 0x3a, 0x31, 0x24, 0x71, 0xa0, 0xe4, 0xe4, 0xb7,\r | |
96 | 0x1a, 0xcb, 0x47, 0xe4, 0xaa, 0x22, 0xcf, 0xef, 0x75, 0x61, 0x80, 0xe3, 0x43,\r | |
97 | 0xb7, 0x48, 0x57, 0x73, 0x11, 0x3d, 0x78, 0x9b, 0x69\r | |
98 | };\r | |
99 | \r | |
100 | //\r | |
101 | // Second KEK: "Microsoft Corporation KEK CA 2011".\r | |
102 | // SHA1: 31:59:0b:fd:89:c9:d7:4e:d0:87:df:ac:66:33:4b:39:31:25:4b:30\r | |
103 | //\r | |
104 | // "dbx" updates in "dbxtool" are signed with a key derived from this KEK.\r | |
105 | //\r | |
32d1440a | 106 | STATIC CONST UINT8 mMicrosoftKEK[] = {\r |
b1163623 LE |
107 | 0x30, 0x82, 0x05, 0xe8, 0x30, 0x82, 0x03, 0xd0, 0xa0, 0x03, 0x02, 0x01, 0x02,\r |
108 | 0x02, 0x0a, 0x61, 0x0a, 0xd1, 0x88, 0x00, 0x00, 0x00, 0x00, 0x00, 0x03, 0x30,\r | |
109 | 0x0d, 0x06, 0x09, 0x2a, 0x86, 0x48, 0x86, 0xf7, 0x0d, 0x01, 0x01, 0x0b, 0x05,\r | |
110 | 0x00, 0x30, 0x81, 0x91, 0x31, 0x0b, 0x30, 0x09, 0x06, 0x03, 0x55, 0x04, 0x06,\r | |
111 | 0x13, 0x02, 0x55, 0x53, 0x31, 0x13, 0x30, 0x11, 0x06, 0x03, 0x55, 0x04, 0x08,\r | |
112 | 0x13, 0x0a, 0x57, 0x61, 0x73, 0x68, 0x69, 0x6e, 0x67, 0x74, 0x6f, 0x6e, 0x31,\r | |
113 | 0x10, 0x30, 0x0e, 0x06, 0x03, 0x55, 0x04, 0x07, 0x13, 0x07, 0x52, 0x65, 0x64,\r | |
114 | 0x6d, 0x6f, 0x6e, 0x64, 0x31, 0x1e, 0x30, 0x1c, 0x06, 0x03, 0x55, 0x04, 0x0a,\r | |
115 | 0x13, 0x15, 0x4d, 0x69, 0x63, 0x72, 0x6f, 0x73, 0x6f, 0x66, 0x74, 0x20, 0x43,\r | |
116 | 0x6f, 0x72, 0x70, 0x6f, 0x72, 0x61, 0x74, 0x69, 0x6f, 0x6e, 0x31, 0x3b, 0x30,\r | |
117 | 0x39, 0x06, 0x03, 0x55, 0x04, 0x03, 0x13, 0x32, 0x4d, 0x69, 0x63, 0x72, 0x6f,\r | |
118 | 0x73, 0x6f, 0x66, 0x74, 0x20, 0x43, 0x6f, 0x72, 0x70, 0x6f, 0x72, 0x61, 0x74,\r | |
119 | 0x69, 0x6f, 0x6e, 0x20, 0x54, 0x68, 0x69, 0x72, 0x64, 0x20, 0x50, 0x61, 0x72,\r | |
120 | 0x74, 0x79, 0x20, 0x4d, 0x61, 0x72, 0x6b, 0x65, 0x74, 0x70, 0x6c, 0x61, 0x63,\r | |
121 | 0x65, 0x20, 0x52, 0x6f, 0x6f, 0x74, 0x30, 0x1e, 0x17, 0x0d, 0x31, 0x31, 0x30,\r | |
122 | 0x36, 0x32, 0x34, 0x32, 0x30, 0x34, 0x31, 0x32, 0x39, 0x5a, 0x17, 0x0d, 0x32,\r | |
123 | 0x36, 0x30, 0x36, 0x32, 0x34, 0x32, 0x30, 0x35, 0x31, 0x32, 0x39, 0x5a, 0x30,\r | |
124 | 0x81, 0x80, 0x31, 0x0b, 0x30, 0x09, 0x06, 0x03, 0x55, 0x04, 0x06, 0x13, 0x02,\r | |
125 | 0x55, 0x53, 0x31, 0x13, 0x30, 0x11, 0x06, 0x03, 0x55, 0x04, 0x08, 0x13, 0x0a,\r | |
126 | 0x57, 0x61, 0x73, 0x68, 0x69, 0x6e, 0x67, 0x74, 0x6f, 0x6e, 0x31, 0x10, 0x30,\r | |
127 | 0x0e, 0x06, 0x03, 0x55, 0x04, 0x07, 0x13, 0x07, 0x52, 0x65, 0x64, 0x6d, 0x6f,\r | |
128 | 0x6e, 0x64, 0x31, 0x1e, 0x30, 0x1c, 0x06, 0x03, 0x55, 0x04, 0x0a, 0x13, 0x15,\r | |
129 | 0x4d, 0x69, 0x63, 0x72, 0x6f, 0x73, 0x6f, 0x66, 0x74, 0x20, 0x43, 0x6f, 0x72,\r | |
130 | 0x70, 0x6f, 0x72, 0x61, 0x74, 0x69, 0x6f, 0x6e, 0x31, 0x2a, 0x30, 0x28, 0x06,\r | |
131 | 0x03, 0x55, 0x04, 0x03, 0x13, 0x21, 0x4d, 0x69, 0x63, 0x72, 0x6f, 0x73, 0x6f,\r | |
132 | 0x66, 0x74, 0x20, 0x43, 0x6f, 0x72, 0x70, 0x6f, 0x72, 0x61, 0x74, 0x69, 0x6f,\r | |
133 | 0x6e, 0x20, 0x4b, 0x45, 0x4b, 0x20, 0x43, 0x41, 0x20, 0x32, 0x30, 0x31, 0x31,\r | |
134 | 0x30, 0x82, 0x01, 0x22, 0x30, 0x0d, 0x06, 0x09, 0x2a, 0x86, 0x48, 0x86, 0xf7,\r | |
135 | 0x0d, 0x01, 0x01, 0x01, 0x05, 0x00, 0x03, 0x82, 0x01, 0x0f, 0x00, 0x30, 0x82,\r | |
136 | 0x01, 0x0a, 0x02, 0x82, 0x01, 0x01, 0x00, 0xc4, 0xe8, 0xb5, 0x8a, 0xbf, 0xad,\r | |
137 | 0x57, 0x26, 0xb0, 0x26, 0xc3, 0xea, 0xe7, 0xfb, 0x57, 0x7a, 0x44, 0x02, 0x5d,\r | |
138 | 0x07, 0x0d, 0xda, 0x4a, 0xe5, 0x74, 0x2a, 0xe6, 0xb0, 0x0f, 0xec, 0x6d, 0xeb,\r | |
139 | 0xec, 0x7f, 0xb9, 0xe3, 0x5a, 0x63, 0x32, 0x7c, 0x11, 0x17, 0x4f, 0x0e, 0xe3,\r | |
140 | 0x0b, 0xa7, 0x38, 0x15, 0x93, 0x8e, 0xc6, 0xf5, 0xe0, 0x84, 0xb1, 0x9a, 0x9b,\r | |
141 | 0x2c, 0xe7, 0xf5, 0xb7, 0x91, 0xd6, 0x09, 0xe1, 0xe2, 0xc0, 0x04, 0xa8, 0xac,\r | |
142 | 0x30, 0x1c, 0xdf, 0x48, 0xf3, 0x06, 0x50, 0x9a, 0x64, 0xa7, 0x51, 0x7f, 0xc8,\r | |
143 | 0x85, 0x4f, 0x8f, 0x20, 0x86, 0xce, 0xfe, 0x2f, 0xe1, 0x9f, 0xff, 0x82, 0xc0,\r | |
144 | 0xed, 0xe9, 0xcd, 0xce, 0xf4, 0x53, 0x6a, 0x62, 0x3a, 0x0b, 0x43, 0xb9, 0xe2,\r | |
145 | 0x25, 0xfd, 0xfe, 0x05, 0xf9, 0xd4, 0xc4, 0x14, 0xab, 0x11, 0xe2, 0x23, 0x89,\r | |
146 | 0x8d, 0x70, 0xb7, 0xa4, 0x1d, 0x4d, 0xec, 0xae, 0xe5, 0x9c, 0xfa, 0x16, 0xc2,\r | |
147 | 0xd7, 0xc1, 0xcb, 0xd4, 0xe8, 0xc4, 0x2f, 0xe5, 0x99, 0xee, 0x24, 0x8b, 0x03,\r | |
148 | 0xec, 0x8d, 0xf2, 0x8b, 0xea, 0xc3, 0x4a, 0xfb, 0x43, 0x11, 0x12, 0x0b, 0x7e,\r | |
149 | 0xb5, 0x47, 0x92, 0x6c, 0xdc, 0xe6, 0x04, 0x89, 0xeb, 0xf5, 0x33, 0x04, 0xeb,\r | |
150 | 0x10, 0x01, 0x2a, 0x71, 0xe5, 0xf9, 0x83, 0x13, 0x3c, 0xff, 0x25, 0x09, 0x2f,\r | |
151 | 0x68, 0x76, 0x46, 0xff, 0xba, 0x4f, 0xbe, 0xdc, 0xad, 0x71, 0x2a, 0x58, 0xaa,\r | |
152 | 0xfb, 0x0e, 0xd2, 0x79, 0x3d, 0xe4, 0x9b, 0x65, 0x3b, 0xcc, 0x29, 0x2a, 0x9f,\r | |
153 | 0xfc, 0x72, 0x59, 0xa2, 0xeb, 0xae, 0x92, 0xef, 0xf6, 0x35, 0x13, 0x80, 0xc6,\r | |
154 | 0x02, 0xec, 0xe4, 0x5f, 0xcc, 0x9d, 0x76, 0xcd, 0xef, 0x63, 0x92, 0xc1, 0xaf,\r | |
155 | 0x79, 0x40, 0x84, 0x79, 0x87, 0x7f, 0xe3, 0x52, 0xa8, 0xe8, 0x9d, 0x7b, 0x07,\r | |
156 | 0x69, 0x8f, 0x15, 0x02, 0x03, 0x01, 0x00, 0x01, 0xa3, 0x82, 0x01, 0x4f, 0x30,\r | |
157 | 0x82, 0x01, 0x4b, 0x30, 0x10, 0x06, 0x09, 0x2b, 0x06, 0x01, 0x04, 0x01, 0x82,\r | |
158 | 0x37, 0x15, 0x01, 0x04, 0x03, 0x02, 0x01, 0x00, 0x30, 0x1d, 0x06, 0x03, 0x55,\r | |
159 | 0x1d, 0x0e, 0x04, 0x16, 0x04, 0x14, 0x62, 0xfc, 0x43, 0xcd, 0xa0, 0x3e, 0xa4,\r | |
160 | 0xcb, 0x67, 0x12, 0xd2, 0x5b, 0xd9, 0x55, 0xac, 0x7b, 0xcc, 0xb6, 0x8a, 0x5f,\r | |
161 | 0x30, 0x19, 0x06, 0x09, 0x2b, 0x06, 0x01, 0x04, 0x01, 0x82, 0x37, 0x14, 0x02,\r | |
162 | 0x04, 0x0c, 0x1e, 0x0a, 0x00, 0x53, 0x00, 0x75, 0x00, 0x62, 0x00, 0x43, 0x00,\r | |
163 | 0x41, 0x30, 0x0b, 0x06, 0x03, 0x55, 0x1d, 0x0f, 0x04, 0x04, 0x03, 0x02, 0x01,\r | |
164 | 0x86, 0x30, 0x0f, 0x06, 0x03, 0x55, 0x1d, 0x13, 0x01, 0x01, 0xff, 0x04, 0x05,\r | |
165 | 0x30, 0x03, 0x01, 0x01, 0xff, 0x30, 0x1f, 0x06, 0x03, 0x55, 0x1d, 0x23, 0x04,\r | |
166 | 0x18, 0x30, 0x16, 0x80, 0x14, 0x45, 0x66, 0x52, 0x43, 0xe1, 0x7e, 0x58, 0x11,\r | |
167 | 0xbf, 0xd6, 0x4e, 0x9e, 0x23, 0x55, 0x08, 0x3b, 0x3a, 0x22, 0x6a, 0xa8, 0x30,\r | |
168 | 0x5c, 0x06, 0x03, 0x55, 0x1d, 0x1f, 0x04, 0x55, 0x30, 0x53, 0x30, 0x51, 0xa0,\r | |
169 | 0x4f, 0xa0, 0x4d, 0x86, 0x4b, 0x68, 0x74, 0x74, 0x70, 0x3a, 0x2f, 0x2f, 0x63,\r | |
170 | 0x72, 0x6c, 0x2e, 0x6d, 0x69, 0x63, 0x72, 0x6f, 0x73, 0x6f, 0x66, 0x74, 0x2e,\r | |
171 | 0x63, 0x6f, 0x6d, 0x2f, 0x70, 0x6b, 0x69, 0x2f, 0x63, 0x72, 0x6c, 0x2f, 0x70,\r | |
172 | 0x72, 0x6f, 0x64, 0x75, 0x63, 0x74, 0x73, 0x2f, 0x4d, 0x69, 0x63, 0x43, 0x6f,\r | |
173 | 0x72, 0x54, 0x68, 0x69, 0x50, 0x61, 0x72, 0x4d, 0x61, 0x72, 0x52, 0x6f, 0x6f,\r | |
174 | 0x5f, 0x32, 0x30, 0x31, 0x30, 0x2d, 0x31, 0x30, 0x2d, 0x30, 0x35, 0x2e, 0x63,\r | |
175 | 0x72, 0x6c, 0x30, 0x60, 0x06, 0x08, 0x2b, 0x06, 0x01, 0x05, 0x05, 0x07, 0x01,\r | |
176 | 0x01, 0x04, 0x54, 0x30, 0x52, 0x30, 0x50, 0x06, 0x08, 0x2b, 0x06, 0x01, 0x05,\r | |
177 | 0x05, 0x07, 0x30, 0x02, 0x86, 0x44, 0x68, 0x74, 0x74, 0x70, 0x3a, 0x2f, 0x2f,\r | |
178 | 0x77, 0x77, 0x77, 0x2e, 0x6d, 0x69, 0x63, 0x72, 0x6f, 0x73, 0x6f, 0x66, 0x74,\r | |
179 | 0x2e, 0x63, 0x6f, 0x6d, 0x2f, 0x70, 0x6b, 0x69, 0x2f, 0x63, 0x65, 0x72, 0x74,\r | |
180 | 0x73, 0x2f, 0x4d, 0x69, 0x63, 0x43, 0x6f, 0x72, 0x54, 0x68, 0x69, 0x50, 0x61,\r | |
181 | 0x72, 0x4d, 0x61, 0x72, 0x52, 0x6f, 0x6f, 0x5f, 0x32, 0x30, 0x31, 0x30, 0x2d,\r | |
182 | 0x31, 0x30, 0x2d, 0x30, 0x35, 0x2e, 0x63, 0x72, 0x74, 0x30, 0x0d, 0x06, 0x09,\r | |
183 | 0x2a, 0x86, 0x48, 0x86, 0xf7, 0x0d, 0x01, 0x01, 0x0b, 0x05, 0x00, 0x03, 0x82,\r | |
184 | 0x02, 0x01, 0x00, 0xd4, 0x84, 0x88, 0xf5, 0x14, 0x94, 0x18, 0x02, 0xca, 0x2a,\r | |
185 | 0x3c, 0xfb, 0x2a, 0x92, 0x1c, 0x0c, 0xd7, 0xa0, 0xd1, 0xf1, 0xe8, 0x52, 0x66,\r | |
186 | 0xa8, 0xee, 0xa2, 0xb5, 0x75, 0x7a, 0x90, 0x00, 0xaa, 0x2d, 0xa4, 0x76, 0x5a,\r | |
187 | 0xea, 0x79, 0xb7, 0xb9, 0x37, 0x6a, 0x51, 0x7b, 0x10, 0x64, 0xf6, 0xe1, 0x64,\r | |
188 | 0xf2, 0x02, 0x67, 0xbe, 0xf7, 0xa8, 0x1b, 0x78, 0xbd, 0xba, 0xce, 0x88, 0x58,\r | |
189 | 0x64, 0x0c, 0xd6, 0x57, 0xc8, 0x19, 0xa3, 0x5f, 0x05, 0xd6, 0xdb, 0xc6, 0xd0,\r | |
190 | 0x69, 0xce, 0x48, 0x4b, 0x32, 0xb7, 0xeb, 0x5d, 0xd2, 0x30, 0xf5, 0xc0, 0xf5,\r | |
191 | 0xb8, 0xba, 0x78, 0x07, 0xa3, 0x2b, 0xfe, 0x9b, 0xdb, 0x34, 0x56, 0x84, 0xec,\r | |
192 | 0x82, 0xca, 0xae, 0x41, 0x25, 0x70, 0x9c, 0x6b, 0xe9, 0xfe, 0x90, 0x0f, 0xd7,\r | |
193 | 0x96, 0x1f, 0xe5, 0xe7, 0x94, 0x1f, 0xb2, 0x2a, 0x0c, 0x8d, 0x4b, 0xff, 0x28,\r | |
194 | 0x29, 0x10, 0x7b, 0xf7, 0xd7, 0x7c, 0xa5, 0xd1, 0x76, 0xb9, 0x05, 0xc8, 0x79,\r | |
195 | 0xed, 0x0f, 0x90, 0x92, 0x9c, 0xc2, 0xfe, 0xdf, 0x6f, 0x7e, 0x6c, 0x0f, 0x7b,\r | |
196 | 0xd4, 0xc1, 0x45, 0xdd, 0x34, 0x51, 0x96, 0x39, 0x0f, 0xe5, 0x5e, 0x56, 0xd8,\r | |
197 | 0x18, 0x05, 0x96, 0xf4, 0x07, 0xa6, 0x42, 0xb3, 0xa0, 0x77, 0xfd, 0x08, 0x19,\r | |
198 | 0xf2, 0x71, 0x56, 0xcc, 0x9f, 0x86, 0x23, 0xa4, 0x87, 0xcb, 0xa6, 0xfd, 0x58,\r | |
199 | 0x7e, 0xd4, 0x69, 0x67, 0x15, 0x91, 0x7e, 0x81, 0xf2, 0x7f, 0x13, 0xe5, 0x0d,\r | |
200 | 0x8b, 0x8a, 0x3c, 0x87, 0x84, 0xeb, 0xe3, 0xce, 0xbd, 0x43, 0xe5, 0xad, 0x2d,\r | |
201 | 0x84, 0x93, 0x8e, 0x6a, 0x2b, 0x5a, 0x7c, 0x44, 0xfa, 0x52, 0xaa, 0x81, 0xc8,\r | |
202 | 0x2d, 0x1c, 0xbb, 0xe0, 0x52, 0xdf, 0x00, 0x11, 0xf8, 0x9a, 0x3d, 0xc1, 0x60,\r | |
203 | 0xb0, 0xe1, 0x33, 0xb5, 0xa3, 0x88, 0xd1, 0x65, 0x19, 0x0a, 0x1a, 0xe7, 0xac,\r | |
204 | 0x7c, 0xa4, 0xc1, 0x82, 0x87, 0x4e, 0x38, 0xb1, 0x2f, 0x0d, 0xc5, 0x14, 0x87,\r | |
205 | 0x6f, 0xfd, 0x8d, 0x2e, 0xbc, 0x39, 0xb6, 0xe7, 0xe6, 0xc3, 0xe0, 0xe4, 0xcd,\r | |
206 | 0x27, 0x84, 0xef, 0x94, 0x42, 0xef, 0x29, 0x8b, 0x90, 0x46, 0x41, 0x3b, 0x81,\r | |
207 | 0x1b, 0x67, 0xd8, 0xf9, 0x43, 0x59, 0x65, 0xcb, 0x0d, 0xbc, 0xfd, 0x00, 0x92,\r | |
208 | 0x4f, 0xf4, 0x75, 0x3b, 0xa7, 0xa9, 0x24, 0xfc, 0x50, 0x41, 0x40, 0x79, 0xe0,\r | |
209 | 0x2d, 0x4f, 0x0a, 0x6a, 0x27, 0x76, 0x6e, 0x52, 0xed, 0x96, 0x69, 0x7b, 0xaf,\r | |
210 | 0x0f, 0xf7, 0x87, 0x05, 0xd0, 0x45, 0xc2, 0xad, 0x53, 0x14, 0x81, 0x1f, 0xfb,\r | |
211 | 0x30, 0x04, 0xaa, 0x37, 0x36, 0x61, 0xda, 0x4a, 0x69, 0x1b, 0x34, 0xd8, 0x68,\r | |
212 | 0xed, 0xd6, 0x02, 0xcf, 0x6c, 0x94, 0x0c, 0xd3, 0xcf, 0x6c, 0x22, 0x79, 0xad,\r | |
213 | 0xb1, 0xf0, 0xbc, 0x03, 0xa2, 0x46, 0x60, 0xa9, 0xc4, 0x07, 0xc2, 0x21, 0x82,\r | |
214 | 0xf1, 0xfd, 0xf2, 0xe8, 0x79, 0x32, 0x60, 0xbf, 0xd8, 0xac, 0xa5, 0x22, 0x14,\r | |
215 | 0x4b, 0xca, 0xc1, 0xd8, 0x4b, 0xeb, 0x7d, 0x3f, 0x57, 0x35, 0xb2, 0xe6, 0x4f,\r | |
216 | 0x75, 0xb4, 0xb0, 0x60, 0x03, 0x22, 0x53, 0xae, 0x91, 0x79, 0x1d, 0xd6, 0x9b,\r | |
217 | 0x41, 0x1f, 0x15, 0x86, 0x54, 0x70, 0xb2, 0xde, 0x0d, 0x35, 0x0f, 0x7c, 0xb0,\r | |
218 | 0x34, 0x72, 0xba, 0x97, 0x60, 0x3b, 0xf0, 0x79, 0xeb, 0xa2, 0xb2, 0x1c, 0x5d,\r | |
219 | 0xa2, 0x16, 0xb8, 0x87, 0xc5, 0xe9, 0x1b, 0xf6, 0xb5, 0x97, 0x25, 0x6f, 0x38,\r | |
220 | 0x9f, 0xe3, 0x91, 0xfa, 0x8a, 0x79, 0x98, 0xc3, 0x69, 0x0e, 0xb7, 0xa3, 0x1c,\r | |
221 | 0x20, 0x05, 0x97, 0xf8, 0xca, 0x14, 0xae, 0x00, 0xd7, 0xc4, 0xf3, 0xc0, 0x14,\r | |
222 | 0x10, 0x75, 0x6b, 0x34, 0xa0, 0x1b, 0xb5, 0x99, 0x60, 0xf3, 0x5c, 0xb0, 0xc5,\r | |
223 | 0x57, 0x4e, 0x36, 0xd2, 0x32, 0x84, 0xbf, 0x9e\r | |
224 | };\r | |
225 | \r | |
226 | //\r | |
227 | // First DB entry: "Microsoft Windows Production PCA 2011"\r | |
228 | // SHA1: 58:0a:6f:4c:c4:e4:b6:69:b9:eb:dc:1b:2b:3e:08:7b:80:d0:67:8d\r | |
229 | //\r | |
230 | // Windows 8 and Windows Server 2012 R2 boot loaders are signed with a chain\r | |
231 | // rooted in this certificate.\r | |
232 | //\r | |
32d1440a | 233 | STATIC CONST UINT8 mMicrosoftPCA[] = {\r |
b1163623 LE |
234 | 0x30, 0x82, 0x05, 0xd7, 0x30, 0x82, 0x03, 0xbf, 0xa0, 0x03, 0x02, 0x01, 0x02,\r |
235 | 0x02, 0x0a, 0x61, 0x07, 0x76, 0x56, 0x00, 0x00, 0x00, 0x00, 0x00, 0x08, 0x30,\r | |
236 | 0x0d, 0x06, 0x09, 0x2a, 0x86, 0x48, 0x86, 0xf7, 0x0d, 0x01, 0x01, 0x0b, 0x05,\r | |
237 | 0x00, 0x30, 0x81, 0x88, 0x31, 0x0b, 0x30, 0x09, 0x06, 0x03, 0x55, 0x04, 0x06,\r | |
238 | 0x13, 0x02, 0x55, 0x53, 0x31, 0x13, 0x30, 0x11, 0x06, 0x03, 0x55, 0x04, 0x08,\r | |
239 | 0x13, 0x0a, 0x57, 0x61, 0x73, 0x68, 0x69, 0x6e, 0x67, 0x74, 0x6f, 0x6e, 0x31,\r | |
240 | 0x10, 0x30, 0x0e, 0x06, 0x03, 0x55, 0x04, 0x07, 0x13, 0x07, 0x52, 0x65, 0x64,\r | |
241 | 0x6d, 0x6f, 0x6e, 0x64, 0x31, 0x1e, 0x30, 0x1c, 0x06, 0x03, 0x55, 0x04, 0x0a,\r | |
242 | 0x13, 0x15, 0x4d, 0x69, 0x63, 0x72, 0x6f, 0x73, 0x6f, 0x66, 0x74, 0x20, 0x43,\r | |
243 | 0x6f, 0x72, 0x70, 0x6f, 0x72, 0x61, 0x74, 0x69, 0x6f, 0x6e, 0x31, 0x32, 0x30,\r | |
244 | 0x30, 0x06, 0x03, 0x55, 0x04, 0x03, 0x13, 0x29, 0x4d, 0x69, 0x63, 0x72, 0x6f,\r | |
245 | 0x73, 0x6f, 0x66, 0x74, 0x20, 0x52, 0x6f, 0x6f, 0x74, 0x20, 0x43, 0x65, 0x72,\r | |
246 | 0x74, 0x69, 0x66, 0x69, 0x63, 0x61, 0x74, 0x65, 0x20, 0x41, 0x75, 0x74, 0x68,\r | |
247 | 0x6f, 0x72, 0x69, 0x74, 0x79, 0x20, 0x32, 0x30, 0x31, 0x30, 0x30, 0x1e, 0x17,\r | |
248 | 0x0d, 0x31, 0x31, 0x31, 0x30, 0x31, 0x39, 0x31, 0x38, 0x34, 0x31, 0x34, 0x32,\r | |
249 | 0x5a, 0x17, 0x0d, 0x32, 0x36, 0x31, 0x30, 0x31, 0x39, 0x31, 0x38, 0x35, 0x31,\r | |
250 | 0x34, 0x32, 0x5a, 0x30, 0x81, 0x84, 0x31, 0x0b, 0x30, 0x09, 0x06, 0x03, 0x55,\r | |
251 | 0x04, 0x06, 0x13, 0x02, 0x55, 0x53, 0x31, 0x13, 0x30, 0x11, 0x06, 0x03, 0x55,\r | |
252 | 0x04, 0x08, 0x13, 0x0a, 0x57, 0x61, 0x73, 0x68, 0x69, 0x6e, 0x67, 0x74, 0x6f,\r | |
253 | 0x6e, 0x31, 0x10, 0x30, 0x0e, 0x06, 0x03, 0x55, 0x04, 0x07, 0x13, 0x07, 0x52,\r | |
254 | 0x65, 0x64, 0x6d, 0x6f, 0x6e, 0x64, 0x31, 0x1e, 0x30, 0x1c, 0x06, 0x03, 0x55,\r | |
255 | 0x04, 0x0a, 0x13, 0x15, 0x4d, 0x69, 0x63, 0x72, 0x6f, 0x73, 0x6f, 0x66, 0x74,\r | |
256 | 0x20, 0x43, 0x6f, 0x72, 0x70, 0x6f, 0x72, 0x61, 0x74, 0x69, 0x6f, 0x6e, 0x31,\r | |
257 | 0x2e, 0x30, 0x2c, 0x06, 0x03, 0x55, 0x04, 0x03, 0x13, 0x25, 0x4d, 0x69, 0x63,\r | |
258 | 0x72, 0x6f, 0x73, 0x6f, 0x66, 0x74, 0x20, 0x57, 0x69, 0x6e, 0x64, 0x6f, 0x77,\r | |
259 | 0x73, 0x20, 0x50, 0x72, 0x6f, 0x64, 0x75, 0x63, 0x74, 0x69, 0x6f, 0x6e, 0x20,\r | |
260 | 0x50, 0x43, 0x41, 0x20, 0x32, 0x30, 0x31, 0x31, 0x30, 0x82, 0x01, 0x22, 0x30,\r | |
261 | 0x0d, 0x06, 0x09, 0x2a, 0x86, 0x48, 0x86, 0xf7, 0x0d, 0x01, 0x01, 0x01, 0x05,\r | |
262 | 0x00, 0x03, 0x82, 0x01, 0x0f, 0x00, 0x30, 0x82, 0x01, 0x0a, 0x02, 0x82, 0x01,\r | |
263 | 0x01, 0x00, 0xdd, 0x0c, 0xbb, 0xa2, 0xe4, 0x2e, 0x09, 0xe3, 0xe7, 0xc5, 0xf7,\r | |
264 | 0x96, 0x69, 0xbc, 0x00, 0x21, 0xbd, 0x69, 0x33, 0x33, 0xef, 0xad, 0x04, 0xcb,\r | |
265 | 0x54, 0x80, 0xee, 0x06, 0x83, 0xbb, 0xc5, 0x20, 0x84, 0xd9, 0xf7, 0xd2, 0x8b,\r | |
266 | 0xf3, 0x38, 0xb0, 0xab, 0xa4, 0xad, 0x2d, 0x7c, 0x62, 0x79, 0x05, 0xff, 0xe3,\r | |
267 | 0x4a, 0x3f, 0x04, 0x35, 0x20, 0x70, 0xe3, 0xc4, 0xe7, 0x6b, 0xe0, 0x9c, 0xc0,\r | |
268 | 0x36, 0x75, 0xe9, 0x8a, 0x31, 0xdd, 0x8d, 0x70, 0xe5, 0xdc, 0x37, 0xb5, 0x74,\r | |
269 | 0x46, 0x96, 0x28, 0x5b, 0x87, 0x60, 0x23, 0x2c, 0xbf, 0xdc, 0x47, 0xa5, 0x67,\r | |
270 | 0xf7, 0x51, 0x27, 0x9e, 0x72, 0xeb, 0x07, 0xa6, 0xc9, 0xb9, 0x1e, 0x3b, 0x53,\r | |
271 | 0x35, 0x7c, 0xe5, 0xd3, 0xec, 0x27, 0xb9, 0x87, 0x1c, 0xfe, 0xb9, 0xc9, 0x23,\r | |
272 | 0x09, 0x6f, 0xa8, 0x46, 0x91, 0xc1, 0x6e, 0x96, 0x3c, 0x41, 0xd3, 0xcb, 0xa3,\r | |
273 | 0x3f, 0x5d, 0x02, 0x6a, 0x4d, 0xec, 0x69, 0x1f, 0x25, 0x28, 0x5c, 0x36, 0xff,\r | |
274 | 0xfd, 0x43, 0x15, 0x0a, 0x94, 0xe0, 0x19, 0xb4, 0xcf, 0xdf, 0xc2, 0x12, 0xe2,\r | |
275 | 0xc2, 0x5b, 0x27, 0xee, 0x27, 0x78, 0x30, 0x8b, 0x5b, 0x2a, 0x09, 0x6b, 0x22,\r | |
276 | 0x89, 0x53, 0x60, 0x16, 0x2c, 0xc0, 0x68, 0x1d, 0x53, 0xba, 0xec, 0x49, 0xf3,\r | |
277 | 0x9d, 0x61, 0x8c, 0x85, 0x68, 0x09, 0x73, 0x44, 0x5d, 0x7d, 0xa2, 0x54, 0x2b,\r | |
278 | 0xdd, 0x79, 0xf7, 0x15, 0xcf, 0x35, 0x5d, 0x6c, 0x1c, 0x2b, 0x5c, 0xce, 0xbc,\r | |
279 | 0x9c, 0x23, 0x8b, 0x6f, 0x6e, 0xb5, 0x26, 0xd9, 0x36, 0x13, 0xc3, 0x4f, 0xd6,\r | |
280 | 0x27, 0xae, 0xb9, 0x32, 0x3b, 0x41, 0x92, 0x2c, 0xe1, 0xc7, 0xcd, 0x77, 0xe8,\r | |
281 | 0xaa, 0x54, 0x4e, 0xf7, 0x5c, 0x0b, 0x04, 0x87, 0x65, 0xb4, 0x43, 0x18, 0xa8,\r | |
282 | 0xb2, 0xe0, 0x6d, 0x19, 0x77, 0xec, 0x5a, 0x24, 0xfa, 0x48, 0x03, 0x02, 0x03,\r | |
283 | 0x01, 0x00, 0x01, 0xa3, 0x82, 0x01, 0x43, 0x30, 0x82, 0x01, 0x3f, 0x30, 0x10,\r | |
284 | 0x06, 0x09, 0x2b, 0x06, 0x01, 0x04, 0x01, 0x82, 0x37, 0x15, 0x01, 0x04, 0x03,\r | |
285 | 0x02, 0x01, 0x00, 0x30, 0x1d, 0x06, 0x03, 0x55, 0x1d, 0x0e, 0x04, 0x16, 0x04,\r | |
286 | 0x14, 0xa9, 0x29, 0x02, 0x39, 0x8e, 0x16, 0xc4, 0x97, 0x78, 0xcd, 0x90, 0xf9,\r | |
287 | 0x9e, 0x4f, 0x9a, 0xe1, 0x7c, 0x55, 0xaf, 0x53, 0x30, 0x19, 0x06, 0x09, 0x2b,\r | |
288 | 0x06, 0x01, 0x04, 0x01, 0x82, 0x37, 0x14, 0x02, 0x04, 0x0c, 0x1e, 0x0a, 0x00,\r | |
289 | 0x53, 0x00, 0x75, 0x00, 0x62, 0x00, 0x43, 0x00, 0x41, 0x30, 0x0b, 0x06, 0x03,\r | |
290 | 0x55, 0x1d, 0x0f, 0x04, 0x04, 0x03, 0x02, 0x01, 0x86, 0x30, 0x0f, 0x06, 0x03,\r | |
291 | 0x55, 0x1d, 0x13, 0x01, 0x01, 0xff, 0x04, 0x05, 0x30, 0x03, 0x01, 0x01, 0xff,\r | |
292 | 0x30, 0x1f, 0x06, 0x03, 0x55, 0x1d, 0x23, 0x04, 0x18, 0x30, 0x16, 0x80, 0x14,\r | |
293 | 0xd5, 0xf6, 0x56, 0xcb, 0x8f, 0xe8, 0xa2, 0x5c, 0x62, 0x68, 0xd1, 0x3d, 0x94,\r | |
294 | 0x90, 0x5b, 0xd7, 0xce, 0x9a, 0x18, 0xc4, 0x30, 0x56, 0x06, 0x03, 0x55, 0x1d,\r | |
295 | 0x1f, 0x04, 0x4f, 0x30, 0x4d, 0x30, 0x4b, 0xa0, 0x49, 0xa0, 0x47, 0x86, 0x45,\r | |
296 | 0x68, 0x74, 0x74, 0x70, 0x3a, 0x2f, 0x2f, 0x63, 0x72, 0x6c, 0x2e, 0x6d, 0x69,\r | |
297 | 0x63, 0x72, 0x6f, 0x73, 0x6f, 0x66, 0x74, 0x2e, 0x63, 0x6f, 0x6d, 0x2f, 0x70,\r | |
298 | 0x6b, 0x69, 0x2f, 0x63, 0x72, 0x6c, 0x2f, 0x70, 0x72, 0x6f, 0x64, 0x75, 0x63,\r | |
299 | 0x74, 0x73, 0x2f, 0x4d, 0x69, 0x63, 0x52, 0x6f, 0x6f, 0x43, 0x65, 0x72, 0x41,\r | |
300 | 0x75, 0x74, 0x5f, 0x32, 0x30, 0x31, 0x30, 0x2d, 0x30, 0x36, 0x2d, 0x32, 0x33,\r | |
301 | 0x2e, 0x63, 0x72, 0x6c, 0x30, 0x5a, 0x06, 0x08, 0x2b, 0x06, 0x01, 0x05, 0x05,\r | |
302 | 0x07, 0x01, 0x01, 0x04, 0x4e, 0x30, 0x4c, 0x30, 0x4a, 0x06, 0x08, 0x2b, 0x06,\r | |
303 | 0x01, 0x05, 0x05, 0x07, 0x30, 0x02, 0x86, 0x3e, 0x68, 0x74, 0x74, 0x70, 0x3a,\r | |
304 | 0x2f, 0x2f, 0x77, 0x77, 0x77, 0x2e, 0x6d, 0x69, 0x63, 0x72, 0x6f, 0x73, 0x6f,\r | |
305 | 0x66, 0x74, 0x2e, 0x63, 0x6f, 0x6d, 0x2f, 0x70, 0x6b, 0x69, 0x2f, 0x63, 0x65,\r | |
306 | 0x72, 0x74, 0x73, 0x2f, 0x4d, 0x69, 0x63, 0x52, 0x6f, 0x6f, 0x43, 0x65, 0x72,\r | |
307 | 0x41, 0x75, 0x74, 0x5f, 0x32, 0x30, 0x31, 0x30, 0x2d, 0x30, 0x36, 0x2d, 0x32,\r | |
308 | 0x33, 0x2e, 0x63, 0x72, 0x74, 0x30, 0x0d, 0x06, 0x09, 0x2a, 0x86, 0x48, 0x86,\r | |
309 | 0xf7, 0x0d, 0x01, 0x01, 0x0b, 0x05, 0x00, 0x03, 0x82, 0x02, 0x01, 0x00, 0x14,\r | |
310 | 0xfc, 0x7c, 0x71, 0x51, 0xa5, 0x79, 0xc2, 0x6e, 0xb2, 0xef, 0x39, 0x3e, 0xbc,\r | |
311 | 0x3c, 0x52, 0x0f, 0x6e, 0x2b, 0x3f, 0x10, 0x13, 0x73, 0xfe, 0xa8, 0x68, 0xd0,\r | |
312 | 0x48, 0xa6, 0x34, 0x4d, 0x8a, 0x96, 0x05, 0x26, 0xee, 0x31, 0x46, 0x90, 0x61,\r | |
313 | 0x79, 0xd6, 0xff, 0x38, 0x2e, 0x45, 0x6b, 0xf4, 0xc0, 0xe5, 0x28, 0xb8, 0xda,\r | |
314 | 0x1d, 0x8f, 0x8a, 0xdb, 0x09, 0xd7, 0x1a, 0xc7, 0x4c, 0x0a, 0x36, 0x66, 0x6a,\r | |
315 | 0x8c, 0xec, 0x1b, 0xd7, 0x04, 0x90, 0xa8, 0x18, 0x17, 0xa4, 0x9b, 0xb9, 0xe2,\r | |
316 | 0x40, 0x32, 0x36, 0x76, 0xc4, 0xc1, 0x5a, 0xc6, 0xbf, 0xe4, 0x04, 0xc0, 0xea,\r | |
317 | 0x16, 0xd3, 0xac, 0xc3, 0x68, 0xef, 0x62, 0xac, 0xdd, 0x54, 0x6c, 0x50, 0x30,\r | |
318 | 0x58, 0xa6, 0xeb, 0x7c, 0xfe, 0x94, 0xa7, 0x4e, 0x8e, 0xf4, 0xec, 0x7c, 0x86,\r | |
319 | 0x73, 0x57, 0xc2, 0x52, 0x21, 0x73, 0x34, 0x5a, 0xf3, 0xa3, 0x8a, 0x56, 0xc8,\r | |
320 | 0x04, 0xda, 0x07, 0x09, 0xed, 0xf8, 0x8b, 0xe3, 0xce, 0xf4, 0x7e, 0x8e, 0xae,\r | |
321 | 0xf0, 0xf6, 0x0b, 0x8a, 0x08, 0xfb, 0x3f, 0xc9, 0x1d, 0x72, 0x7f, 0x53, 0xb8,\r | |
322 | 0xeb, 0xbe, 0x63, 0xe0, 0xe3, 0x3d, 0x31, 0x65, 0xb0, 0x81, 0xe5, 0xf2, 0xac,\r | |
323 | 0xcd, 0x16, 0xa4, 0x9f, 0x3d, 0xa8, 0xb1, 0x9b, 0xc2, 0x42, 0xd0, 0x90, 0x84,\r | |
324 | 0x5f, 0x54, 0x1d, 0xff, 0x89, 0xea, 0xba, 0x1d, 0x47, 0x90, 0x6f, 0xb0, 0x73,\r | |
325 | 0x4e, 0x41, 0x9f, 0x40, 0x9f, 0x5f, 0xe5, 0xa1, 0x2a, 0xb2, 0x11, 0x91, 0x73,\r | |
326 | 0x8a, 0x21, 0x28, 0xf0, 0xce, 0xde, 0x73, 0x39, 0x5f, 0x3e, 0xab, 0x5c, 0x60,\r | |
327 | 0xec, 0xdf, 0x03, 0x10, 0xa8, 0xd3, 0x09, 0xe9, 0xf4, 0xf6, 0x96, 0x85, 0xb6,\r | |
328 | 0x7f, 0x51, 0x88, 0x66, 0x47, 0x19, 0x8d, 0xa2, 0xb0, 0x12, 0x3d, 0x81, 0x2a,\r | |
329 | 0x68, 0x05, 0x77, 0xbb, 0x91, 0x4c, 0x62, 0x7b, 0xb6, 0xc1, 0x07, 0xc7, 0xba,\r | |
330 | 0x7a, 0x87, 0x34, 0x03, 0x0e, 0x4b, 0x62, 0x7a, 0x99, 0xe9, 0xca, 0xfc, 0xce,\r | |
331 | 0x4a, 0x37, 0xc9, 0x2d, 0xa4, 0x57, 0x7c, 0x1c, 0xfe, 0x3d, 0xdc, 0xb8, 0x0f,\r | |
332 | 0x5a, 0xfa, 0xd6, 0xc4, 0xb3, 0x02, 0x85, 0x02, 0x3a, 0xea, 0xb3, 0xd9, 0x6e,\r | |
333 | 0xe4, 0x69, 0x21, 0x37, 0xde, 0x81, 0xd1, 0xf6, 0x75, 0x19, 0x05, 0x67, 0xd3,\r | |
334 | 0x93, 0x57, 0x5e, 0x29, 0x1b, 0x39, 0xc8, 0xee, 0x2d, 0xe1, 0xcd, 0xe4, 0x45,\r | |
335 | 0x73, 0x5b, 0xd0, 0xd2, 0xce, 0x7a, 0xab, 0x16, 0x19, 0x82, 0x46, 0x58, 0xd0,\r | |
336 | 0x5e, 0x9d, 0x81, 0xb3, 0x67, 0xaf, 0x6c, 0x35, 0xf2, 0xbc, 0xe5, 0x3f, 0x24,\r | |
337 | 0xe2, 0x35, 0xa2, 0x0a, 0x75, 0x06, 0xf6, 0x18, 0x56, 0x99, 0xd4, 0x78, 0x2c,\r | |
338 | 0xd1, 0x05, 0x1b, 0xeb, 0xd0, 0x88, 0x01, 0x9d, 0xaa, 0x10, 0xf1, 0x05, 0xdf,\r | |
339 | 0xba, 0x7e, 0x2c, 0x63, 0xb7, 0x06, 0x9b, 0x23, 0x21, 0xc4, 0xf9, 0x78, 0x6c,\r | |
340 | 0xe2, 0x58, 0x17, 0x06, 0x36, 0x2b, 0x91, 0x12, 0x03, 0xcc, 0xa4, 0xd9, 0xf2,\r | |
341 | 0x2d, 0xba, 0xf9, 0x94, 0x9d, 0x40, 0xed, 0x18, 0x45, 0xf1, 0xce, 0x8a, 0x5c,\r | |
342 | 0x6b, 0x3e, 0xab, 0x03, 0xd3, 0x70, 0x18, 0x2a, 0x0a, 0x6a, 0xe0, 0x5f, 0x47,\r | |
343 | 0xd1, 0xd5, 0x63, 0x0a, 0x32, 0xf2, 0xaf, 0xd7, 0x36, 0x1f, 0x2a, 0x70, 0x5a,\r | |
344 | 0xe5, 0x42, 0x59, 0x08, 0x71, 0x4b, 0x57, 0xba, 0x7e, 0x83, 0x81, 0xf0, 0x21,\r | |
345 | 0x3c, 0xf4, 0x1c, 0xc1, 0xc5, 0xb9, 0x90, 0x93, 0x0e, 0x88, 0x45, 0x93, 0x86,\r | |
346 | 0xe9, 0xb1, 0x20, 0x99, 0xbe, 0x98, 0xcb, 0xc5, 0x95, 0xa4, 0x5d, 0x62, 0xd6,\r | |
347 | 0xa0, 0x63, 0x08, 0x20, 0xbd, 0x75, 0x10, 0x77, 0x7d, 0x3d, 0xf3, 0x45, 0xb9,\r | |
348 | 0x9f, 0x97, 0x9f, 0xcb, 0x57, 0x80, 0x6f, 0x33, 0xa9, 0x04, 0xcf, 0x77, 0xa4,\r | |
349 | 0x62, 0x1c, 0x59, 0x7e\r | |
350 | };\r | |
351 | \r | |
352 | //\r | |
353 | // Second DB entry: "Microsoft Corporation UEFI CA 2011"\r | |
354 | // SHA1: 46:de:f6:3b:5c:e6:1c:f8:ba:0d:e2:e6:63:9c:10:19:d0:ed:14:f3\r | |
355 | //\r | |
356 | // To verify the "shim" binary and PCI expansion ROMs with.\r | |
357 | //\r | |
32d1440a | 358 | STATIC CONST UINT8 mMicrosoftUefiCA[] = {\r |
b1163623 LE |
359 | 0x30, 0x82, 0x06, 0x10, 0x30, 0x82, 0x03, 0xf8, 0xa0, 0x03, 0x02, 0x01, 0x02,\r |
360 | 0x02, 0x0a, 0x61, 0x08, 0xd3, 0xc4, 0x00, 0x00, 0x00, 0x00, 0x00, 0x04, 0x30,\r | |
361 | 0x0d, 0x06, 0x09, 0x2a, 0x86, 0x48, 0x86, 0xf7, 0x0d, 0x01, 0x01, 0x0b, 0x05,\r | |
362 | 0x00, 0x30, 0x81, 0x91, 0x31, 0x0b, 0x30, 0x09, 0x06, 0x03, 0x55, 0x04, 0x06,\r | |
363 | 0x13, 0x02, 0x55, 0x53, 0x31, 0x13, 0x30, 0x11, 0x06, 0x03, 0x55, 0x04, 0x08,\r | |
364 | 0x13, 0x0a, 0x57, 0x61, 0x73, 0x68, 0x69, 0x6e, 0x67, 0x74, 0x6f, 0x6e, 0x31,\r | |
365 | 0x10, 0x30, 0x0e, 0x06, 0x03, 0x55, 0x04, 0x07, 0x13, 0x07, 0x52, 0x65, 0x64,\r | |
366 | 0x6d, 0x6f, 0x6e, 0x64, 0x31, 0x1e, 0x30, 0x1c, 0x06, 0x03, 0x55, 0x04, 0x0a,\r | |
367 | 0x13, 0x15, 0x4d, 0x69, 0x63, 0x72, 0x6f, 0x73, 0x6f, 0x66, 0x74, 0x20, 0x43,\r | |
368 | 0x6f, 0x72, 0x70, 0x6f, 0x72, 0x61, 0x74, 0x69, 0x6f, 0x6e, 0x31, 0x3b, 0x30,\r | |
369 | 0x39, 0x06, 0x03, 0x55, 0x04, 0x03, 0x13, 0x32, 0x4d, 0x69, 0x63, 0x72, 0x6f,\r | |
370 | 0x73, 0x6f, 0x66, 0x74, 0x20, 0x43, 0x6f, 0x72, 0x70, 0x6f, 0x72, 0x61, 0x74,\r | |
371 | 0x69, 0x6f, 0x6e, 0x20, 0x54, 0x68, 0x69, 0x72, 0x64, 0x20, 0x50, 0x61, 0x72,\r | |
372 | 0x74, 0x79, 0x20, 0x4d, 0x61, 0x72, 0x6b, 0x65, 0x74, 0x70, 0x6c, 0x61, 0x63,\r | |
373 | 0x65, 0x20, 0x52, 0x6f, 0x6f, 0x74, 0x30, 0x1e, 0x17, 0x0d, 0x31, 0x31, 0x30,\r | |
374 | 0x36, 0x32, 0x37, 0x32, 0x31, 0x32, 0x32, 0x34, 0x35, 0x5a, 0x17, 0x0d, 0x32,\r | |
375 | 0x36, 0x30, 0x36, 0x32, 0x37, 0x32, 0x31, 0x33, 0x32, 0x34, 0x35, 0x5a, 0x30,\r | |
376 | 0x81, 0x81, 0x31, 0x0b, 0x30, 0x09, 0x06, 0x03, 0x55, 0x04, 0x06, 0x13, 0x02,\r | |
377 | 0x55, 0x53, 0x31, 0x13, 0x30, 0x11, 0x06, 0x03, 0x55, 0x04, 0x08, 0x13, 0x0a,\r | |
378 | 0x57, 0x61, 0x73, 0x68, 0x69, 0x6e, 0x67, 0x74, 0x6f, 0x6e, 0x31, 0x10, 0x30,\r | |
379 | 0x0e, 0x06, 0x03, 0x55, 0x04, 0x07, 0x13, 0x07, 0x52, 0x65, 0x64, 0x6d, 0x6f,\r | |
380 | 0x6e, 0x64, 0x31, 0x1e, 0x30, 0x1c, 0x06, 0x03, 0x55, 0x04, 0x0a, 0x13, 0x15,\r | |
381 | 0x4d, 0x69, 0x63, 0x72, 0x6f, 0x73, 0x6f, 0x66, 0x74, 0x20, 0x43, 0x6f, 0x72,\r | |
382 | 0x70, 0x6f, 0x72, 0x61, 0x74, 0x69, 0x6f, 0x6e, 0x31, 0x2b, 0x30, 0x29, 0x06,\r | |
383 | 0x03, 0x55, 0x04, 0x03, 0x13, 0x22, 0x4d, 0x69, 0x63, 0x72, 0x6f, 0x73, 0x6f,\r | |
384 | 0x66, 0x74, 0x20, 0x43, 0x6f, 0x72, 0x70, 0x6f, 0x72, 0x61, 0x74, 0x69, 0x6f,\r | |
385 | 0x6e, 0x20, 0x55, 0x45, 0x46, 0x49, 0x20, 0x43, 0x41, 0x20, 0x32, 0x30, 0x31,\r | |
386 | 0x31, 0x30, 0x82, 0x01, 0x22, 0x30, 0x0d, 0x06, 0x09, 0x2a, 0x86, 0x48, 0x86,\r | |
387 | 0xf7, 0x0d, 0x01, 0x01, 0x01, 0x05, 0x00, 0x03, 0x82, 0x01, 0x0f, 0x00, 0x30,\r | |
388 | 0x82, 0x01, 0x0a, 0x02, 0x82, 0x01, 0x01, 0x00, 0xa5, 0x08, 0x6c, 0x4c, 0xc7,\r | |
389 | 0x45, 0x09, 0x6a, 0x4b, 0x0c, 0xa4, 0xc0, 0x87, 0x7f, 0x06, 0x75, 0x0c, 0x43,\r | |
390 | 0x01, 0x54, 0x64, 0xe0, 0x16, 0x7f, 0x07, 0xed, 0x92, 0x7d, 0x0b, 0xb2, 0x73,\r | |
391 | 0xbf, 0x0c, 0x0a, 0xc6, 0x4a, 0x45, 0x61, 0xa0, 0xc5, 0x16, 0x2d, 0x96, 0xd3,\r | |
392 | 0xf5, 0x2b, 0xa0, 0xfb, 0x4d, 0x49, 0x9b, 0x41, 0x80, 0x90, 0x3c, 0xb9, 0x54,\r | |
393 | 0xfd, 0xe6, 0xbc, 0xd1, 0x9d, 0xc4, 0xa4, 0x18, 0x8a, 0x7f, 0x41, 0x8a, 0x5c,\r | |
394 | 0x59, 0x83, 0x68, 0x32, 0xbb, 0x8c, 0x47, 0xc9, 0xee, 0x71, 0xbc, 0x21, 0x4f,\r | |
395 | 0x9a, 0x8a, 0x7c, 0xff, 0x44, 0x3f, 0x8d, 0x8f, 0x32, 0xb2, 0x26, 0x48, 0xae,\r | |
396 | 0x75, 0xb5, 0xee, 0xc9, 0x4c, 0x1e, 0x4a, 0x19, 0x7e, 0xe4, 0x82, 0x9a, 0x1d,\r | |
397 | 0x78, 0x77, 0x4d, 0x0c, 0xb0, 0xbd, 0xf6, 0x0f, 0xd3, 0x16, 0xd3, 0xbc, 0xfa,\r | |
398 | 0x2b, 0xa5, 0x51, 0x38, 0x5d, 0xf5, 0xfb, 0xba, 0xdb, 0x78, 0x02, 0xdb, 0xff,\r | |
399 | 0xec, 0x0a, 0x1b, 0x96, 0xd5, 0x83, 0xb8, 0x19, 0x13, 0xe9, 0xb6, 0xc0, 0x7b,\r | |
400 | 0x40, 0x7b, 0xe1, 0x1f, 0x28, 0x27, 0xc9, 0xfa, 0xef, 0x56, 0x5e, 0x1c, 0xe6,\r | |
401 | 0x7e, 0x94, 0x7e, 0xc0, 0xf0, 0x44, 0xb2, 0x79, 0x39, 0xe5, 0xda, 0xb2, 0x62,\r | |
402 | 0x8b, 0x4d, 0xbf, 0x38, 0x70, 0xe2, 0x68, 0x24, 0x14, 0xc9, 0x33, 0xa4, 0x08,\r | |
403 | 0x37, 0xd5, 0x58, 0x69, 0x5e, 0xd3, 0x7c, 0xed, 0xc1, 0x04, 0x53, 0x08, 0xe7,\r | |
404 | 0x4e, 0xb0, 0x2a, 0x87, 0x63, 0x08, 0x61, 0x6f, 0x63, 0x15, 0x59, 0xea, 0xb2,\r | |
405 | 0x2b, 0x79, 0xd7, 0x0c, 0x61, 0x67, 0x8a, 0x5b, 0xfd, 0x5e, 0xad, 0x87, 0x7f,\r | |
406 | 0xba, 0x86, 0x67, 0x4f, 0x71, 0x58, 0x12, 0x22, 0x04, 0x22, 0x22, 0xce, 0x8b,\r | |
407 | 0xef, 0x54, 0x71, 0x00, 0xce, 0x50, 0x35, 0x58, 0x76, 0x95, 0x08, 0xee, 0x6a,\r | |
408 | 0xb1, 0xa2, 0x01, 0xd5, 0x02, 0x03, 0x01, 0x00, 0x01, 0xa3, 0x82, 0x01, 0x76,\r | |
409 | 0x30, 0x82, 0x01, 0x72, 0x30, 0x12, 0x06, 0x09, 0x2b, 0x06, 0x01, 0x04, 0x01,\r | |
410 | 0x82, 0x37, 0x15, 0x01, 0x04, 0x05, 0x02, 0x03, 0x01, 0x00, 0x01, 0x30, 0x23,\r | |
411 | 0x06, 0x09, 0x2b, 0x06, 0x01, 0x04, 0x01, 0x82, 0x37, 0x15, 0x02, 0x04, 0x16,\r | |
412 | 0x04, 0x14, 0xf8, 0xc1, 0x6b, 0xb7, 0x7f, 0x77, 0x53, 0x4a, 0xf3, 0x25, 0x37,\r | |
413 | 0x1d, 0x4e, 0xa1, 0x26, 0x7b, 0x0f, 0x20, 0x70, 0x80, 0x30, 0x1d, 0x06, 0x03,\r | |
414 | 0x55, 0x1d, 0x0e, 0x04, 0x16, 0x04, 0x14, 0x13, 0xad, 0xbf, 0x43, 0x09, 0xbd,\r | |
415 | 0x82, 0x70, 0x9c, 0x8c, 0xd5, 0x4f, 0x31, 0x6e, 0xd5, 0x22, 0x98, 0x8a, 0x1b,\r | |
416 | 0xd4, 0x30, 0x19, 0x06, 0x09, 0x2b, 0x06, 0x01, 0x04, 0x01, 0x82, 0x37, 0x14,\r | |
417 | 0x02, 0x04, 0x0c, 0x1e, 0x0a, 0x00, 0x53, 0x00, 0x75, 0x00, 0x62, 0x00, 0x43,\r | |
418 | 0x00, 0x41, 0x30, 0x0b, 0x06, 0x03, 0x55, 0x1d, 0x0f, 0x04, 0x04, 0x03, 0x02,\r | |
419 | 0x01, 0x86, 0x30, 0x0f, 0x06, 0x03, 0x55, 0x1d, 0x13, 0x01, 0x01, 0xff, 0x04,\r | |
420 | 0x05, 0x30, 0x03, 0x01, 0x01, 0xff, 0x30, 0x1f, 0x06, 0x03, 0x55, 0x1d, 0x23,\r | |
421 | 0x04, 0x18, 0x30, 0x16, 0x80, 0x14, 0x45, 0x66, 0x52, 0x43, 0xe1, 0x7e, 0x58,\r | |
422 | 0x11, 0xbf, 0xd6, 0x4e, 0x9e, 0x23, 0x55, 0x08, 0x3b, 0x3a, 0x22, 0x6a, 0xa8,\r | |
423 | 0x30, 0x5c, 0x06, 0x03, 0x55, 0x1d, 0x1f, 0x04, 0x55, 0x30, 0x53, 0x30, 0x51,\r | |
424 | 0xa0, 0x4f, 0xa0, 0x4d, 0x86, 0x4b, 0x68, 0x74, 0x74, 0x70, 0x3a, 0x2f, 0x2f,\r | |
425 | 0x63, 0x72, 0x6c, 0x2e, 0x6d, 0x69, 0x63, 0x72, 0x6f, 0x73, 0x6f, 0x66, 0x74,\r | |
426 | 0x2e, 0x63, 0x6f, 0x6d, 0x2f, 0x70, 0x6b, 0x69, 0x2f, 0x63, 0x72, 0x6c, 0x2f,\r | |
427 | 0x70, 0x72, 0x6f, 0x64, 0x75, 0x63, 0x74, 0x73, 0x2f, 0x4d, 0x69, 0x63, 0x43,\r | |
428 | 0x6f, 0x72, 0x54, 0x68, 0x69, 0x50, 0x61, 0x72, 0x4d, 0x61, 0x72, 0x52, 0x6f,\r | |
429 | 0x6f, 0x5f, 0x32, 0x30, 0x31, 0x30, 0x2d, 0x31, 0x30, 0x2d, 0x30, 0x35, 0x2e,\r | |
430 | 0x63, 0x72, 0x6c, 0x30, 0x60, 0x06, 0x08, 0x2b, 0x06, 0x01, 0x05, 0x05, 0x07,\r | |
431 | 0x01, 0x01, 0x04, 0x54, 0x30, 0x52, 0x30, 0x50, 0x06, 0x08, 0x2b, 0x06, 0x01,\r | |
432 | 0x05, 0x05, 0x07, 0x30, 0x02, 0x86, 0x44, 0x68, 0x74, 0x74, 0x70, 0x3a, 0x2f,\r | |
433 | 0x2f, 0x77, 0x77, 0x77, 0x2e, 0x6d, 0x69, 0x63, 0x72, 0x6f, 0x73, 0x6f, 0x66,\r | |
434 | 0x74, 0x2e, 0x63, 0x6f, 0x6d, 0x2f, 0x70, 0x6b, 0x69, 0x2f, 0x63, 0x65, 0x72,\r | |
435 | 0x74, 0x73, 0x2f, 0x4d, 0x69, 0x63, 0x43, 0x6f, 0x72, 0x54, 0x68, 0x69, 0x50,\r | |
436 | 0x61, 0x72, 0x4d, 0x61, 0x72, 0x52, 0x6f, 0x6f, 0x5f, 0x32, 0x30, 0x31, 0x30,\r | |
437 | 0x2d, 0x31, 0x30, 0x2d, 0x30, 0x35, 0x2e, 0x63, 0x72, 0x74, 0x30, 0x0d, 0x06,\r | |
438 | 0x09, 0x2a, 0x86, 0x48, 0x86, 0xf7, 0x0d, 0x01, 0x01, 0x0b, 0x05, 0x00, 0x03,\r | |
439 | 0x82, 0x02, 0x01, 0x00, 0x35, 0x08, 0x42, 0xff, 0x30, 0xcc, 0xce, 0xf7, 0x76,\r | |
440 | 0x0c, 0xad, 0x10, 0x68, 0x58, 0x35, 0x29, 0x46, 0x32, 0x76, 0x27, 0x7c, 0xef,\r | |
441 | 0x12, 0x41, 0x27, 0x42, 0x1b, 0x4a, 0xaa, 0x6d, 0x81, 0x38, 0x48, 0x59, 0x13,\r | |
442 | 0x55, 0xf3, 0xe9, 0x58, 0x34, 0xa6, 0x16, 0x0b, 0x82, 0xaa, 0x5d, 0xad, 0x82,\r | |
443 | 0xda, 0x80, 0x83, 0x41, 0x06, 0x8f, 0xb4, 0x1d, 0xf2, 0x03, 0xb9, 0xf3, 0x1a,\r | |
444 | 0x5d, 0x1b, 0xf1, 0x50, 0x90, 0xf9, 0xb3, 0x55, 0x84, 0x42, 0x28, 0x1c, 0x20,\r | |
445 | 0xbd, 0xb2, 0xae, 0x51, 0x14, 0xc5, 0xc0, 0xac, 0x97, 0x95, 0x21, 0x1c, 0x90,\r | |
446 | 0xdb, 0x0f, 0xfc, 0x77, 0x9e, 0x95, 0x73, 0x91, 0x88, 0xca, 0xbd, 0xbd, 0x52,\r | |
447 | 0xb9, 0x05, 0x50, 0x0d, 0xdf, 0x57, 0x9e, 0xa0, 0x61, 0xed, 0x0d, 0xe5, 0x6d,\r | |
448 | 0x25, 0xd9, 0x40, 0x0f, 0x17, 0x40, 0xc8, 0xce, 0xa3, 0x4a, 0xc2, 0x4d, 0xaf,\r | |
449 | 0x9a, 0x12, 0x1d, 0x08, 0x54, 0x8f, 0xbd, 0xc7, 0xbc, 0xb9, 0x2b, 0x3d, 0x49,\r | |
450 | 0x2b, 0x1f, 0x32, 0xfc, 0x6a, 0x21, 0x69, 0x4f, 0x9b, 0xc8, 0x7e, 0x42, 0x34,\r | |
451 | 0xfc, 0x36, 0x06, 0x17, 0x8b, 0x8f, 0x20, 0x40, 0xc0, 0xb3, 0x9a, 0x25, 0x75,\r | |
452 | 0x27, 0xcd, 0xc9, 0x03, 0xa3, 0xf6, 0x5d, 0xd1, 0xe7, 0x36, 0x54, 0x7a, 0xb9,\r | |
453 | 0x50, 0xb5, 0xd3, 0x12, 0xd1, 0x07, 0xbf, 0xbb, 0x74, 0xdf, 0xdc, 0x1e, 0x8f,\r | |
454 | 0x80, 0xd5, 0xed, 0x18, 0xf4, 0x2f, 0x14, 0x16, 0x6b, 0x2f, 0xde, 0x66, 0x8c,\r | |
455 | 0xb0, 0x23, 0xe5, 0xc7, 0x84, 0xd8, 0xed, 0xea, 0xc1, 0x33, 0x82, 0xad, 0x56,\r | |
456 | 0x4b, 0x18, 0x2d, 0xf1, 0x68, 0x95, 0x07, 0xcd, 0xcf, 0xf0, 0x72, 0xf0, 0xae,\r | |
457 | 0xbb, 0xdd, 0x86, 0x85, 0x98, 0x2c, 0x21, 0x4c, 0x33, 0x2b, 0xf0, 0x0f, 0x4a,\r | |
458 | 0xf0, 0x68, 0x87, 0xb5, 0x92, 0x55, 0x32, 0x75, 0xa1, 0x6a, 0x82, 0x6a, 0x3c,\r | |
459 | 0xa3, 0x25, 0x11, 0xa4, 0xed, 0xad, 0xd7, 0x04, 0xae, 0xcb, 0xd8, 0x40, 0x59,\r | |
460 | 0xa0, 0x84, 0xd1, 0x95, 0x4c, 0x62, 0x91, 0x22, 0x1a, 0x74, 0x1d, 0x8c, 0x3d,\r | |
461 | 0x47, 0x0e, 0x44, 0xa6, 0xe4, 0xb0, 0x9b, 0x34, 0x35, 0xb1, 0xfa, 0xb6, 0x53,\r | |
462 | 0xa8, 0x2c, 0x81, 0xec, 0xa4, 0x05, 0x71, 0xc8, 0x9d, 0xb8, 0xba, 0xe8, 0x1b,\r | |
463 | 0x44, 0x66, 0xe4, 0x47, 0x54, 0x0e, 0x8e, 0x56, 0x7f, 0xb3, 0x9f, 0x16, 0x98,\r | |
464 | 0xb2, 0x86, 0xd0, 0x68, 0x3e, 0x90, 0x23, 0xb5, 0x2f, 0x5e, 0x8f, 0x50, 0x85,\r | |
465 | 0x8d, 0xc6, 0x8d, 0x82, 0x5f, 0x41, 0xa1, 0xf4, 0x2e, 0x0d, 0xe0, 0x99, 0xd2,\r | |
466 | 0x6c, 0x75, 0xe4, 0xb6, 0x69, 0xb5, 0x21, 0x86, 0xfa, 0x07, 0xd1, 0xf6, 0xe2,\r | |
467 | 0x4d, 0xd1, 0xda, 0xad, 0x2c, 0x77, 0x53, 0x1e, 0x25, 0x32, 0x37, 0xc7, 0x6c,\r | |
468 | 0x52, 0x72, 0x95, 0x86, 0xb0, 0xf1, 0x35, 0x61, 0x6a, 0x19, 0xf5, 0xb2, 0x3b,\r | |
469 | 0x81, 0x50, 0x56, 0xa6, 0x32, 0x2d, 0xfe, 0xa2, 0x89, 0xf9, 0x42, 0x86, 0x27,\r | |
470 | 0x18, 0x55, 0xa1, 0x82, 0xca, 0x5a, 0x9b, 0xf8, 0x30, 0x98, 0x54, 0x14, 0xa6,\r | |
471 | 0x47, 0x96, 0x25, 0x2f, 0xc8, 0x26, 0xe4, 0x41, 0x94, 0x1a, 0x5c, 0x02, 0x3f,\r | |
472 | 0xe5, 0x96, 0xe3, 0x85, 0x5b, 0x3c, 0x3e, 0x3f, 0xbb, 0x47, 0x16, 0x72, 0x55,\r | |
473 | 0xe2, 0x25, 0x22, 0xb1, 0xd9, 0x7b, 0xe7, 0x03, 0x06, 0x2a, 0xa3, 0xf7, 0x1e,\r | |
474 | 0x90, 0x46, 0xc3, 0x00, 0x0d, 0xd6, 0x19, 0x89, 0xe3, 0x0e, 0x35, 0x27, 0x62,\r | |
475 | 0x03, 0x71, 0x15, 0xa6, 0xef, 0xd0, 0x27, 0xa0, 0xa0, 0x59, 0x37, 0x60, 0xf8,\r | |
476 | 0x38, 0x94, 0xb8, 0xe0, 0x78, 0x70, 0xf8, 0xba, 0x4c, 0x86, 0x87, 0x94, 0xf6,\r | |
477 | 0xe0, 0xae, 0x02, 0x45, 0xee, 0x65, 0xc2, 0xb6, 0xa3, 0x7e, 0x69, 0x16, 0x75,\r | |
478 | 0x07, 0x92, 0x9b, 0xf5, 0xa6, 0xbc, 0x59, 0x83, 0x58\r | |
479 | };\r | |
480 | \r | |
481 | //\r | |
482 | // The Microsoft.UefiSecureBootLogo.Tests.OutOfBoxConfirmDBXisPresent test case\r | |
483 | // of the Secure Boot Logo Test in the Microsoft Hardware Certification Kit\r | |
484 | // expects that the "dbx" variable exist.\r | |
485 | //\r | |
486 | // The article at <https://technet.microsoft.com/en-us/library/dn747883.aspx>\r | |
487 | // writes (excerpt):\r | |
488 | //\r | |
489 | // Windows 8.1 Secure Boot Key Creation and Management Guidance\r | |
490 | // 1. Secure Boot, Windows 8.1 and Key Management\r | |
491 | // 1.4 Signature Databases (Db and Dbx)\r | |
492 | // 1.4.3 Forbidden Signature Database (dbx)\r | |
493 | //\r | |
494 | // The contents of EFI_IMAGE_SIGNATURE_DATABASE1 dbx must be checked when\r | |
495 | // verifying images before checking db and any matches must prevent the\r | |
496 | // image from executing. The database may contain multiple certificates,\r | |
497 | // keys, and hashes in order to identify forbidden images. The Windows\r | |
498 | // Hardware Certification Requirements state that a dbx must be present, so\r | |
499 | // any dummy value, such as the SHA-256 hash of 0, may be used as a safe\r | |
500 | // placeholder until such time as Microsoft begins delivering dbx updates.\r | |
501 | //\r | |
502 | // The byte array below captures the SHA256 checksum of the empty file,\r | |
503 | // blacklisting it for loading & execution. This qualifies as a dummy, since\r | |
504 | // the empty file is not a valid UEFI binary anyway.\r | |
505 | //\r | |
506 | // Technically speaking, we could also capture an official (although soon to be\r | |
507 | // obsolete) dbx update from <http://www.uefi.org/revocationlistfile>. However,\r | |
508 | // the terms and conditions on distributing that binary aren't exactly light\r | |
509 | // reading, so let's best steer clear of it, and follow the "dummy entry"\r | |
510 | // practice recommended -- in natural English langauge -- in the\r | |
511 | // above-referenced TechNet article.\r | |
512 | //\r | |
513 | STATIC CONST UINT8 mSha256OfDevNull[] = {\r | |
514 | 0xe3, 0xb0, 0xc4, 0x42, 0x98, 0xfc, 0x1c, 0x14, 0x9a, 0xfb, 0xf4, 0xc8, 0x99,\r | |
515 | 0x6f, 0xb9, 0x24, 0x27, 0xae, 0x41, 0xe4, 0x64, 0x9b, 0x93, 0x4c, 0xa4, 0x95,\r | |
516 | 0x99, 0x1b, 0x78, 0x52, 0xb8, 0x55\r | |
517 | };\r | |
518 | \r | |
519 | //\r | |
520 | // The following test cases of the Secure Boot Logo Test in the Microsoft\r | |
521 | // Hardware Certification Kit:\r | |
522 | //\r | |
523 | // - Microsoft.UefiSecureBootLogo.Tests.OutOfBoxVerifyMicrosoftKEKpresent\r | |
524 | // - Microsoft.UefiSecureBootLogo.Tests.OutOfBoxConfirmMicrosoftSignatureInDB\r | |
525 | //\r | |
526 | // expect the EFI_SIGNATURE_DATA.SignatureOwner GUID to be\r | |
527 | // 77FA9ABD-0359-4D32-BD60-28F4E78F784B, when the\r | |
528 | // EFI_SIGNATURE_DATA.SignatureData field carries any of the following X509\r | |
529 | // certificates:\r | |
530 | //\r | |
531 | // - "Microsoft Corporation KEK CA 2011" (in KEK)\r | |
532 | // - "Microsoft Windows Production PCA 2011" (in db)\r | |
533 | // - "Microsoft Corporation UEFI CA 2011" (in db)\r | |
534 | //\r | |
535 | // This is despite the fact that the UEFI specification requires\r | |
536 | // EFI_SIGNATURE_DATA.SignatureOwner to reflect the agent (i.e., OS,\r | |
537 | // application or driver) that enrolled and therefore owns\r | |
538 | // EFI_SIGNATURE_DATA.SignatureData, and not the organization that issued\r | |
539 | // EFI_SIGNATURE_DATA.SignatureData.\r | |
540 | //\r | |
541 | STATIC CONST EFI_GUID mMicrosoftOwnerGuid = {\r | |
542 | 0x77fa9abd, 0x0359, 0x4d32,\r | |
543 | { 0xbd, 0x60, 0x28, 0xf4, 0xe7, 0x8f, 0x78, 0x4b },\r | |
544 | };\r | |
545 | \r | |
546 | //\r | |
547 | // The most important thing about the variable payload is that it is a list of\r | |
548 | // lists, where the element size of any given *inner* list is constant.\r | |
549 | //\r | |
550 | // Since X509 certificates vary in size, each of our *inner* lists will contain\r | |
551 | // one element only (one X.509 certificate). This is explicitly mentioned in\r | |
552 | // the UEFI specification, in "28.4.1 Signature Database", in a Note.\r | |
553 | //\r | |
554 | // The list structure looks as follows:\r | |
555 | //\r | |
556 | // struct EFI_VARIABLE_AUTHENTICATION_2 { |\r | |
557 | // struct EFI_TIME { |\r | |
558 | // UINT16 Year; |\r | |
559 | // UINT8 Month; |\r | |
560 | // UINT8 Day; |\r | |
561 | // UINT8 Hour; |\r | |
562 | // UINT8 Minute; |\r | |
563 | // UINT8 Second; |\r | |
564 | // UINT8 Pad1; |\r | |
565 | // UINT32 Nanosecond; |\r | |
566 | // INT16 TimeZone; |\r | |
567 | // UINT8 Daylight; |\r | |
568 | // UINT8 Pad2; |\r | |
569 | // } TimeStamp; |\r | |
570 | // |\r | |
571 | // struct WIN_CERTIFICATE_UEFI_GUID { | |\r | |
572 | // struct WIN_CERTIFICATE { | |\r | |
573 | // UINT32 dwLength; ----------------------------------------+ |\r | |
574 | // UINT16 wRevision; | |\r | |
575 | // UINT16 wCertificateType; | |\r | |
576 | // } Hdr; | +- DataSize\r | |
577 | // | |\r | |
578 | // EFI_GUID CertType; | |\r | |
579 | // UINT8 CertData[1] = { <--- "struct hack" | |\r | |
580 | // struct EFI_SIGNATURE_LIST { | | |\r | |
581 | // EFI_GUID SignatureType; | | |\r | |
582 | // UINT32 SignatureListSize; -------------------------+ | |\r | |
583 | // UINT32 SignatureHeaderSize; | | |\r | |
584 | // UINT32 SignatureSize; ---------------------------+ | | |\r | |
585 | // UINT8 SignatureHeader[SignatureHeaderSize]; | | | |\r | |
586 | // v | | |\r | |
587 | // struct EFI_SIGNATURE_DATA { | | | |\r | |
588 | // EFI_GUID SignatureOwner; | | | |\r | |
589 | // UINT8 SignatureData[1] = { <--- "struct hack" | | | |\r | |
590 | // X.509 payload | | | |\r | |
591 | // } | | | |\r | |
592 | // } Signatures[]; | | |\r | |
593 | // } SigLists[]; | |\r | |
594 | // }; | |\r | |
595 | // } AuthInfo; | |\r | |
596 | // }; |\r | |
597 | //\r | |
598 | // Given that the "struct hack" invokes undefined behavior (which is why C99\r | |
599 | // introduced the flexible array member), and because subtracting those pesky\r | |
600 | // sizes of 1 is annoying, and because the format is fully specified in the\r | |
601 | // UEFI specification, we'll introduce two matching convenience structures that\r | |
602 | // are customized for our X.509 purposes.\r | |
603 | //\r | |
85d96998 | 604 | #pragma pack (1)\r |
b1163623 LE |
605 | typedef struct {\r |
606 | EFI_TIME TimeStamp;\r | |
607 | \r | |
608 | //\r | |
609 | // dwLength covers data below\r | |
610 | //\r | |
611 | UINT32 dwLength;\r | |
612 | UINT16 wRevision;\r | |
613 | UINT16 wCertificateType;\r | |
614 | EFI_GUID CertType;\r | |
615 | } SINGLE_HEADER;\r | |
616 | \r | |
617 | typedef struct {\r | |
618 | //\r | |
619 | // SignatureListSize covers data below\r | |
620 | //\r | |
621 | EFI_GUID SignatureType;\r | |
622 | UINT32 SignatureListSize;\r | |
623 | UINT32 SignatureHeaderSize; // constant 0\r | |
624 | UINT32 SignatureSize;\r | |
625 | \r | |
626 | //\r | |
627 | // SignatureSize covers data below\r | |
628 | //\r | |
629 | EFI_GUID SignatureOwner;\r | |
630 | \r | |
631 | //\r | |
632 | // X.509 certificate follows\r | |
633 | //\r | |
634 | } REPEATING_HEADER;\r | |
85d96998 | 635 | #pragma pack ()\r |
b1163623 LE |
636 | \r |
637 | /**\r | |
638 | Enroll a set of certificates in a global variable, overwriting it.\r | |
639 | \r | |
640 | The variable will be rewritten with NV+BS+RT+AT attributes.\r | |
641 | \r | |
642 | @param[in] VariableName The name of the variable to overwrite.\r | |
643 | \r | |
644 | @param[in] VendorGuid The namespace (ie. vendor GUID) of the variable to\r | |
645 | overwrite.\r | |
646 | \r | |
647 | @param[in] CertType The GUID determining the type of all the\r | |
648 | certificates in the set that is passed in. For\r | |
649 | example, gEfiCertX509Guid stands for DER-encoded\r | |
650 | X.509 certificates, while gEfiCertSha256Guid stands\r | |
651 | for SHA256 image hashes.\r | |
652 | \r | |
653 | @param[in] ... A list of\r | |
654 | \r | |
655 | IN CONST UINT8 *Cert,\r | |
656 | IN UINTN CertSize,\r | |
657 | IN CONST EFI_GUID *OwnerGuid\r | |
658 | \r | |
659 | triplets. If the first component of a triplet is\r | |
660 | NULL, then the other two components are not\r | |
661 | accessed, and processing is terminated. The list of\r | |
662 | certificates is enrolled in the variable specified,\r | |
663 | overwriting it. The OwnerGuid component identifies\r | |
664 | the agent installing the certificate.\r | |
665 | \r | |
666 | @retval EFI_INVALID_PARAMETER The triplet list is empty (ie. the first Cert\r | |
667 | value is NULL), or one of the CertSize values\r | |
668 | is 0, or one of the CertSize values would\r | |
669 | overflow the accumulated UINT32 data size.\r | |
670 | \r | |
671 | @retval EFI_OUT_OF_RESOURCES Out of memory while formatting variable\r | |
672 | payload.\r | |
673 | \r | |
674 | @retval EFI_SUCCESS Enrollment successful; the variable has been\r | |
675 | overwritten (or created).\r | |
676 | \r | |
677 | @return Error codes from gRT->GetTime() and\r | |
678 | gRT->SetVariable().\r | |
679 | **/\r | |
680 | STATIC\r | |
681 | EFI_STATUS\r | |
682 | EFIAPI\r | |
683 | EnrollListOfCerts (\r | |
684 | IN CHAR16 *VariableName,\r | |
685 | IN EFI_GUID *VendorGuid,\r | |
686 | IN EFI_GUID *CertType,\r | |
687 | ...\r | |
688 | )\r | |
689 | {\r | |
690 | UINTN DataSize;\r | |
691 | SINGLE_HEADER *SingleHeader;\r | |
692 | REPEATING_HEADER *RepeatingHeader;\r | |
693 | VA_LIST Marker;\r | |
694 | CONST UINT8 *Cert;\r | |
695 | EFI_STATUS Status;\r | |
696 | UINT8 *Data;\r | |
697 | UINT8 *Position;\r | |
698 | \r | |
699 | Status = EFI_SUCCESS;\r | |
700 | \r | |
701 | //\r | |
702 | // compute total size first, for UINT32 range check, and allocation\r | |
703 | //\r | |
704 | DataSize = sizeof *SingleHeader;\r | |
705 | VA_START (Marker, CertType);\r | |
706 | for (Cert = VA_ARG (Marker, CONST UINT8 *);\r | |
707 | Cert != NULL;\r | |
708 | Cert = VA_ARG (Marker, CONST UINT8 *)) {\r | |
709 | UINTN CertSize;\r | |
710 | \r | |
711 | CertSize = VA_ARG (Marker, UINTN);\r | |
712 | (VOID)VA_ARG (Marker, CONST EFI_GUID *);\r | |
713 | \r | |
714 | if (CertSize == 0 ||\r | |
715 | CertSize > MAX_UINT32 - sizeof *RepeatingHeader ||\r | |
716 | DataSize > MAX_UINT32 - sizeof *RepeatingHeader - CertSize) {\r | |
717 | Status = EFI_INVALID_PARAMETER;\r | |
718 | break;\r | |
719 | }\r | |
720 | DataSize += sizeof *RepeatingHeader + CertSize;\r | |
721 | }\r | |
722 | VA_END (Marker);\r | |
723 | \r | |
724 | if (DataSize == sizeof *SingleHeader) {\r | |
725 | Status = EFI_INVALID_PARAMETER;\r | |
726 | }\r | |
727 | if (EFI_ERROR (Status)) {\r | |
728 | goto Out;\r | |
729 | }\r | |
730 | \r | |
731 | Data = AllocatePool (DataSize);\r | |
732 | if (Data == NULL) {\r | |
733 | Status = EFI_OUT_OF_RESOURCES;\r | |
734 | goto Out;\r | |
735 | }\r | |
736 | \r | |
737 | Position = Data;\r | |
738 | \r | |
739 | SingleHeader = (SINGLE_HEADER *)Position;\r | |
740 | Status = gRT->GetTime (&SingleHeader->TimeStamp, NULL);\r | |
741 | if (EFI_ERROR (Status)) {\r | |
742 | goto FreeData;\r | |
743 | }\r | |
744 | SingleHeader->TimeStamp.Pad1 = 0;\r | |
745 | SingleHeader->TimeStamp.Nanosecond = 0;\r | |
746 | SingleHeader->TimeStamp.TimeZone = 0;\r | |
747 | SingleHeader->TimeStamp.Daylight = 0;\r | |
748 | SingleHeader->TimeStamp.Pad2 = 0;\r | |
749 | #if 0\r | |
750 | SingleHeader->dwLength = DataSize - sizeof SingleHeader->TimeStamp;\r | |
751 | #else\r | |
752 | //\r | |
753 | // This looks like a bug in edk2. According to the UEFI specification,\r | |
754 | // dwLength is "The length of the entire certificate, including the length of\r | |
755 | // the header, in bytes". That shouldn't stop right after CertType -- it\r | |
756 | // should include everything below it.\r | |
757 | //\r | |
758 | SingleHeader->dwLength = sizeof *SingleHeader\r | |
759 | - sizeof SingleHeader->TimeStamp;\r | |
760 | #endif\r | |
761 | SingleHeader->wRevision = 0x0200;\r | |
762 | SingleHeader->wCertificateType = WIN_CERT_TYPE_EFI_GUID;\r | |
763 | CopyGuid (&SingleHeader->CertType, &gEfiCertPkcs7Guid);\r | |
764 | Position += sizeof *SingleHeader;\r | |
765 | \r | |
766 | VA_START (Marker, CertType);\r | |
767 | for (Cert = VA_ARG (Marker, CONST UINT8 *);\r | |
768 | Cert != NULL;\r | |
769 | Cert = VA_ARG (Marker, CONST UINT8 *)) {\r | |
770 | UINTN CertSize;\r | |
771 | CONST EFI_GUID *OwnerGuid;\r | |
772 | \r | |
773 | CertSize = VA_ARG (Marker, UINTN);\r | |
774 | OwnerGuid = VA_ARG (Marker, CONST EFI_GUID *);\r | |
775 | \r | |
776 | RepeatingHeader = (REPEATING_HEADER *)Position;\r | |
777 | CopyGuid (&RepeatingHeader->SignatureType, CertType);\r | |
778 | RepeatingHeader->SignatureListSize =\r | |
779 | (UINT32)(sizeof *RepeatingHeader + CertSize);\r | |
780 | RepeatingHeader->SignatureHeaderSize = 0;\r | |
781 | RepeatingHeader->SignatureSize =\r | |
782 | (UINT32)(sizeof RepeatingHeader->SignatureOwner + CertSize);\r | |
783 | CopyGuid (&RepeatingHeader->SignatureOwner, OwnerGuid);\r | |
784 | Position += sizeof *RepeatingHeader;\r | |
785 | \r | |
786 | CopyMem (Position, Cert, CertSize);\r | |
787 | Position += CertSize;\r | |
788 | }\r | |
789 | VA_END (Marker);\r | |
790 | \r | |
791 | ASSERT (Data + DataSize == Position);\r | |
792 | \r | |
793 | Status = gRT->SetVariable (VariableName, VendorGuid,\r | |
794 | (EFI_VARIABLE_NON_VOLATILE |\r | |
795 | EFI_VARIABLE_BOOTSERVICE_ACCESS |\r | |
796 | EFI_VARIABLE_RUNTIME_ACCESS |\r | |
797 | EFI_VARIABLE_TIME_BASED_AUTHENTICATED_WRITE_ACCESS),\r | |
798 | DataSize, Data);\r | |
799 | \r | |
800 | FreeData:\r | |
801 | FreePool (Data);\r | |
802 | \r | |
803 | Out:\r | |
804 | if (EFI_ERROR (Status)) {\r | |
805 | AsciiPrint ("error: %a(\"%s\", %g): %r\n", __FUNCTION__, VariableName,\r | |
806 | VendorGuid, Status);\r | |
807 | }\r | |
808 | return Status;\r | |
809 | }\r | |
810 | \r | |
811 | \r | |
812 | STATIC\r | |
813 | EFI_STATUS\r | |
814 | EFIAPI\r | |
815 | GetExact (\r | |
816 | IN CHAR16 *VariableName,\r | |
817 | IN EFI_GUID *VendorGuid,\r | |
818 | OUT VOID *Data,\r | |
819 | IN UINTN DataSize,\r | |
820 | IN BOOLEAN AllowMissing\r | |
821 | )\r | |
822 | {\r | |
823 | UINTN Size;\r | |
824 | EFI_STATUS Status;\r | |
825 | \r | |
826 | Size = DataSize;\r | |
827 | Status = gRT->GetVariable (VariableName, VendorGuid, NULL, &Size, Data);\r | |
828 | if (EFI_ERROR (Status)) {\r | |
829 | if (Status == EFI_NOT_FOUND && AllowMissing) {\r | |
830 | ZeroMem (Data, DataSize);\r | |
831 | return EFI_SUCCESS;\r | |
832 | }\r | |
833 | \r | |
834 | AsciiPrint ("error: GetVariable(\"%s\", %g): %r\n", VariableName,\r | |
835 | VendorGuid, Status);\r | |
836 | return Status;\r | |
837 | }\r | |
838 | \r | |
839 | if (Size != DataSize) {\r | |
840 | AsciiPrint ("error: GetVariable(\"%s\", %g): expected size 0x%Lx, "\r | |
841 | "got 0x%Lx\n", VariableName, VendorGuid, (UINT64)DataSize, (UINT64)Size);\r | |
842 | return EFI_PROTOCOL_ERROR;\r | |
843 | }\r | |
844 | \r | |
845 | return EFI_SUCCESS;\r | |
846 | }\r | |
847 | \r | |
848 | typedef struct {\r | |
849 | UINT8 SetupMode;\r | |
850 | UINT8 SecureBoot;\r | |
851 | UINT8 SecureBootEnable;\r | |
852 | UINT8 CustomMode;\r | |
853 | UINT8 VendorKeys;\r | |
854 | } SETTINGS;\r | |
855 | \r | |
856 | STATIC\r | |
857 | EFI_STATUS\r | |
858 | EFIAPI\r | |
859 | GetSettings (\r | |
860 | OUT SETTINGS *Settings\r | |
861 | )\r | |
862 | {\r | |
863 | EFI_STATUS Status;\r | |
864 | \r | |
865 | Status = GetExact (EFI_SETUP_MODE_NAME, &gEfiGlobalVariableGuid,\r | |
866 | &Settings->SetupMode, sizeof Settings->SetupMode, FALSE);\r | |
867 | if (EFI_ERROR (Status)) {\r | |
868 | return Status;\r | |
869 | }\r | |
870 | \r | |
871 | Status = GetExact (EFI_SECURE_BOOT_MODE_NAME, &gEfiGlobalVariableGuid,\r | |
872 | &Settings->SecureBoot, sizeof Settings->SecureBoot, FALSE);\r | |
873 | if (EFI_ERROR (Status)) {\r | |
874 | return Status;\r | |
875 | }\r | |
876 | \r | |
877 | Status = GetExact (EFI_SECURE_BOOT_ENABLE_NAME,\r | |
878 | &gEfiSecureBootEnableDisableGuid, &Settings->SecureBootEnable,\r | |
879 | sizeof Settings->SecureBootEnable, TRUE);\r | |
880 | if (EFI_ERROR (Status)) {\r | |
881 | return Status;\r | |
882 | }\r | |
883 | \r | |
884 | Status = GetExact (EFI_CUSTOM_MODE_NAME, &gEfiCustomModeEnableGuid,\r | |
885 | &Settings->CustomMode, sizeof Settings->CustomMode, FALSE);\r | |
886 | if (EFI_ERROR (Status)) {\r | |
887 | return Status;\r | |
888 | }\r | |
889 | \r | |
890 | Status = GetExact (EFI_VENDOR_KEYS_VARIABLE_NAME, &gEfiGlobalVariableGuid,\r | |
891 | &Settings->VendorKeys, sizeof Settings->VendorKeys, FALSE);\r | |
892 | return Status;\r | |
893 | }\r | |
894 | \r | |
895 | STATIC\r | |
896 | VOID\r | |
897 | EFIAPI\r | |
898 | PrintSettings (\r | |
899 | IN CONST SETTINGS *Settings\r | |
900 | )\r | |
901 | {\r | |
902 | AsciiPrint ("info: SetupMode=%d SecureBoot=%d SecureBootEnable=%d "\r | |
903 | "CustomMode=%d VendorKeys=%d\n", Settings->SetupMode, Settings->SecureBoot,\r | |
904 | Settings->SecureBootEnable, Settings->CustomMode, Settings->VendorKeys);\r | |
905 | }\r | |
906 | \r | |
907 | \r | |
908 | INTN\r | |
909 | EFIAPI\r | |
910 | ShellAppMain (\r | |
911 | IN UINTN Argc,\r | |
912 | IN CHAR16 **Argv\r | |
913 | )\r | |
914 | {\r | |
915 | EFI_STATUS Status;\r | |
916 | SETTINGS Settings;\r | |
917 | \r | |
918 | Status = GetSettings (&Settings);\r | |
919 | if (EFI_ERROR (Status)) {\r | |
920 | return 1;\r | |
921 | }\r | |
922 | PrintSettings (&Settings);\r | |
923 | \r | |
924 | if (Settings.SetupMode != 1) {\r | |
925 | AsciiPrint ("error: already in User Mode\n");\r | |
926 | return 1;\r | |
927 | }\r | |
928 | \r | |
929 | if (Settings.CustomMode != CUSTOM_SECURE_BOOT_MODE) {\r | |
930 | Settings.CustomMode = CUSTOM_SECURE_BOOT_MODE;\r | |
931 | Status = gRT->SetVariable (EFI_CUSTOM_MODE_NAME, &gEfiCustomModeEnableGuid,\r | |
932 | (EFI_VARIABLE_NON_VOLATILE |\r | |
933 | EFI_VARIABLE_BOOTSERVICE_ACCESS),\r | |
934 | sizeof Settings.CustomMode, &Settings.CustomMode);\r | |
935 | if (EFI_ERROR (Status)) {\r | |
936 | AsciiPrint ("error: SetVariable(\"%s\", %g): %r\n", EFI_CUSTOM_MODE_NAME,\r | |
937 | &gEfiCustomModeEnableGuid, Status);\r | |
938 | return 1;\r | |
939 | }\r | |
940 | }\r | |
941 | \r | |
942 | Status = EnrollListOfCerts (\r | |
943 | EFI_IMAGE_SECURITY_DATABASE,\r | |
944 | &gEfiImageSecurityDatabaseGuid,\r | |
945 | &gEfiCertX509Guid,\r | |
32d1440a LE |
946 | mMicrosoftPCA, sizeof mMicrosoftPCA, &mMicrosoftOwnerGuid,\r |
947 | mMicrosoftUefiCA, sizeof mMicrosoftUefiCA, &mMicrosoftOwnerGuid,\r | |
b1163623 LE |
948 | NULL);\r |
949 | if (EFI_ERROR (Status)) {\r | |
950 | return 1;\r | |
951 | }\r | |
952 | \r | |
953 | Status = EnrollListOfCerts (\r | |
954 | EFI_IMAGE_SECURITY_DATABASE1,\r | |
955 | &gEfiImageSecurityDatabaseGuid,\r | |
956 | &gEfiCertSha256Guid,\r | |
957 | mSha256OfDevNull, sizeof mSha256OfDevNull, &gEfiCallerIdGuid,\r | |
958 | NULL);\r | |
959 | if (EFI_ERROR (Status)) {\r | |
960 | return 1;\r | |
961 | }\r | |
962 | \r | |
963 | Status = EnrollListOfCerts (\r | |
964 | EFI_KEY_EXCHANGE_KEY_NAME,\r | |
965 | &gEfiGlobalVariableGuid,\r | |
966 | &gEfiCertX509Guid,\r | |
32d1440a LE |
967 | mRedHatPkKek1, sizeof mRedHatPkKek1, &gEfiCallerIdGuid,\r |
968 | mMicrosoftKEK, sizeof mMicrosoftKEK, &mMicrosoftOwnerGuid,\r | |
b1163623 LE |
969 | NULL);\r |
970 | if (EFI_ERROR (Status)) {\r | |
971 | return 1;\r | |
972 | }\r | |
973 | \r | |
974 | Status = EnrollListOfCerts (\r | |
975 | EFI_PLATFORM_KEY_NAME,\r | |
976 | &gEfiGlobalVariableGuid,\r | |
977 | &gEfiCertX509Guid,\r | |
32d1440a | 978 | mRedHatPkKek1, sizeof mRedHatPkKek1, &gEfiGlobalVariableGuid,\r |
b1163623 LE |
979 | NULL);\r |
980 | if (EFI_ERROR (Status)) {\r | |
981 | return 1;\r | |
982 | }\r | |
983 | \r | |
984 | Settings.CustomMode = STANDARD_SECURE_BOOT_MODE;\r | |
985 | Status = gRT->SetVariable (EFI_CUSTOM_MODE_NAME, &gEfiCustomModeEnableGuid,\r | |
986 | EFI_VARIABLE_NON_VOLATILE | EFI_VARIABLE_BOOTSERVICE_ACCESS,\r | |
987 | sizeof Settings.CustomMode, &Settings.CustomMode);\r | |
988 | if (EFI_ERROR (Status)) {\r | |
989 | AsciiPrint ("error: SetVariable(\"%s\", %g): %r\n", EFI_CUSTOM_MODE_NAME,\r | |
990 | &gEfiCustomModeEnableGuid, Status);\r | |
991 | return 1;\r | |
992 | }\r | |
993 | \r | |
994 | Status = GetSettings (&Settings);\r | |
995 | if (EFI_ERROR (Status)) {\r | |
996 | return 1;\r | |
997 | }\r | |
998 | PrintSettings (&Settings);\r | |
999 | \r | |
1000 | if (Settings.SetupMode != 0 || Settings.SecureBoot != 1 ||\r | |
1001 | Settings.SecureBootEnable != 1 || Settings.CustomMode != 0 ||\r | |
1002 | Settings.VendorKeys != 0) {\r | |
1003 | AsciiPrint ("error: unexpected\n");\r | |
1004 | return 1;\r | |
1005 | }\r | |
1006 | \r | |
1007 | AsciiPrint ("info: success\n");\r | |
1008 | return 0;\r | |
1009 | }\r |