Standalone backup agents for Linux, Mac, AIX & Solaris workloads on-premises or in the public cloud
Post Reply
mike2307
Novice
Posts: 9
Liked: 2 times
Joined: Mar 26, 2019 10:42 am
Contact:

UEFI Secure boot on Fedora

Post by mike2307 »

Hi all,

in the User Guide for the latest version of the Veeam Agent for Linux is written:
To make UEFI systems with Secure Boot work with the pre-built veeamsnap kernel module, you need to enroll the Veeam public key to the MOK list using the mokutil utility...
Well, how about the automatically build veeamsnap kernel module on Fedora?
Is there any chance to have UEFI Secure boot enabled with the veeamsnap kernel module working?

Thanks in advance.

Kind regards,
Michael
PTide
Product Manager
Posts: 6408
Liked: 724 times
Joined: May 19, 2015 1:46 pm
Contact:

Re: UEFI Secure boot on Fedora

Post by PTide »

Hi,

Every time you rebuild the module you need to sign it with a private key again. As you can imagine, since you are rebuilding the module on your machine, you need to sign it there too : )

Thanks!
mike2307
Novice
Posts: 9
Liked: 2 times
Joined: Mar 26, 2019 10:42 am
Contact:

Re: UEFI Secure boot on Fedora

Post by mike2307 »

Thanks for the quick reply.

Whenever a new kernel is getting installed, dkms automatically takes the sources from e.g. /usr/src/veeamsnap-3.0.1.1046/ and compiles and installs the module.
Is there something like a "hook", that can be triggered to automatically sign the module?

Even if I would install e.g. http://repository.veeam.com/backup/linu ... noarch.rpm, it won't help as I of course don't have the private key to sign the module.
Is there a way how I can create my own public/private key pair for signing the module?

I'm rather unfamiliar with that topic. Can you recommend a guide where signing modules and importing keys is explained?

Kind regards,
Michael
PTide
Product Manager
Posts: 6408
Liked: 724 times
Joined: May 19, 2015 1:46 pm
Contact:

Re: UEFI Secure boot on Fedora

Post by PTide » 1 person likes this post

Here is the guide explaining how to sign things on Fedora: link

Here is a wrapper that can help with signing: link

Thanks!
mike2307
Novice
Posts: 9
Liked: 2 times
Joined: Mar 26, 2019 10:42 am
Contact:

Re: UEFI Secure boot on Fedora

Post by mike2307 » 1 person likes this post

Thank you very much for the links. I finally got it working. :-)

But there are many pitfalls...
I list them here to save someone else's time in case they stumble across this post.

Users of Fedora 29 need to be aware of this bug: https://bugzilla.redhat.com/show_bug.cgi?id=1701096
Users of Fedora (any version I guess) need to be aware of this bug: https://bugzilla.redhat.com/show_bug.cgi?id=1704698
Users of HP Notebooks need to be aware of this bug: https://github.com/rhboot/shim/issues/105
Post Reply

Who is online

Users browsing this forum: Baidu [Spider] and 9 guests