Bug 1877343

Summary: mokutil needs to be updated to retrieve th secure boot key from the kernel
Product: Red Hat Enterprise Linux 8 Reporter: Dave Young <ruyang>
Component: mokutilAssignee: Javier Martinez Canillas <fmartine>
Status: CLOSED ERRATA QA Contact: Erico Nunes <ernunes>
Severity: urgent Docs Contact:
Priority: urgent    
Version: 8.3CC: ajb, blc, bootloader-eng-team, cww, cye, dhoward, dyoung, emcnabb, ernunes, fmartine, jdonohue, jkucera, jwboyer, kasong, kernel-qe-hw, kwalker, ldu, lilu, lmiksik, lszubowi, manuel.wolfshant, pasteur, peter, phil, pholica, pjanda, pjones, pkotvan, ptalbert, qzhao, release-test-team-automation, rmetrich, ruyang, rvr, sbroz, toracat, twaugh, xiawu, xuli, yacao, zguo, zsun
Target Milestone: rcKeywords: OtherQA, Regression, ZStream
Target Release: 8.0   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: mokutil-0.3.0-10.el8 Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: 1868820
: 1900044 1907418 (view as bug list) Environment:
Last Closed: 2020-11-04 02:18:40 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1868306    
Bug Blocks: 1900044, 1907418    
Attachments:
Description Flags
mokutil-0.3.0-10.el8.x86_64.rpm none

Comment 7 Javier Martinez Canillas 2020-09-22 10:38:20 UTC
Created attachment 1715679 [details]
mokutil-0.3.0-10.el8.x86_64.rpm

Comment 8 Renaud Métrich 2020-09-22 11:31:42 UTC
I confirm the new mokutil works assuming a recent kernel (I used kernel-core-4.18.0-239.el8.x86_64 is installed).

- With kernel-core-4.18.0-239.el8.x86_64 but mokutil-0.3.0-9.el8.x86_64:

  # mokutil --list-enrolled
  MokListRT is empty
  #

- With kernel-core-4.18.0-239.el8.x86_64 and mokutil-0.3.0-10.el8.x86_64:

  # mokutil --list-enrolled
  [key 1]
  ...
  #

- With kernel-4.18.0-193.19.1.el8_2.x86_64 and mokutil-0.3.0-10.el8.x86_64:

  # mokutil --list-enrolled
  #

  --> no output at all

Comment 9 Javier Martinez Canillas 2020-09-23 06:52:03 UTC
*** Bug 1866107 has been marked as a duplicate of this bug. ***

Comment 10 Renaud Métrich 2020-09-23 12:55:35 UTC
Making the bz public

Comment 18 errata-xmlrpc 2020-11-04 02:18:40 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory (mokutil bug fix and enhancement update), and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHBA-2020:4604