Bug 2233526
| Summary: | UEFI + Secure Boot: Cannot boot Restore entry when backup is created on USB key | ||
|---|---|---|---|
| Product: | Red Hat Enterprise Linux 8 | Reporter: | Pavel Cahyna <pcahyna> |
| Component: | rear | Assignee: | Pavel Cahyna <pcahyna> |
| Status: | CLOSED ERRATA | QA Contact: | Jakub Haruda <jharuda> |
| Severity: | high | Docs Contact: | Šárka Jana <sjanderk> |
| Priority: | high | ||
| Version: | 8.8 | CC: | bwelterl, jharuda, ovasik, pcahyna, rmetrich, sjanderk |
| Target Milestone: | rc | Keywords: | Triaged |
| Target Release: | --- | Flags: | pm-rhel:
mirror+
|
| Hardware: | x86_64 | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | rear-2.6-10.el8 | Doc Type: | Bug Fix |
| Doc Text: |
.ReaR now supports UEFI Secure Boot with `OUTPUT=USB`
Previously, the `OUTPUT=USB` ReaR output method, which stores the rescue image on a bootable disk drive, did not respect the `SECURE_BOOT_BOOTLOADER` setting. Consequently, on systems with UEFI Secure Boot enabled, the disk with the rescue image would not boot because the bootloader was not signed.
With this fix, the `OUTPUT=USB` ReaR output method now uses the bootloader that you specify in the `SECURE_BOOT_BOOTLOADER` setting when creating the rescue disk. To use the signed UEFI shim bootloader, change the following setting in the `/etc/rear/local.conf` file:
----
SECURE_BOOT_BOOTLOADER=/boot/efi/EFI/redhat/shimx64.efi
----
As a result, the rescue disk is bootable when UEFI Secure Boot is enabled. It is safe to set the variable to this value on all systems with UEFI, even when Secure Boot is not enabled. It is even recommended for consistency. For details about the UEFI boot procedure and the shim bootloader, see link:https://access.redhat.com/articles/6645591[UEFI: what happens when booting the system].
|
Story Points: | --- |
| Clone Of: | 2196445 | Environment: | |
| Last Closed: | 2023-11-14 15:37:10 UTC | Type: | Bug |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2196445 | ||
| Bug Blocks: | |||
|
Description
Pavel Cahyna
2023-08-22 12:24:39 UTC
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory (rear bug fix and enhancement update), and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHBA-2023:7060 The needinfo request[s] on this closed bug have been removed as they have been unresolved for 120 days |