From c4084a6419fc33cf7a178ae930fcc75ec9417141 Mon Sep 17 00:00:00 2001 From: Mounir IDRASSI Date: Sat, 1 Sep 2018 19:01:41 +0200 Subject: Add support for new Intel certificate in SecureBoot powershell script --- SecureBoot/certs/Intel_CISD_FW_Update_2017-08-30.crt | Bin 0 -> 840 bytes SecureBoot/sb_set_siglists.ps1 | 5 +++++ .../siglists/Intel_CISD_FW_Update_2017-08-30_SigList.bin | Bin 0 -> 868 bytes ...l_CISD_FW_Update_2017-08-30_SigList_Serialization.bin | Bin 0 -> 908 bytes ...ISD_FW_Update_2017-08-30_SigList_Serialization.bin.p7 | Bin 0 -> 1492 bytes 5 files changed, 5 insertions(+) create mode 100644 SecureBoot/certs/Intel_CISD_FW_Update_2017-08-30.crt create mode 100644 SecureBoot/siglists/Intel_CISD_FW_Update_2017-08-30_SigList.bin create mode 100644 SecureBoot/siglists/Intel_CISD_FW_Update_2017-08-30_SigList_Serialization.bin create mode 100644 SecureBoot/siglists/Intel_CISD_FW_Update_2017-08-30_SigList_Serialization.bin.p7 (limited to 'SecureBoot') diff --git a/SecureBoot/certs/Intel_CISD_FW_Update_2017-08-30.crt b/SecureBoot/certs/Intel_CISD_FW_Update_2017-08-30.crt new file mode 100644 index 0000000..020b6f9 Binary files /dev/null and b/SecureBoot/certs/Intel_CISD_FW_Update_2017-08-30.crt differ diff --git a/SecureBoot/sb_set_siglists.ps1 b/SecureBoot/sb_set_siglists.ps1 index 6e6f501..cf735cb 100644 --- a/SecureBoot/sb_set_siglists.ps1 +++ b/SecureBoot/sb_set_siglists.ps1 @@ -57,6 +57,11 @@ Set-SecureBootUEFI -Time 2018-07-05T00:00:00Z -ContentFilePath $scriptPath\sigli # Set-SecureBootUEFI -Time 2018-07-05T00:00:00Z -ContentFilePath $scriptPath\siglists\HP_UEFI_Secure_Boot_2013_DB_key_2013_08_23_SigList.bin -SignedFilePath $scriptPath\siglists\HP_UEFI_Secure_Boot_2013_DB_key_2013_08_23_SigList_Serialization.bin.p7 -Name db -AppendWrite:$true # Set-SecureBootUEFI -Time 2018-07-05T00:00:00Z -ContentFilePath $scriptPath\siglists\HP_UEFI_Secure_Boot_DB_2017_2017-01-20_SigList.bin -SignedFilePath $scriptPath\siglists\HP_UEFI_Secure_Boot_DB_2017_2017-01-20_SigList_Serialization.bin.p7 -Name db -AppendWrite:$true +############### Intel ############### +# Write-Host "Setting KEK-signed Intel cert in db..." +# Set-SecureBootUEFI -Time 2018-07-05T00:00:00Z -ContentFilePath $scriptPath\siglists\Intel_CISD_FW_Update_2017-08-30_SigList.bin -SignedFilePath $scriptPath\siglists\Intel_CISD_FW_Update_2017-08-30_SigList_Serialization.bin.p7 -Name db -AppendWrite:$true + + ############### Lenovo ############### # Write-Host "Setting KEK-signed Lenovo certs in db..." # Set-SecureBootUEFI -Time 2018-07-05T00:00:00Z -ContentFilePath $scriptPath\siglists\Lenovo_1T110-1415ISK-2016-02-17_SigList.bin -SignedFilePath $scriptPath\siglists\Lenovo_1T110-1415ISK-2016-02-17_SigList_Serialization.bin.p7 -Name db -AppendWrite:$true diff --git a/SecureBoot/siglists/Intel_CISD_FW_Update_2017-08-30_SigList.bin b/SecureBoot/siglists/Intel_CISD_FW_Update_2017-08-30_SigList.bin new file mode 100644 index 0000000..426dec3 Binary files /dev/null and b/SecureBoot/siglists/Intel_CISD_FW_Update_2017-08-30_SigList.bin differ diff --git a/SecureBoot/siglists/Intel_CISD_FW_Update_2017-08-30_SigList_Serialization.bin b/SecureBoot/siglists/Intel_CISD_FW_Update_2017-08-30_SigList_Serialization.bin new file mode 100644 index 0000000..3ca95db Binary files /dev/null and b/SecureBoot/siglists/Intel_CISD_FW_Update_2017-08-30_SigList_Serialization.bin differ diff --git a/SecureBoot/siglists/Intel_CISD_FW_Update_2017-08-30_SigList_Serialization.bin.p7 b/SecureBoot/siglists/Intel_CISD_FW_Update_2017-08-30_SigList_Serialization.bin.p7 new file mode 100644 index 0000000..80b2c69 Binary files /dev/null and b/SecureBoot/siglists/Intel_CISD_FW_Update_2017-08-30_SigList_Serialization.bin.p7 differ -- cgit v1.2.3