Hi Laszlo, Chao,<br /><br />Sorry for late response in this thread.<br /><br />I review Mantis#1983 and this discussion again. I agree with Laszlo. <br /> 1. UEFI spec 2.8 is not very clear about PK validation in Setup mode.<br /> 2. This patch only reduce the complexity of update PK process.<br /><br />Having a FeaturePCD to control this kind of behavior in EDK2 is weird. That only make things more complicated to me.<br />To simplify and make things clear, updating PK shall always be signed in both Setup Mode and User Mode. <br /><br />Anyway, I agree with Laszlo and I'm good with current implementation now.
<div width="1" style="color:white;clear:both">_._,_._,_</div>
<hr>
Groups.io Links:<p>
You receive all messages sent to this group.
<p>
<a target="_blank" href="https://edk2.groups.io/g/devel/message/46251">View/Reply Online (#46251)</a> |
|
<a target="_blank" href="https://groups.io/mt/32283314/1813853">Mute This Topic</a>
| <a href="https://edk2.groups.io/g/devel/post">New Topic</a><br>
<br>
<a href="https://edk2.groups.io/g/devel/editsub/1813853">Your Subscription</a> |
<a href="mailto:devel+owner@edk2.groups.io">Contact Group Owner</a> |
<a href="https://edk2.groups.io/g/devel/unsub">Unsubscribe</a>
[edk2-devel-archive@redhat.com]<br>
<div width="1" style="color:white;clear:both">_._,_._,_</div>