On Mon, May 31, 2021 at 08:10:25PM +0200, Heinrich Schuchardt wrote: ..
We have in the EBBR a chapter "UEFI Secure Boot (Optional)". If we have bugs in authenticated EFI variables, we may not have secure boot.
What does the SystemReady IR certification require concerning secure boot?
Hi Heinrich,
You are right: secure boot is optional in EBBR and for SystemReady IR. This will be required in the future by the SystemReady Security option.
For the SystemReady IR certification, the requirements are described in the SRS[1]. They boil down to:
- BSA (for 64b) - EBBR - Devicetree
Testing is done with the ACS[2] (SCT + FWTS + Bsa) and 2x OS install.
Best regards,
Vincent Stehlé System Architect - Arm
[1]: https://developer.arm.com/documentation/den0109/latest [2]: https://github.com/ARM-software/arm-systemready/tree/main/IR