Skip to content

Conversation

@lethedata
Copy link

@lethedata lethedata commented Feb 2, 2023

Fixes #1076 and closes heads-wiki#102

Code is from linuxboot/heads-wiki#102 (comment) but instead of making a function and call, it's incorporated into the gpg_key_reset function after the Nitrokey AES key reset.

To-Do:

  • Compile
  • Flash
  • Verify oem-factory-reset
    • Yubikey
    • Nitrokey (Don't have the hardware to verify)

@tlaurion
Copy link
Collaborator

Will test as part of next test runs on top of #1312

@tlaurion
Copy link
Collaborator

No regression on my side. LGTM.
@JonathonHall-Purism ?

tlaurion added a commit to tlaurion/heads that referenced this pull request Feb 19, 2023
…, yubikey test regression for oem-factory-reset, optimized for space (03-O2->Os) and fix for sh: argument expected, with local CONFIG_DEBUG_OUTPUT enabled and fused in ROM.

Includes linuxboot#1317, linuxboot#1121, linuxboot#1312, linuxboot#1305 for test on daily driver
tlaurion added a commit to tlaurion/heads that referenced this pull request Feb 19, 2023
…ix-sh_argument_expected-yubikey-oem-factory-reset_dasharo-flashrom

Daily driver test fo x230-hotp-maximized on coreboot 4.19, with debug, yubikey test regression for oem-factory-reset, optimized for space (03-O2->Os) and fix for sh: argument expected, with local CONFIG_DEBUG_OUTPUT enabled and fused in ROM.
    Includes linuxboot#1317, linuxboot#1121, linuxboot#1312, linuxboot#1305, linuxboot#1251 for test on daily driver
tlaurion referenced this pull request in tlaurion/heads Feb 19, 2023
…ix-sh_argument_expected-yubikey-oem-factory-reset_dasharo-flashrom

Daily driver test fo x230-hotp-maximized on coreboot 4.19, with debug, yubikey test regression for oem-factory-reset, optimized for space (03-O2->Os) and fix for sh: argument expected, with local CONFIG_DEBUG_OUTPUT enabled and fused in ROM.
    Includes osresearch#1317, osresearch#1121, osresearch#1312, osresearch#1305, osresearch#1251 for test on daily driver
@JonathonHall-Purism
Copy link
Collaborator

Agree, this change makes sense. OEM reset is intended to restore defaults and sign, and "forced" is the default as far as I can tell, at least for the keys I have.

Let's merge it 👍

@tlaurion tlaurion merged commit 5c7148f into linuxboot:master Feb 21, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Provisioning Yubikey 5 Nano for Heads configuration oem-factory-reset fails to generate PGP keys with some Yubikeys

3 participants