]> git.dujemihanovic.xyz Git - u-boot.git/commit
efi_loader: image_loader: add a check against certificate type of authenticode
authorAKASHI Takahiro <takahiro.akashi@linaro.org>
Wed, 8 Jul 2020 05:01:52 +0000 (14:01 +0900)
committerHeinrich Schuchardt <xypron.glpk@gmx.de>
Sat, 11 Jul 2020 21:14:15 +0000 (23:14 +0200)
commit1a44b7059c183a227f2fc4519df24da09d403cba
tree0bf24ccb0f3581816d397f0b864dfbb79ac53fe8
parentb9f217a4cbe8c808a34f824503d15996a7f8be13
efi_loader: image_loader: add a check against certificate type of authenticode

UEFI specification requires that we shall support three type of
certificates of authenticode in PE image:
  WIN_CERT_TYPE_EFI_GUID with the guid, EFI_CERT_TYPE_PCKS7_GUID
  WIN_CERT_TYPE_PKCS_SIGNED_DATA
  WIN_CERT_TYPE_EFI_PKCS1_15

As EDK2 does, we will support the first two that are pkcs7 SignedData.

Signed-off-by: AKASHI Takahiro <takahiro.akashi@linaro.org>
lib/efi_loader/efi_image_loader.c