Calificación:
  • 6 voto(s) - 5 Media
  • 1
  • 2
  • 3
  • 4
  • 5
A nadie le importa una mierda, pero... v13
Estaba leyendo los requisitos para el fabricante que quiera pegatina W8:
Cita:Mandatory. On non-ARM systems, the platform MUST implement the ability for a physically present user to select between two Secure Boot modes in firmware setup: "Custom" and "Standard". Custom Mode allows for more flexibility as specified in the following:

It shall be possible for a physically present user to use the Custom Mode firmware setup option to modify the contents of the Secure Boot signature databases and the PK. This may be implemented by simply providing the option to clear all Secure Boot databases (PK, KEK, db, dbx), which puts the system into setup mode.

If the user ends up deleting the PK then, upon exiting the Custom Mode firmware setup, the system is operating in Setup Mode with SecureBoot turned off.

The firmware setup shall indicate if Secure Boot is turned on, and if it is operated in Standard or Custom Mode. The firmware setup must provide an option to return from Custom to Standard Mode which restores the factory defaults. On an ARM system, it is forbidden to enable Custom Mode. Only Standard Mode may be enabled.

Mandatory. Enable/Disable Secure Boot. On non-ARM systems, it is required to implement the ability to disable Secure Boot via firmware setup. A physically present user must be allowed to disable Secure Boot via firmware setup without possession of PKpriv. A Windows Server may also disable Secure Boot remotely using a strongly authenticated (preferably public-key based) out-of-band management connection, such as to a baseboard management controller or service processor. Programmatic disabling of Secure Boot either during Boot Services or after exiting EFI Boot Services MUST NOT be possible. Disabling Secure Boot must not be possible on ARM systems.
http://msdn.microsoft.com/en-us/library/...28256.aspx

y hay una cosa del 1º que no queda clara. Dice que el usuario debe poder usar un custom mode para el secureboot y que podrá modificar la BBDD de firmas, PERO que esa opción de modificar basta que consista en permitir borrar la BBDD firmas o_O ¿DEBE permitir cargar nuevas o no es obligatorio?
[Imagen: e4jeCf8.png]







Mensajes en este tema
Imágenes raras - por Chachibukai - 01-30-2013, 09:16 PM
RE: A nadie le importa una mierda, pero... v13 - por Yumichan - 04-22-2013, 12:36 PM
¡Loros, loros, loros! - por Chachibukai - 05-31-2013, 11:06 PM
RE: ¡Loros, loros, loros! - por Unmeikuro - 05-31-2013, 11:12 PM
Loros!!! - por Yumichan - 05-31-2013, 11:44 PM

Salto de foro:


Usuarios navegando en este tema: 55 invitado(s)