[openstack-dev] [Ironic][FFE] secure boot support in iLO drivers

Devananda van der Veen devananda.vdv at gmail.com
Thu Mar 19 17:14:31 UTC 2015


woops! thanks...

-Devananda

On Thu, Mar 19, 2015 at 10:04 AM, Ramakrishnan G
<rameshg87.openstack at gmail.com> wrote:
>
> Corrected [1]  is below (link for pxe_ilo patch review):
>
> [1] https://review.openstack.org/#/c/154808/
>
> On Thu, Mar 19, 2015 at 10:24 PM, Devananda van der Veen
> <devananda.vdv at gmail.com> wrote:
>>
>> -----BEGIN PGP SIGNED MESSAGE-----
>> Hash: SHA1
>>
>> All,
>>
>> This feature [0] enables secure boot mode for hardware which supports
>> UEFI.
>> Ironic added support for UEFI in Juno. This is an incremental improvement,
>> allowing those users to benefit more from their hardware's security
>> features.
>>
>> After this morning's final round of reviews to get features in, we agreed
>> to
>> defer the pxe_ilo driver changes, as those are the highest risk component
>> of
>> the secure boot blueprint, but grant a short extension for the other two
>> drivers (iscsi_ilo and agent_ilo) which do not require PXE booting.
>>
>> The remaining changes are already either approved or very close to, and
>> we're
>> confident this can be landed in the next couple days without impact
>> outside of
>> those drivers.
>>
>> As such, I have blocked the pxe_ilo patch [1], retargeted the blueprint to
>> RC1,
>> and am granting an exception for those drivers. I'll re-review the status
>> of
>> this on Monday, March 23rd.
>>
>> [0] https://blueprints.launchpad.net/ironic/+spec/uefi-secure-boot
>>
>> [1] https://review.openstack.org/#/c/159322/
>>
>> - -Devananda
>> -----BEGIN PGP SIGNATURE-----
>> Version: GnuPG v1
>>
>> iEYEARECAAYFAlUK/woACgkQhFvuBniJg6demgCgxiSlIAPPSqNwUK8gGo2qOpxF
>> gsEAoM65a5bTlBlaPKOKfpcJsN67INnW
>> =bdk6
>> -----END PGP SIGNATURE-----
>>
>> __________________________________________________________________________
>> OpenStack Development Mailing List (not for usage questions)
>> Unsubscribe: OpenStack-dev-request at lists.openstack.org?subject:unsubscribe
>> http://lists.openstack.org/cgi-bin/mailman/listinfo/openstack-dev
>
>
>
> __________________________________________________________________________
> OpenStack Development Mailing List (not for usage questions)
> Unsubscribe: OpenStack-dev-request at lists.openstack.org?subject:unsubscribe
> http://lists.openstack.org/cgi-bin/mailman/listinfo/openstack-dev
>



More information about the OpenStack-dev mailing list