среда

[Bug 1932582] Re: Implement support for Intel SGX

This bug was fixed in the package linux-base - 4.5ubuntu9

---------------
linux-base (4.5ubuntu9) impish; urgency=medium

[ Tim Gardner ]
* Add SGX support for Linux >= v5.11 (LP: #1932582)
- Added a udev rule for v5.11 SGX device names,

[ Tim Gardner & Dimitri John Ledkov ]
- Add /etc/profile.d/linux-base-sgx.sh and
/usr/lib/systemd/system-environment-generators/linux-base-sgx to
export environmental variable for out-of-process attestation by
default for: tty login sessions; ssh login sessions; systemd
user services; systemd system services.

-- Tim Gardner <tim.gardner@canonical.com> Tue, 22 Jun 2021 07:38:37
-0600

** Changed in: linux-base (Ubuntu Impish)
Status: Fix Committed => Fix Released

--
You received this bug notification because you are subscribed to linux
in Ubuntu.
Matching subscriptions: Bgg, Bmail, Nb
https://bugs.launchpad.net/bugs/1932582

Title:
Implement support for Intel SGX

Status in linux package in Ubuntu:
Fix Released
Status in linux-azure package in Ubuntu:
Fix Released
Status in linux-azure-5.11 package in Ubuntu:
Invalid
Status in linux-base package in Ubuntu:
Fix Released
Status in linux source package in Focal:
Invalid
Status in linux-azure source package in Focal:
Invalid
Status in linux-azure-5.11 source package in Focal:
Fix Committed
Status in linux-base source package in Focal:
In Progress
Status in linux source package in Hirsute:
Fix Released
Status in linux-azure source package in Hirsute:
Fix Released
Status in linux-azure-5.11 source package in Hirsute:
Invalid
Status in linux-base source package in Hirsute:
In Progress
Status in linux source package in Impish:
Fix Released
Status in linux-azure source package in Impish:
Fix Released
Status in linux-azure-5.11 source package in Impish:
Invalid
Status in linux-base source package in Impish:
Fix Released

Bug description:
[Impact]

Backport Linux kernel 5.11 SGX native support to new Azure Ubuntu 20.04
releases.

[Fix]

Update linux-base to add a UDEV rule to set group permissions on the SGX device.
Add an environment variable to default to out-of-proc attestation.

[Test]

Install focal:linux-azure-5.11 or hirsute:linux-azure.
Install linux-base-sgx
reboot
systemctl --user show-environment | grep SGX_AESM_ADDR
systemctl --system show-environment | grep SGX_AESM_ADDR
login via tty and check $ env | grep SGX_AESM_ADDR
login via ssh and check $ env | grep SGX_AESM_ADDR


[other info]

SF:00308240

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/linux/+bug/1932582/+subscriptions

Комментариев нет:

Отправить комментарий