Skip to content

hash-to-efi-sig-list (linuxmint-21-iso)/bootx64.efi ~/bootx64-efi-hash.esl : Failed to get hash of bootx64.efi: 2 #5

Description

@conrad-heimbold

How to reproduce:

  1. Download Linuxmint Cinnamon ISO and its verification files:
$ wget https://mirror.bauhuette.fh-aachen.de/linuxmint-cd/stable/21/linuxmint-21-cinnamon-64bit.iso
$ wget https://mirror.bauhuette.fh-aachen.de/linuxmint-cd/stable/21/sha256sum.txt 
$ wget https://mirror.bauhuette.fh-aachen.de/linuxmint-cd/stable/21/sha256sum.txt.gpg 
  1. Verify the downloaded ISO file:
$ sha256sum linuxmint-21-cinnamon-64bit.iso
$ grep "linuxmint-21-cinnamon-64bit.iso" < sha256sum.txt 
$ gpg2 --verify sha256sum.txt.gpg sha256sum.txt
  1. Mount the downloaded ISO file as read-only, loop device with multiple partitions:
$ sudo losetup -Pfr linuxmint-21-cinnamon-64bit.iso
  1. Create the directories to mount the different partitions of this ISO file:
$ sudo mkdir -p /mnt/linuxmint-iso-root/ 
$ sudo mount -r /dev/loop0p1 /mnt/linuxmint-iso-root/
$ sudo mkdir -p /mnt/linuxmint-iso-esp/ 
$ sudo mount -r /dev/loop0p2 /mnt/linuxmint-iso-esp/ 
  1. Go into the ESP directory for EFI files:
$ cd /mnt/linuxmint-iso-esp/EFI/boot 
  1. Get the SHA256 hash of the BOOTx64.EFI file and the GRUB bootloader on the mounted ISO file of Linuxmint:
$ hash-to-efi-sig-list bootx64.efi ~/linuxmint-21-cinnamon-64bit-iso-bootx64-efi-hash.esl 
Failed to get hash of bootx64.efi: 2
$ hash-to-efi-sig-list grubx64.efi ~/linuxmint-21-cinnamon-64bit-iso-grubx64-efi-hash.esl 
Failed to get hash of grubx64.efi: 2
  1. The same thing happens for the (identical) EFI files in /mnt/linuxmint-iso-root:
$ cd /mnt/linuxmint-iso-root/EFI/boot/
$ hash-to-efi-sig-list bootx64.efi ~/linuxmint-21-cinnamon-64bit-iso-root-bootx64-efi-hash.esl 
Failed to get hash of bootx64.efi: 2
$ hash-to-efi-sig-list grubx64.efi ~/linuxmint-21-cinnamon-64bit-iso-root-grubx64-efi-hash.esl 
Failed to get hash of grubx64.efi: 2

What went wrong?

1.hash-to-efi-sig-list did produce EFI Signature List (ESL) files, but these files contain 00000000 .... 00000000 as hash for bootx64.efi and grubx64.efi, which is obviously wrong:

$ xxd -ps -c 128 ~/linuxmint-21-cinnamon-64bit-iso-bootx64-efi-hash.esl 
2616c4c14c509240aca941f9369343284c000000000000003000000050ab5d6046e00043abb63dd810dd8b230000000000000000000000000000000000000000000000000000000000000000
$ xxd -ps -c 128 ~/linuxmint-21-cinnamon-64bit-iso-grubx64-efi-hash.esl 
2616c4c14c509240aca941f9369343284c000000000000003000000050ab5d6046e00043abb63dd810dd8b230000000000000000000000000000000000000000000000000000000000000000
# According to https://media.defense.gov/2020/Sep/15/2002497594/-1/-1/0/CTR-UEFI-Secure-Boot-Customization-UOO168873-20.PDF p. 12, these ESL files consist of:
# 1: 2616c4c14c509240aca941f936934328------------------------------------------------------------------------------------------------------------------------
# 2: --------------------------------4c000000----------------------------------------------------------------------------------------------------------------
# 3: ----------------------------------------00000000--------------------------------------------------------------------------------------------------------
# 4: ------------------------------------------------30000000------------------------------------------------------------------------------------------------
# 5: --------------------------------------------------------50ab5d6046e00043abb63dd810dd8b23----------------------------------------------------------------
# 6: ----------------------------------------------------------------------------------------0000000000000000000000000000000000000000000000000000000000000000
# 1: EFI_GUID Signature Type
# 2: Signature List Size 
# 3: Signature Header Size
# 4: Signature Size 
# 5: Originator UUID
# 6: Payload (SHA256 hash) 
  1. The error Failed to get hash of comes from:
    ( https://github.com/mjg59/efitools/blob/master/hash-to-efi-sig-list.c#L91 )
    ... which is calling sha256_get_pecoff_digest_mem() in line 88 to get the error code 2:
    ( https://github.com/mjg59/efitools/blob/master/hash-to-efi-sig-list.c#L88 )
    I don't know where the function sha256_get_pecoff_digest_mem() is defined.

  2. With pesign, I can produce a hash (but unfortunately not an EFI Signature List (ESL) file):

$ pesign -h -i bootx64.efi 
bootx64.efi dbffd70a2c43fd2c1931f18b8f8c08c5181db15f996f747dfed34def52fad036
$ pesign -h -i grubx64.efi 
grubx64.efi 25a2581c25ef38de4294c7b70a5e926817d1aeff413e20c81dfa26bda40b7c36

... so it must be a bug in hash-to-efi-sig-list.

  1. Getting the hash from other EFI files is possible, pesign and hash-to-efi-sig-list give identical results:
$ hash-to-efi-sig-list /boot/efi/EFI/Microsoft/Boot/bootmgfw.efi ~/windows-10-bootmgfw-efi-hash.esl 
HASH IS 8bb655643293399b784985587fd7522e1295d1350c99bda69eb01d0c5acacf4a
$ pesign /boot/efi/EFI/Microsoft/Boot/bootmgfw.efi 
/boot/efi/EFI/Microsoft/Boot/bootmgfw.efi 8bb655643293399b784985587fd7522e1295d1350c99bda69eb01d0c5acacf4a
$ xxd -ps -c 128 ~/windows-10-bootmgfw-efi-hash.esl | grep "8bb655643293399b784985587fd7522e1295d1350c99bda69eb01d0c5acacf4a"
2616c4c14c509240aca941f9369343284c000000000000003000000050ab5d6046e00043abb63dd810dd8b238bb655643293399b784985587fd7522e1295d1350c99bda69eb01d0c5acacf4a

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions