How to reproduce:
- Download Linuxmint Cinnamon ISO and its verification files:
$ wget https://mirror.bauhuette.fh-aachen.de/linuxmint-cd/stable/21/linuxmint-21-cinnamon-64bit.iso
$ wget https://mirror.bauhuette.fh-aachen.de/linuxmint-cd/stable/21/sha256sum.txt
$ wget https://mirror.bauhuette.fh-aachen.de/linuxmint-cd/stable/21/sha256sum.txt.gpg
- Verify the downloaded ISO file:
$ sha256sum linuxmint-21-cinnamon-64bit.iso
$ grep "linuxmint-21-cinnamon-64bit.iso" < sha256sum.txt
$ gpg2 --verify sha256sum.txt.gpg sha256sum.txt
- Mount the downloaded ISO file as read-only, loop device with multiple partitions:
$ sudo losetup -Pfr linuxmint-21-cinnamon-64bit.iso
- Create the directories to mount the different partitions of this ISO file:
$ sudo mkdir -p /mnt/linuxmint-iso-root/
$ sudo mount -r /dev/loop0p1 /mnt/linuxmint-iso-root/
$ sudo mkdir -p /mnt/linuxmint-iso-esp/
$ sudo mount -r /dev/loop0p2 /mnt/linuxmint-iso-esp/
- Go into the ESP directory for EFI files:
$ cd /mnt/linuxmint-iso-esp/EFI/boot
- Get the SHA256 hash of the BOOTx64.EFI file and the GRUB bootloader on the mounted ISO file of Linuxmint:
$ hash-to-efi-sig-list bootx64.efi ~/linuxmint-21-cinnamon-64bit-iso-bootx64-efi-hash.esl
Failed to get hash of bootx64.efi: 2
$ hash-to-efi-sig-list grubx64.efi ~/linuxmint-21-cinnamon-64bit-iso-grubx64-efi-hash.esl
Failed to get hash of grubx64.efi: 2
- The same thing happens for the (identical) EFI files in /mnt/linuxmint-iso-root:
$ cd /mnt/linuxmint-iso-root/EFI/boot/
$ hash-to-efi-sig-list bootx64.efi ~/linuxmint-21-cinnamon-64bit-iso-root-bootx64-efi-hash.esl
Failed to get hash of bootx64.efi: 2
$ hash-to-efi-sig-list grubx64.efi ~/linuxmint-21-cinnamon-64bit-iso-root-grubx64-efi-hash.esl
Failed to get hash of grubx64.efi: 2
What went wrong?
1.hash-to-efi-sig-list did produce EFI Signature List (ESL) files, but these files contain 00000000 .... 00000000 as hash for bootx64.efi and grubx64.efi, which is obviously wrong:
$ xxd -ps -c 128 ~/linuxmint-21-cinnamon-64bit-iso-bootx64-efi-hash.esl
2616c4c14c509240aca941f9369343284c000000000000003000000050ab5d6046e00043abb63dd810dd8b230000000000000000000000000000000000000000000000000000000000000000
$ xxd -ps -c 128 ~/linuxmint-21-cinnamon-64bit-iso-grubx64-efi-hash.esl
2616c4c14c509240aca941f9369343284c000000000000003000000050ab5d6046e00043abb63dd810dd8b230000000000000000000000000000000000000000000000000000000000000000
# According to https://media.defense.gov/2020/Sep/15/2002497594/-1/-1/0/CTR-UEFI-Secure-Boot-Customization-UOO168873-20.PDF p. 12, these ESL files consist of:
# 1: 2616c4c14c509240aca941f936934328------------------------------------------------------------------------------------------------------------------------
# 2: --------------------------------4c000000----------------------------------------------------------------------------------------------------------------
# 3: ----------------------------------------00000000--------------------------------------------------------------------------------------------------------
# 4: ------------------------------------------------30000000------------------------------------------------------------------------------------------------
# 5: --------------------------------------------------------50ab5d6046e00043abb63dd810dd8b23----------------------------------------------------------------
# 6: ----------------------------------------------------------------------------------------0000000000000000000000000000000000000000000000000000000000000000
# 1: EFI_GUID Signature Type
# 2: Signature List Size
# 3: Signature Header Size
# 4: Signature Size
# 5: Originator UUID
# 6: Payload (SHA256 hash)
-
The error Failed to get hash of comes from:
( https://github.com/mjg59/efitools/blob/master/hash-to-efi-sig-list.c#L91 )
... which is calling sha256_get_pecoff_digest_mem() in line 88 to get the error code 2:
( https://github.com/mjg59/efitools/blob/master/hash-to-efi-sig-list.c#L88 )
I don't know where the function sha256_get_pecoff_digest_mem() is defined.
-
With pesign, I can produce a hash (but unfortunately not an EFI Signature List (ESL) file):
$ pesign -h -i bootx64.efi
bootx64.efi dbffd70a2c43fd2c1931f18b8f8c08c5181db15f996f747dfed34def52fad036
$ pesign -h -i grubx64.efi
grubx64.efi 25a2581c25ef38de4294c7b70a5e926817d1aeff413e20c81dfa26bda40b7c36
... so it must be a bug in hash-to-efi-sig-list.
- Getting the hash from other EFI files is possible, pesign and hash-to-efi-sig-list give identical results:
$ hash-to-efi-sig-list /boot/efi/EFI/Microsoft/Boot/bootmgfw.efi ~/windows-10-bootmgfw-efi-hash.esl
HASH IS 8bb655643293399b784985587fd7522e1295d1350c99bda69eb01d0c5acacf4a
$ pesign /boot/efi/EFI/Microsoft/Boot/bootmgfw.efi
/boot/efi/EFI/Microsoft/Boot/bootmgfw.efi 8bb655643293399b784985587fd7522e1295d1350c99bda69eb01d0c5acacf4a
$ xxd -ps -c 128 ~/windows-10-bootmgfw-efi-hash.esl | grep "8bb655643293399b784985587fd7522e1295d1350c99bda69eb01d0c5acacf4a"
2616c4c14c509240aca941f9369343284c000000000000003000000050ab5d6046e00043abb63dd810dd8b238bb655643293399b784985587fd7522e1295d1350c99bda69eb01d0c5acacf4a
How to reproduce:
What went wrong?
1.
hash-to-efi-sig-listdid produce EFI Signature List (ESL) files, but these files contain00000000 .... 00000000as hash forbootx64.efiandgrubx64.efi, which is obviously wrong:The error
Failed to get hash ofcomes from:( https://github.com/mjg59/efitools/blob/master/hash-to-efi-sig-list.c#L91 )
... which is calling
sha256_get_pecoff_digest_mem()in line 88 to get the error code 2:( https://github.com/mjg59/efitools/blob/master/hash-to-efi-sig-list.c#L88 )
I don't know where the function
sha256_get_pecoff_digest_mem()is defined.With
pesign, I can produce a hash (but unfortunately not an EFI Signature List (ESL) file):... so it must be a bug in hash-to-efi-sig-list.