diff mbox series

[ovs-dev] doc: document the nointegritychecks setting.

Message ID 1583172404-36717-1-git-send-email-u9012063@gmail.com
State Rejected
Headers show
Series [ovs-dev] doc: document the nointegritychecks setting. | expand

Commit Message

William Tu March 2, 2020, 6:06 p.m. UTC
OVS kernel module requires to turn on the 'nointegritychecks'. It has following
limitations:
nointegritychecks [ on | off ] Disables integrity checks.
    Cannot be set when secure boot is enabled. This value is
    ignored by Windows 7 and Windows 8.
https://docs.microsoft.com/en-us/windows-hardware/drivers/devtest/bcdedit--set

Signed-off-by: William Tu <u9012063@gmail.com>
---
 Documentation/intro/install/windows.rst | 2 ++
 1 file changed, 2 insertions(+)

Comments

Alin Serdean March 8, 2020, 4:35 a.m. UTC | #1
> -----Original Message-----
> From: William Tu <u9012063@gmail.com>
> Sent: Monday, March 2, 2020 8:07 PM
> To: dev@openvswitch.org
> Cc: aserdean@ovn.org
> Subject: [PATCH] doc: document the nointegritychecks setting.
> 
> OVS kernel module requires to turn on the 'nointegritychecks'. It has following
> limitations:
 [Alin Serdean] Actually the generated driver from our project is testsigned, which
implies the host only needs the /testsigning enabled, which again is not valid
under secure boot.
William Tu March 9, 2020, 9:47 p.m. UTC | #2
On Sat, Mar 7, 2020 at 8:35 PM Alin Serdean
<aserdean@cloudbasesolutions.com> wrote:
>
> > -----Original Message-----
> > From: William Tu <u9012063@gmail.com>
> > Sent: Monday, March 2, 2020 8:07 PM
> > To: dev@openvswitch.org
> > Cc: aserdean@ovn.org
> > Subject: [PATCH] doc: document the nointegritychecks setting.
> >
> > OVS kernel module requires to turn on the 'nointegritychecks'. It has following
> > limitations:
>  [Alin Serdean] Actually the generated driver from our project is testsigned, which
> implies the host only needs the /testsigning enabled, which again is not valid
> under secure boot.
>
I see.
So anyway the secure boot should be disabled.
William
diff mbox series

Patch

diff --git a/Documentation/intro/install/windows.rst b/Documentation/intro/install/windows.rst
index 394572f001e9..579e41b73d8e 100644
--- a/Documentation/intro/install/windows.rst
+++ b/Documentation/intro/install/windows.rst
@@ -287,6 +287,8 @@  Enforcement' during boot.  The following commands can be used:
 .. note::
 
   You may have to restart the machine for the settings to take effect.
+  The nointegritychecks cannot be set when secure boot is enabled and
+  the value is ignored by Windows 8.
 
 In the Virtual Switch Manager configuration you can enable the Open vSwitch
 Extension on an existing switch or create a new switch.  If you are using an