Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 681936 - sys-firmware/edk2-ovmf lacks Secure Boot support
Summary: sys-firmware/edk2-ovmf lacks Secure Boot support
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: Current packages (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Matthias Maier
Depends on:
Reported: 2019-03-28 17:04 UTC by Sebastian Hamann
Modified: 2019-07-28 23:17 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Note You need to log in before you can comment on or make changes to this bug.
Description Sebastian Hamann 2019-03-28 17:04:11 UTC
Currently available versions of sys-firmware/edk2-ovmf only install a firmware build without Secure Boot support. A build with Secure Boot support would allow easily experimenting/developing/testing Secure Boot in a VM.

Build instructions from Tianocore:,-KVM-and-libvirt

What Fedora does:

Similar feature request on Arch Linux:

I think, the gist of it is to add -D SMM_REQUIRE -D SECURE_BOOT_ENABLE to the build process. Some fiddling with OpenSSL may be required as well.

I extracted OVMF_CODE.secboot.fd from Fedora's edk2-ovmf-20190308stable-1.fc31.noarch.rpm and dropped it on my Gentoo system. It works fine with qemu and libvirt.
Comment 1 Larry the Git Cow gentoo-dev 2019-07-28 23:17:50 UTC
The bug has been closed via the following commit(s):

commit 6137d4c59ea47d77517e925d8bfd46b8b3b1f669
Author:     Matthias Maier <>
AuthorDate: 2019-07-28 21:00:39 +0000
Commit:     Matthias Maier <>
CommitDate: 2019-07-28 23:17:16 +0000

    sys-firmware/edk2-ovmf: version bump to 201905
     * switch to new upstream version number
     * add secure boot support
     * versions contains security fixes for all vulnerabilities identified
       in #678906c1
    Package-Manager: Portage-2.3.69, Repoman-2.3.16
    Signed-off-by: Matthias Maier <>

 sys-firmware/edk2-ovmf/Manifest                |   5 +-
 sys-firmware/edk2-ovmf/edk2-ovmf-201905.ebuild | 153 +++++++++++++++++++++++++
 2 files changed, 156 insertions(+), 2 deletions(-)