AWS linux: Enforce UEFI Secure Boot by recommending 'uefi' BootMode
Summary
Updated guidance to set BootMode to 'uefi' (not 'uefi-preferred') to prevent accidental Secure Boot disablement
Security assessment
Prevents accidental boot on BIOS instances which would disable UEFI Secure Boot, a critical security feature
Evidence
+When registering an image, we recommend using the `BootMode` parameter of the [`RegisterImage`](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_RegisterImage.html) API set to `uefi` instead of `uefi-preferred`. This allows you to enable NitroTPM by setting the `TpmSupport` parameter to `v2.0`. Also, setting `BootMode` to `uefi` prevents boot on BIOS instances, thus ensures that UEFI Secure Boot can't be disabled by accident when switching to an instance type that doesn't support UEFI.
Diff
diff --git a/linux/al2023/ug/uefi-secure-boot.md b/linux/al2023/ug/uefi-secure-boot.md index f2c802f1f..0b4eeafd7 100644 --- a//linux/al2023/ug/uefi-secure-boot.md +++ b//linux/al2023/ug/uefi-secure-boot.md @@ -66 +66 @@ To enroll an existing instance, populate the specific UEFI firmware variables wi -Amazon Linux AMIs currently don't support Nitro Trusted Platform Module (NitroTPM). If you need NitroTPM in addition to UEFI Secure Boot, use the information in the following section. +Amazon Linux AMIs currently don't enable Nitro Trusted Platform Module (NitroTPM) by default with `BootMode` set to `uefi-preferred`. If you need NitroTPM in addition to UEFI Secure Boot, use the information in the following section. @@ -72,2 +71,0 @@ When registering an AMI from a snapshot of an Amazon EBS root volume using the A -For more information about creating and using a binary blob, see [Create a binary blob containing a pre-filled variable store](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/create-ami-with-uefi-secure-boot.html#uefi-secure-boot-optionB) in the _Amazon EC2 User Guide_. - @@ -80 +78,3 @@ To ensure that you are using the latest version of keys and revocations, use the -When registering an image, we recommend using the `BootMode` parameter of the [`RegisterImage`](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_RegisterImage.html) API set to `uefi`. This allows you to enable NitroTPM by setting the `TpmSupport` parameter to `v2.0`. Also, setting `BootMode` to `uefi` ensures that UEFI Secure Boot is enabled and can't be disabled by accident when switching to an instance type that doesn't support UEFI. +If you would like to add custom binary blobs, use the keys in `/usr/share/amazon-linux-sb-keys`. Find more information about creating and using binary blobs at [Create a binary blob containing a pre-filled variable store](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/create-ami-with-uefi-secure-boot.html#uefi-secure-boot-optionB) in the _Amazon EC2 User Guide_. + +When registering an image, we recommend using the `BootMode` parameter of the [`RegisterImage`](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_RegisterImage.html) API set to `uefi` instead of `uefi-preferred`. This allows you to enable NitroTPM by setting the `TpmSupport` parameter to `v2.0`. Also, setting `BootMode` to `uefi` prevents boot on BIOS instances, thus ensures that UEFI Secure Boot can't be disabled by accident when switching to an instance type that doesn't support UEFI. @@ -88 +88 @@ It may be necessary for Amazon Linux to distribute a new version of the bootload -Package updates to the `grub2`or `kernel` packages always automatically update the list of revocations into the UEFI variable store of the running instance. This means that with UEFI Secure Boot enabled, you can no longer run the old version of a package after installing a security update for the package. +Package updates to the `grub2`or `kernel` packages always automatically update the list of revocations into the UEFI variable store of the running instance. This means that with UEFI Secure Boot enabled, you might no longer be able to run the old version of a package after installing a security update for the package.