Skip to content

Comments

jetson orin: enroll UEFI secure boot keys from certs#1713

Open
vadika wants to merge 1 commit intotiiuae:mainfrom
vadika:jetson-orin-uefi-secureboot-keys
Open

jetson orin: enroll UEFI secure boot keys from certs#1713
vadika wants to merge 1 commit intotiiuae:mainfrom
vadika:jetson-orin-uefi-secureboot-keys

Conversation

@vadika
Copy link
Contributor

@vadika vadika commented Jan 27, 2026

Summary

  • Generate ESLs from repo PK/KEK/db certs at build time for Jetson Orin.
  • Wire ESLs into jetpack‑nixos UEFI secure boot enrollment.
  • Enable the new secure boot module by default for Orin targets.

Description of Changes

Type of Change

  • New Feature
  • Bug Fix
  • Improvement / Refactor

Related Issues / Tickets

Checklist

  • Clear summary in PR description
  • Detailed and meaningful commit message(s)
  • Commits are logically organized and squashed if appropriate
  • Contribution guidelines followed
  • Ghaf documentation updated with the commit - https://tiiuae.github.io/ghaf/
  • Author has run make-checks and it passes
  • All automatic GitHub Action checks pass - see actions
  • Author has added reviewers and removed PR draft status

Testing Instructions

Applicable Targets

  • Orin AGX aarch64
  • Orin NX aarch64
  • Lenovo X1 x86_64
  • Dell Latitude x86_64
  • System 76 x86_64

Installation Method

  • Requires full re-installation
  • Can be updated with nixos-rebuild ... switch
  • Other:

Test Steps To Verify:

Build, flash and reboot -- SB should be enabled on device

Signed-off-by: vadik likholetov <vadikas@gmail.com>
@vadika vadika force-pushed the jetson-orin-uefi-secureboot-keys branch from 7c42129 to 6984bce Compare February 12, 2026 18:57
@milva-unikie milva-unikie removed the Needs Testing CI Team to pre-verify label Feb 17, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants