#5680 HIGH Update.: G1G1 laptops are shipping with "security" enabled

Zarro Boogs per Child bugtracker at laptop.org
Mon Feb 4 14:55:36 EST 2008


#5680: G1G1 laptops are shipping with "security" enabled
-----------------------+----------------------------------------------------
  Reporter:  gnu       |       Owner:  jg                      
      Type:  defect    |      Status:  new                     
  Priority:  high      |   Milestone:  Update.1                
 Component:  security  |     Version:                          
Resolution:            |    Keywords:  firmware, security, G1G1
  Verified:  0         |    Blocking:                          
 Blockedby:            |  
-----------------------+----------------------------------------------------
Changes (by cscott):

 * cc: cscott (removed)


Comment:

 I believe copy and paste from browser to terminal work in update.1.  I
 don't know anything about whatever certificate bugs jg is complaining
 about in his item 1.  jg's item 2 is presently infeasible, for a number of
 reasons.   A better solution is to use 'disable-security' if that is what
 you want to do, which is what gnu recommends in his reply.  Even better:
 keep using olpc-update, which has no problem preserving the key.  No idea
 what jg means by item 3; we already protect against access to SPI flash
 access even with a dev key, which is what causes the reboot cycle gnu
 complains about.

 The "automatic installation from web browser problem" is out of my court:
 stuff downloaded from the browser ends up in the journal and the journal
 needs to grow some special knowledge of dev keys and put them in the right
 place.  Please file a separate bug for that, and assign it to the journal
 guys.

-- 
Ticket URL: <http://dev.laptop.org/ticket/5680#comment:10>
One Laptop Per Child <http://dev.laptop.org>
OLPC bug tracking system



More information about the Bugs mailing list