Bug ID 1270525: Shielded VM or UEFI secure boot compatible support

Last Modified: Feb 28, 2025

Affected Product(s):
BIG-IP TMOS(all modules)

Known Affected Versions:
14.1.4.4, 14.1.4.5, 14.1.4.6, 14.1.5, 14.1.5.1, 14.1.5.2, 14.1.5.3, 14.1.5.4, 14.1.5.6

Fixed In:
17.5.0

Opened: Mar 14, 2023

Severity: 0-Unspecified

Symptoms

Shielded VM support on Google Cloud Platform (GCP) is a feature designed to enhance the security of virtual machines (VMs) by providing a more trusted environment for workloads.

Impact

Shielded VMs use Secure Boot to ensure that the VM's boot process only allows signed and verified code to run. This helps prevent unauthorized modifications to the operating system and firmware.

Conditions

-- This feature applies to the Google Cloud Platform.

Workaround

None

Fix Information

To add the shielded VM support, below changes were done. 1. Creating EFI framework 2. Creating grub.cfg (content required inside - timer + menu entry + TMOS maintenance) 3. Updating grub.cfg automatically when installing new image in another volume 4. Copying EFI files (Shim content) to /dev/sda1/

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips