Append secure boot utility by adding expired and rootca cert generation - #20
Append secure boot utility by adding expired and rootca cert generation#20kiemonbb wants to merge 4 commits into
Conversation
…ge generation Signed-off-by: Oktawian Bieszke <oktawian.bieszke@3mdeb.com>
Signed-off-by: Oktawian Bieszke <oktawian.bieszke@3mdeb.com>
Signed-off-by: Oktawian Bieszke <oktawian.bieszke@3mdeb.com>
|
Log showing |
Just a quick note before I review, have you considered the UEFI spec details @miczyg1 gave here? Dasharo/dasharo-issues#1863 |
|
Yes, I'm aware of Dasharo/dasharo-issues#1863, but this PR only intended to transfer utility from the lost sb-image-wrapper.sh file . The expired cert wasn't too much of a hassle to add and as @miczyg1 said it should still fail on UEFI compliant firmware. |
It would require some more fields in the certificates and timestamping the signature, which |
f32cdc5 to
f47f9de
Compare
Added note in readme https://github.com/Dasharo/osfv-test-data/pull/20/changes#diff-b2b6a9e250b262ad7ba45030f2bb02dd4be8f08a3c8f9220b1767cfa9b9e6d3bR30 |
903db11 to
bd6766b
Compare
bd6766b to
325d357
Compare
Signed-off-by: Oktawian Bieszke <oktawian.bieszke@3mdeb.com>
325d357 to
ab6d2c4
Compare
|
Have you tried running the OSFV tests with these? |
No description provided.