Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.kernel > #56701
| From | Ben Hutchings <ben@decadent.org.uk> |
|---|---|
| Newsgroups | linux.debian.bugs.dist, linux.debian.kernel |
| Subject | Bug#826959: linux-signed is not yet suitable for testing |
| Date | 2017-01-23 16:10 +0100 |
| Message-ID | <t2OpR-812-47@gated-at.bofh.it> (permalink) |
| References | <t2OpS-812-65@gated-at.bofh.it> <rIx0J-6rg-3@gated-at.bofh.it> <scZ2Q-1kr-65@gated-at.bofh.it> <t2LBE-6hm-23@gated-at.bofh.it> <t2NDs-7uE-17@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
Cross-posted to 2 groups.
[Multipart message — attachments visible in raw view] - view raw
On Mon, 2017-01-23 at 14:12 +0000, Luca Boccassi wrote: > On Mon, 23 Jan 2017 12:02:04 +0000 Luca Boccassi <luca.boccassi@gmail.com> wrote: > > On Fri, 02 Sep 2016 16:54:10 +0100 Ben Hutchings <ben@decadent.org.uk> wrote: > > > Control: severity -1 important > > > > > > On Fri, 10 Jun 2016 16:55:43 +0100 Ben Hutchings <ben@decadent.org.uk> > > > wrote: > > > > Package: src:linux-signed > > > > Version: 1.1 > > > > Severity: serious > > > > > > > > Several changes are needed before it's ready for release: > > > > > > > > 1. Building signed udebs > > > > 2. Removing the -signed suffix from signed image packages > > > > > > These are now done as of version 2.2. > > > > > > > 3. Signing with an HSM > > > > > > This is not, and it really should be, but I think we can't treat this > > > as a blocker for testing propagation. > > > > > > Ben. > > > > Hello Ben, > > > > I've done some minor changes to add flags to use pesign which supports > > hardware tokens via PKCS11. Inline patch for review. > > > > Fortunately kbuild's sign-file already supports just passing a PKCS11 > > URI, which makes it so much simpler. On the other hand as you most > > likely have found out already pesign needs an NSS DB and cert nicknames > > and tokens, and all in all it's a really awkward API to use, but that's > > what we have to work with I suppose. > > > > What do you think? > > > > Thanks! > > > > Kind regards, > > Luca Boccassi > > And as a followup, the build-time change to attach using pesign. The > build-dependency is generated based on rules.defs. [...] This doesn't make sense to me. It shouldn't matter which tool was used to generate the detached signature. If pesign and sbsigntool use different file formats for detached signatures (WTF?) then sign.py should convert to a single format. Ben. -- Ben Hutchings Hoare's Law of Large Problems: Inside every large problem is a small problem struggling to get out.
Back to linux.debian.kernel | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
Bug#826959: linux-signed is not yet suitable for testing Ben Hutchings <ben@decadent.org.uk> - 2016-06-10 18:00 +0200
Bug#826959: linux-signed is not yet suitable for testing Luca Boccassi <luca.boccassi@gmail.com> - 2017-01-23 13:10 +0100
Bug#826959: linux-signed is not yet suitable for testing Luca Boccassi <lboccass@Brocade.com> - 2017-01-23 15:20 +0100
Bug#826959: linux-signed is not yet suitable for testing Ben Hutchings <ben@decadent.org.uk> - 2017-01-23 16:10 +0100
Bug#826959: linux-signed is not yet suitable for testing Luca Boccassi <luca.boccassi@gmail.com> - 2017-01-23 17:00 +0100
Bug#826959: linux-signed is not yet suitable for testing Ben Hutchings <ben@decadent.org.uk> - 2017-01-23 16:00 +0100
Bug#826959: linux-signed is not yet suitable for testing Luca Boccassi <luca.boccassi@gmail.com> - 2017-01-23 16:50 +0100
Bug#826959: marked as done (linux-signed is not yet suitable for testing) owner@bugs.debian.org (Debian Bug Tracking System) - 2017-05-20 01:30 +0200
csiph-web