Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.kernel > #56703
| From | Luca Boccassi <luca.boccassi@gmail.com> |
|---|---|
| Newsgroups | linux.debian.bugs.dist, linux.debian.kernel |
| Subject | Bug#826959: linux-signed is not yet suitable for testing |
| Date | 2017-01-23 16:50 +0100 |
| Message-ID | <t2P2x-8f3-17@gated-at.bofh.it> (permalink) |
| References | <t2P2y-8f3-41@gated-at.bofh.it> <rIx0J-6rg-3@gated-at.bofh.it> <scZ2Q-1kr-65@gated-at.bofh.it> <t2LBE-6hm-23@gated-at.bofh.it> <t2Oga-7Iq-15@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
Cross-posted to 2 groups.
[Multipart message — attachments visible in raw view] - view raw
On Mon, 2017-01-23 at 14:52 +0000, Ben Hutchings wrote: > On Mon, 2017-01-23 at 12:02 +0000, Luca Boccassi wrote: > > > On Fri, 02 Sep 2016 16:54:10 +0100 Ben Hutchings <ben@decadent.org.uk> wrote: > > > Control: severity -1 important > > > > > > On Fri, 10 Jun 2016 16:55:43 +0100 Ben Hutchings <ben@decadent.org.uk> > > > wrote: > > > > Package: src:linux-signed > > > > Version: 1.1 > > > > Severity: serious > > > > > > > > Several changes are needed before it's ready for release: > > > > > > > > 1. Building signed udebs > > > > 2. Removing the -signed suffix from signed image packages > > > > > > These are now done as of version 2.2. > > > > > > > 3. Signing with an HSM > > > > > > This is not, and it really should be, but I think we can't treat this > > > as a blocker for testing propagation. > > > > > > Ben. > > > > Hello Ben, > > > > I've done some minor changes to add flags to use pesign which supports > > hardware tokens via PKCS11. Inline patch for review. > > > > Fortunately kbuild's sign-file already supports just passing a PKCS11 > > URI, which makes it so much simpler. On the other hand as you most > > likely have found out already pesign needs an NSS DB and cert nicknames > > and tokens, and all in all it's a really awkward API to use, but that's > > what we have to work with I suppose. > > > > What do you think? > > What I left implicit in step 3 was '...held by the FTP team'. I could > use a smartcard for signing but there's never going to be a trust path > from a Microsoft or OEM certificate to my personal key (nor do I want > to be the only uploader of src:linux-signed). The work towards that is > tracked by #821051. > > Ben. Hi, Yep I'm following that bug and others. I just thought having support in linux-sign itself would be useful for users who want to self-sign and for downstream distros that rebuild the kernel and don't use dak. The latter is my case hence these changes, and I thought to share them back in case they could be useful for others. Kind regards, Luca Boccassi
Back to linux.debian.kernel | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
Bug#826959: linux-signed is not yet suitable for testing Ben Hutchings <ben@decadent.org.uk> - 2016-06-10 18:00 +0200
Bug#826959: linux-signed is not yet suitable for testing Luca Boccassi <luca.boccassi@gmail.com> - 2017-01-23 13:10 +0100
Bug#826959: linux-signed is not yet suitable for testing Luca Boccassi <lboccass@Brocade.com> - 2017-01-23 15:20 +0100
Bug#826959: linux-signed is not yet suitable for testing Ben Hutchings <ben@decadent.org.uk> - 2017-01-23 16:10 +0100
Bug#826959: linux-signed is not yet suitable for testing Luca Boccassi <luca.boccassi@gmail.com> - 2017-01-23 17:00 +0100
Bug#826959: linux-signed is not yet suitable for testing Ben Hutchings <ben@decadent.org.uk> - 2017-01-23 16:00 +0100
Bug#826959: linux-signed is not yet suitable for testing Luca Boccassi <luca.boccassi@gmail.com> - 2017-01-23 16:50 +0100
Bug#826959: marked as done (linux-signed is not yet suitable for testing) owner@bugs.debian.org (Debian Bug Tracking System) - 2017-05-20 01:30 +0200
csiph-web