Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.kernel > #63452

Re: last preparations for switching to production Secure Boot key

Path csiph.com!news.redatomik.org!aioe.org!bofh.it!news.nic.it!robomod
From Ansgar <ansgar@debian.org>
Newsgroups linux.debian.kernel
Subject Re: last preparations for switching to production Secure Boot key
Date Tue, 26 Feb 2019 21:30:01 +0100
Message-ID <xvRwt-3R7-3@gated-at.bofh.it> (permalink)
References <xvtXb-5U8-1@gated-at.bofh.it> <xvPO1-2Ji-7@gated-at.bofh.it>
X-Original-To debian-efi@lists.debian.org
X-Mailbox-Line From debian-kernel-request@lists.debian.org Tue Feb 26 20:24:13 2019
Old-Return-Path <ansgar@43-1.org>
X-Amavis-Spam-Status No, score=-6.999 tagged_above=-10000 required=5.3 tests=[BAYES_00=-2, DIGITS_LETTERS=1, HEADER_FROM_DIFFERENT_DOMAINS=0.001, LDO_WHITELIST=-5, MD5_SHA1_SUM=-1] autolearn=ham autolearn_force=no
X-Policyd-Weight using cached result; rate: -4.6
User-Agent Gnus/5.13 (Gnus v5.13) Emacs/26.1 (gnu/linux)
MIME-Version 1.0
Content-Type text/plain
X-Mailing-List <debian-kernel@lists.debian.org> archive/latest/119745
List-ID <debian-kernel.lists.debian.org>
List-URL <https://lists.debian.org/debian-kernel/>
List-Archive https://lists.debian.org/msgid-search/87bm2yxpr5.fsf@marvin.43-1.org
Approved robomod@news.nic.it
Lines 48
Organization linux.* mail to news gateway
Sender robomod@news.nic.it
X-Original-Cc GRUB Maintainers <pkg-grub-devel@alioth-lists.debian.net>, Debian Kernel Team <debian-kernel@lists.debian.org>, ftpmaster@ftp-master.debian.org
X-Original-Date Tue, 26 Feb 2019 21:23:58 +0100
X-Original-Message-ID <87bm2yxpr5.fsf@marvin.43-1.org>
X-Original-References <87zhqj65rh.fsf@43-1.org> <20190226183323.xyjbdf3zztkzdxv4@riva.ucam.org>
Xref csiph.com linux.debian.kernel:63452

Show key headers only | View raw


Hi,

Colin Watson writes:
> On Mon, Feb 25, 2019 at 08:13:22PM +0100, Ansgar wrote:
>> I added support for listing `trusted_certs`[1] as proposed by Ben
>> Hutchings.  This means the `files.json` structure *must* list the
>> sha256sum of certificates the signed binaries will trust (this can be an
>> empty list in case no hard-coded certificates are trusted).
>
> Do I understand correctly that this ought to be empty in the case of
> grub2, since it does all its signature checking via shim?  If so, done:
>
>   https://salsa.debian.org/grub-team/grub/commit/89c1529cd82f106dbb9a4b17bae03e828ec349b6

Yes, that looks okay.

>> I would like to implement one additional change.  Currently files.json
>> looks like this:
> [...]
>> This is not extendable; therefore I would like to move everything below a
>> top-level `packages` key, i.e. the file would look like this instead:
> [...]
>> This would allow adding additional top-level keys later should the need
>> arise.  (I'll prepare the archive-side changes for this later today.)
>
> I'm happy to do this, though presumably it's a flag day?

It is a flag day change, but we already have a flag day for adding
trusted_certs (as uploads without the key will no longer get signed).
It also means we won't have to support the old files.json format as we
never had a (stable) release using it.

>> Could all maintainers (for fwupd, fwupdate, grub2, linux) please ack one
>> last time that their packages are ready for switching to the production
>> key?  And prepare an upload with the changes described above and ready
>> to use the production key?
>
> I don't know of any blockers from the grub2 side.  Once the archive has
> the "packages" key changes, I can prepare an upload - I was planning to
> make one this week anyway.

The changes to code-signing are done and pushed to my fork on salsa[1]; I'm
just waiting to deploy them (well, and change the config to use the
production key at the same time).

Ansgar

  [1] https://salsa.debian.org/ansgar/code-signing/commits/d22b8ec28d7b50a6cda738a52e5496492edb8ba9

Back to linux.debian.kernel | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

last preparations for switching to production Secure Boot key Ansgar <ansgar@debian.org> - 2019-02-25 20:20 +0100
  Re: last preparations for switching to production Secure Boot key Colin Watson <cjwatson@debian.org> - 2019-02-26 19:40 +0100
    Re: last preparations for switching to production Secure Boot key Ansgar <ansgar@debian.org> - 2019-02-26 21:30 +0100
      Re: last preparations for switching to production Secure Boot key Ben Hutchings <ben@decadent.org.uk> - 2019-03-10 23:50 +0100

csiph-web