Bug 2225009 - Include the newly created secureboot{304, 504, 704} certs into redhat-sb-certs [NEEDINFO]
Summary: Include the newly created secureboot{304, 504, 704} certs into redhat-sb-certs
Keywords:
Status: ASSIGNED
Alias: None
Product: Red Hat Enterprise Linux 9
Classification: Red Hat
Component: redhat-release
Version: 9.3
Hardware: Unspecified
OS: Unspecified
unspecified
unspecified
Target Milestone: rc
: ---
Assignee: Veronika Doubkova
QA Contact: Release Test Team
URL:
Whiteboard:
Depends On:
Blocks: 2225529
TreeView+ depends on / blocked
 
Reported: 2023-07-24 08:54 UTC by Vitaly Kuznetsov
Modified: 2023-08-13 21:13 UTC (History)
6 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed:
Type: Bug
Target Upstream Version:
Embargoed:
zveleba: needinfo? (vdoubkov)


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Issue Tracker RHELBLD-13378 0 None None None 2023-07-24 08:57:29 UTC
Red Hat Issue Tracker RHELPLAN-163042 0 None None None 2023-07-24 08:57:33 UTC

Description Vitaly Kuznetsov 2023-07-24 08:54:00 UTC
New secureboot keys to sign Unified Kernel Images were created: https://issues.redhat.com/browse/SIGNSERVER-416 so we need to include them into 'redhat-sb-certs' package.

For RHEL9.3+, I suggest we create /usr/share/pki/sb-certs/secureboot-uki-virt-x86_64.cer and /etc/pki/sb-certs/secureboot-uki-virt-x86_64.cer link containing 
secureboot504.

Comment 1 Vitaly Kuznetsov 2023-07-24 08:55:20 UTC
For CentOS Stream, we need to package centossecureboot204. I can create a separate BZ if needed.

Comment 10 Lisa S 2023-07-31 21:16:56 UTC
We will get to this next sprint, which starts next week.


Note You need to log in before you can comment on or make changes to this bug.