Revisions of shim
Stephan Kulow (coolo)
accepted
request 197952
from
Gary Ching-Pang Lin (gary_lin)
(revision 22)
- set timestamp of PE file to time of the binary the signature was made for. - make sure cert.o get's rebuilt for each target - Update microsoft.asc: shim signed by UEFI signing service, based on code from "Wed Aug 28 15:54:38 UTC 2013" (forwarded request 197604 from lnussel)
Stephan Kulow (coolo)
accepted
request 196741
from
Gary Ching-Pang Lin (gary_lin)
(revision 21)
- always build a shim that embeds the distro's certificate (e.g. shim-opensuse.efi). If the package is built in the devel project additionally shim-devel.efi is created. That allows us to either load grub2/kernel signed by the distro or signed by the devel project, depending on use case. Also shim-$distro.efi from the devel project can be used to request additional signatures. (forwarded request 196735 from lnussel)
Stephan Kulow (coolo)
accepted
request 196635
from
Gary Ching-Pang Lin (gary_lin)
(revision 20)
- also include old openSUSE 4096 bit certificate to be able to still boot kernels signed with that key. - add show_signatures script (forwarded request 196609 from lnussel)
Stephan Kulow (coolo)
accepted
request 196499
from
Gary Ching-Pang Lin (gary_lin)
(revision 19)
- replace the 4096 bit openSUSE UEFI CA certificate with new a standard compliant 2048 bit one. (forwarded request 196493 from lnussel)
Tomáš Chvátal (scarabeus_factory)
accepted
request 195856
from
Gary Ching-Pang Lin (gary_lin)
(revision 18)
- fix shell syntax error (forwarded request 195685 from lnussel)
Tomáš Chvátal (scarabeus_factory)
accepted
request 186559
from
Gary Ching-Pang Lin (gary_lin)
(revision 17)
- don't include binary in the sources. Instead package the raw signature and attach it during build (bnc#813448). (forwarded request 186534 from lnussel)
Stephan Kulow (coolo)
accepted
request 185350
from
Gary Ching-Pang Lin (gary_lin)
(revision 16)
- Update shim-mokmanager-ui-revamp.patch to include fixes for MokManager + reboot the system after clearing MOK password + fetch more info from X509 name + check the suffix of the key file (forwarded request 185349 from gary_lin)
Stephan Kulow (coolo)
accepted
request 184040
from
Gary Ching-Pang Lin (gary_lin)
(revision 15)
- Update to 0.4 - Rebase patches + shim-suse-build.patch + shim-mokmanager-support-crypt-hash-method.patch + shim-bnc804631-fix-broken-bootpath.patch + shim-bnc798043-no-doulbe-separators.patch + shim-bnc807760-change-pxe-2nd-loader-name.patch + shim-bnc808106-correct-certcount.patch + shim-mokmanager-ui-revamp.patch - Add patches + shim-merge-lf-loader-code.patch: merge the Linux Foundation loader UI code + shim-fix-pointer-casting.patch: fix a casting issue and the size of an empty vendor cert + shim-fix-simple-file-selector.patch: fix the buffer allocation in the simple file selector - Remove upstreamed patches + shim-support-mok-delete.patch + shim-reboot-after-changes.patch + shim-clear-queued-key.patch + shim-local-key-sign-mokmanager.patch + shim-get-2nd-stage-loader.patch + shim-fix-loadoptions.patch - Remove unused patch: shim-mokmanager-new-pw-hash.patch and shim-keep-unsigned-mokmanager.patch - Install the vendor certificate to /etc/uefi/certs (forwarded request 184039 from gary_lin)
Stephan Kulow (coolo)
accepted
request 174779
from
Gary Ching-Pang Lin (gary_lin)
(revision 14)
Revamp the MokManager UI (forwarded request 174778 from gary_lin)
Stephan Kulow (coolo)
accepted
request 162328
from
Gary Ching-Pang Lin (gary_lin)
(revision 13)
bnc#813079: Call update-bootloader in %post to update *.efi in \efi\opensuse (forwarded request 162327 from gary_lin)
Stephan Kulow (coolo)
accepted
request 157971
from
Gary Ching-Pang Lin (gary_lin)
(revision 12)
bnc#807760: change the PXE 2nd stage loader name bnc#808106: certificate count of the signature list (forwarded request 157970 from gary_lin)
Stephan Kulow (coolo)
accepted
request 157343
from
Gary Ching-Pang Lin (gary_lin)
(revision 11)
(bnc#798043#c4) remove double seperators from the bootpath (forwarded request 157208 from gary_lin)
Stephan Kulow (coolo)
accepted
request 156904
from
Gary Ching-Pang Lin (gary_lin)
(revision 10)
- sign shim also with openSUSE certificate (forwarded request 156849 from lnussel)
Stephan Kulow (coolo)
accepted
request 156082
from
Gary Ching-Pang Lin (gary_lin)
(revision 9)
bnc#804631: fix the broken bootpath generated in generate_path() (forwarded request 156025 from gary_lin)
Stephan Kulow (coolo)
accepted
request 155108
from
Stephan Kulow (coolo)
(revision 8)
- Update with shim signed by UEFI signing service, based on code from "Thu Feb 7 06:56:19 UTC 2013". (forwarded request 155105 from fcrozat)
Stephan Kulow (coolo)
accepted
request 151607
from
Stephan Kulow (coolo)
(revision 7)
- prepare for having a signed shim from the UEFI signing service (forwarded request 151605 from lnussel)
Stephan Kulow (coolo)
accepted
request 151556
from
Gary Ching-Pang Lin (gary_lin)
(revision 6)
- Sign shim-opensuse.efi and MokManager.efi with the openSUSE cert - Add shim-keep-unsigned-mokmanager.patch to keep the unsigned MokManager and sign it later. (forwarded request 151555 from gary_lin)
Stephan Kulow (coolo)
accepted
request 150398
from
Gary Ching-Pang Lin (gary_lin)
(revision 5)
Add shim-mokmanager-support-crypt-hash-method.patch to support password hash from /etc/shadow (FATE#314506) (forwarded request 150394 from gary_lin)
Stephan Kulow (coolo)
accepted
request 150244
from
Gary Ching-Pang Lin (gary_lin)
(revision 4)
- Embed openSUSE-UEFI-CA-Certificate.crt in shim - Rename shim-unsigned.efi to shim-opensuse.efi. (forwarded request 150243 from gary_lin)
Displaying revisions 101 - 120 of 123