Revisions of shim

Stephan Kulow's avatar Stephan Kulow (coolo) accepted request 197952 from Gary Ching-Pang Lin's avatar Gary Ching-Pang Lin (gary_lin) (revision 22)
- set timestamp of PE file to time of the binary the signature was
  made for.
- make sure cert.o get's rebuilt for each target

- Update microsoft.asc: shim signed by UEFI signing service, based
  on code from "Wed Aug 28 15:54:38 UTC 2013" (forwarded request 197604 from lnussel)
Stephan Kulow's avatar Stephan Kulow (coolo) accepted request 196741 from Gary Ching-Pang Lin's avatar Gary Ching-Pang Lin (gary_lin) (revision 21)
- always build a shim that embeds the distro's certificate (e.g.
  shim-opensuse.efi). If the package is built in the devel project
  additionally shim-devel.efi is created. That allows us to either
  load grub2/kernel signed by the distro or signed by the devel
  project, depending on use case. Also shim-$distro.efi from the
  devel project can be used to request additional signatures. (forwarded request 196735 from lnussel)
Stephan Kulow's avatar Stephan Kulow (coolo) accepted request 196635 from Gary Ching-Pang Lin's avatar Gary Ching-Pang Lin (gary_lin) (revision 20)
- also include old openSUSE 4096 bit certificate to be able to still
  boot kernels signed with that key.
- add show_signatures script (forwarded request 196609 from lnussel)
Stephan Kulow's avatar Stephan Kulow (coolo) accepted request 196499 from Gary Ching-Pang Lin's avatar Gary Ching-Pang Lin (gary_lin) (revision 19)
- replace the 4096 bit openSUSE UEFI CA certificate with new a
  standard compliant 2048 bit one. (forwarded request 196493 from lnussel)
Tomáš Chvátal's avatar Tomáš Chvátal (scarabeus_factory) accepted request 195856 from Gary Ching-Pang Lin's avatar Gary Ching-Pang Lin (gary_lin) (revision 18)
- fix shell syntax error (forwarded request 195685 from lnussel)
Tomáš Chvátal's avatar Tomáš Chvátal (scarabeus_factory) accepted request 186559 from Gary Ching-Pang Lin's avatar Gary Ching-Pang Lin (gary_lin) (revision 17)
- don't include binary in the sources. Instead package the raw
  signature and attach it during build (bnc#813448). (forwarded request 186534 from lnussel)
Stephan Kulow's avatar Stephan Kulow (coolo) accepted request 185350 from Gary Ching-Pang Lin's avatar Gary Ching-Pang Lin (gary_lin) (revision 16)
- Update shim-mokmanager-ui-revamp.patch to include fixes for
  MokManager
  + reboot the system after clearing MOK password
  + fetch more info from X509 name
  + check the suffix of the key file (forwarded request 185349 from gary_lin)
Stephan Kulow's avatar Stephan Kulow (coolo) accepted request 184040 from Gary Ching-Pang Lin's avatar Gary Ching-Pang Lin (gary_lin) (revision 15)
- Update to 0.4
- Rebase patches
  + shim-suse-build.patch
  + shim-mokmanager-support-crypt-hash-method.patch
  + shim-bnc804631-fix-broken-bootpath.patch
  + shim-bnc798043-no-doulbe-separators.patch
  + shim-bnc807760-change-pxe-2nd-loader-name.patch
  + shim-bnc808106-correct-certcount.patch 
  + shim-mokmanager-ui-revamp.patch
- Add patches
  + shim-merge-lf-loader-code.patch: merge the Linux Foundation
    loader UI code
  + shim-fix-pointer-casting.patch: fix a casting issue and the
    size of an empty vendor cert
  + shim-fix-simple-file-selector.patch: fix the buffer allocation
    in the simple file selector
- Remove upstreamed patches
  + shim-support-mok-delete.patch
  + shim-reboot-after-changes.patch
  + shim-clear-queued-key.patch
  + shim-local-key-sign-mokmanager.patch
  + shim-get-2nd-stage-loader.patch
  + shim-fix-loadoptions.patch
- Remove unused patch: shim-mokmanager-new-pw-hash.patch and
  shim-keep-unsigned-mokmanager.patch
- Install the vendor certificate to /etc/uefi/certs (forwarded request 184039 from gary_lin)
Stephan Kulow's avatar Stephan Kulow (coolo) accepted request 174779 from Gary Ching-Pang Lin's avatar Gary Ching-Pang Lin (gary_lin) (revision 14)
Revamp the MokManager UI (forwarded request 174778 from gary_lin)
Stephan Kulow's avatar Stephan Kulow (coolo) accepted request 162328 from Gary Ching-Pang Lin's avatar Gary Ching-Pang Lin (gary_lin) (revision 13)
bnc#813079: Call update-bootloader in %post to update *.efi in \efi\opensuse (forwarded request 162327 from gary_lin)
Stephan Kulow's avatar Stephan Kulow (coolo) accepted request 157971 from Gary Ching-Pang Lin's avatar Gary Ching-Pang Lin (gary_lin) (revision 12)
bnc#807760: change the PXE 2nd stage loader name
bnc#808106: certificate count of the signature list (forwarded request 157970 from gary_lin)
Stephan Kulow's avatar Stephan Kulow (coolo) accepted request 157343 from Gary Ching-Pang Lin's avatar Gary Ching-Pang Lin (gary_lin) (revision 11)
(bnc#798043#c4) remove double seperators from the bootpath (forwarded request 157208 from gary_lin)
Stephan Kulow's avatar Stephan Kulow (coolo) accepted request 156904 from Gary Ching-Pang Lin's avatar Gary Ching-Pang Lin (gary_lin) (revision 10)
- sign shim also with openSUSE certificate (forwarded request 156849 from lnussel)
Stephan Kulow's avatar Stephan Kulow (coolo) accepted request 156082 from Gary Ching-Pang Lin's avatar Gary Ching-Pang Lin (gary_lin) (revision 9)
bnc#804631: fix the broken bootpath generated in generate_path() (forwarded request 156025 from gary_lin)
Stephan Kulow's avatar Stephan Kulow (coolo) accepted request 155108 from Stephan Kulow's avatar Stephan Kulow (coolo) (revision 8)
- Update with shim signed by UEFI signing service, based on code
  from "Thu Feb  7 06:56:19 UTC 2013". (forwarded request 155105 from fcrozat)
Stephan Kulow's avatar Stephan Kulow (coolo) accepted request 151607 from Stephan Kulow's avatar Stephan Kulow (coolo) (revision 7)
- prepare for having a signed shim from the UEFI signing service (forwarded request 151605 from lnussel)
Stephan Kulow's avatar Stephan Kulow (coolo) accepted request 151556 from Gary Ching-Pang Lin's avatar Gary Ching-Pang Lin (gary_lin) (revision 6)
- Sign shim-opensuse.efi and MokManager.efi with the openSUSE cert
- Add shim-keep-unsigned-mokmanager.patch to keep the unsigned
  MokManager and sign it later. (forwarded request 151555 from gary_lin)
Stephan Kulow's avatar Stephan Kulow (coolo) accepted request 150398 from Gary Ching-Pang Lin's avatar Gary Ching-Pang Lin (gary_lin) (revision 5)
Add shim-mokmanager-support-crypt-hash-method.patch to support password hash from /etc/shadow (FATE#314506) (forwarded request 150394 from gary_lin)
Stephan Kulow's avatar Stephan Kulow (coolo) accepted request 150244 from Gary Ching-Pang Lin's avatar Gary Ching-Pang Lin (gary_lin) (revision 4)
- Embed openSUSE-UEFI-CA-Certificate.crt in shim
- Rename shim-unsigned.efi to shim-opensuse.efi. (forwarded request 150243 from gary_lin)
Displaying revisions 101 - 120 of 123
openSUSE Build Service is sponsored by