Hey folks.
Just a heads up that I have migrated sigul to the new 1.2 version with rhel9 vault/bridge.
Please let me know if you see any signing issues in the coming days. It seems to be processing as expected, so hopefully everything will be transparent to everyone, and look for some nice improvements to hopefully be enabled in coming weeks.
See: https://pagure.io/fedora-infrastructure/issue/11505 for more info.
kevin
Kevin,
Awesome. Once we sort out how we are going to support [releng] Issue #10765 (systemd-boot signing) will this upgrade enable us to consider signing things like memtest?
- Jon
On Fri, Apr 26, 2024 at 2:55 PM Kevin Fenzi kevin@scrye.com wrote:
Hey folks.
Just a heads up that I have migrated sigul to the new 1.2 version with rhel9 vault/bridge.
Please let me know if you see any signing issues in the coming days. It seems to be processing as expected, so hopefully everything will be transparent to everyone, and look for some nice improvements to hopefully be enabled in coming weeks.
See: https://pagure.io/fedora-infrastructure/issue/11505 for more info.
kevin
infrastructure mailing list -- infrastructure@lists.fedoraproject.org To unsubscribe send an email to infrastructure-leave@lists.fedoraproject.org Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/infrastructure@lists.fedorapro... Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue
On Fri, 26 Apr 2024 at 22:06, Jonathan Steffan jonathansteffan@gmail.com wrote:
Kevin,
Awesome. Once we sort out how we are going to support [releng] Issue #10765 (systemd-boot signing) will this upgrade enable us to consider signing things like memtest?
The new version has initial support for signing PE artifacts, I believe it likely needs a bit more work.
- Jon
On Fri, Apr 26, 2024 at 2:55 PM Kevin Fenzi kevin@scrye.com wrote:
Hey folks.
Just a heads up that I have migrated sigul to the new 1.2 version with rhel9 vault/bridge.
Please let me know if you see any signing issues in the coming days. It seems to be processing as expected, so hopefully everything will be transparent to everyone, and look for some nice improvements to hopefully be enabled in coming weeks.
See: https://pagure.io/fedora-infrastructure/issue/11505 for more info.
kevin
infrastructure mailing list -- infrastructure@lists.fedoraproject.org To unsubscribe send an email to infrastructure-leave@lists.fedoraproject.org Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/infrastructure@lists.fedorapro... Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue
-- Jonathan Steffan -- _______________________________________________ infrastructure mailing list -- infrastructure@lists.fedoraproject.org To unsubscribe send an email to infrastructure-leave@lists.fedoraproject.org Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/infrastructure@lists.fedorapro... Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue
On Sat, Apr 27, 2024 at 04:42:50PM GMT, Peter Robinson wrote:
On Fri, 26 Apr 2024 at 22:06, Jonathan Steffan jonathansteffan@gmail.com wrote:
Kevin,
Awesome. Once we sort out how we are going to support [releng] Issue #10765 (systemd-boot signing) will this upgrade enable us to consider signing things like memtest?
The new version has initial support for signing PE artifacts, I believe it likely needs a bit more work.
yeah.
I am not familliar with how memtest currently works... is it an efi app thats directly booted by firmware? Or does it follow the shim -> grub2 -> path?
kevin
On Mon, Apr 29, 2024 at 10:11 AM Kevin Fenzi kevin@scrye.com wrote:
yeah.
I am not familliar with how memtest currently works... is it an efi app thats directly booted by firmware? Or does it follow the shim -> grub2 -> path?
We can boot memtest86+ both directly from the firmware or via shim -> grub2. Right now, I have the package installing a BLS through a kernel-install plugin. It currently is taking the shim -> grub2 path and I planned on adding sd-boot support once that stuff stabilizes and is available via the installer (anaconda). To be able to run it, you have to disable secureboot.
infrastructure@lists.fedoraproject.org