[Kernel-packages] [Bug 1829749] Re: Please add support for zipl signing
s390-tools in UNAPPROVED https://launchpad.net/ubuntu/eoan/+queue?queue_state=1&queue_text=s390-tools s390-tools-signed in source NEW https://launchpad.net/ubuntu/eoan/+queue?queue_state=0&queue_text=s390-tools-signed ** Summary changed: - Please add support for zipl signing + Please add support for sipl -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux-signed in Ubuntu. https://bugs.launchpad.net/bugs/1829749 Title: Please add support for sipl Status in Launchpad itself: Fix Released Status in linux-signed package in Ubuntu: New Status in s390-tools package in Ubuntu: Fix Committed Bug description: Please add support for zipl ("z/ecureBoot") signing. It should be similar to opal signing, but using the new zipl signing key. I am expecting to sign s390-tools stage3.bin and kernel images using this key. s390-tools -> can be signed already kernels -> should only sign v5.2+ To manage notifications about this bug go to: https://bugs.launchpad.net/launchpad/+bug/1829749/+subscriptions -- Mailing list: https://launchpad.net/~kernel-packages Post to : kernel-packages@lists.launchpad.net Unsubscribe : https://launchpad.net/~kernel-packages More help : https://help.launchpad.net/ListHelp
[Kernel-packages] [Bug 1829749] Re: Please add support for zipl signing
** Changed in: s390-tools (Ubuntu) Status: In Progress => Fix Committed -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux-signed in Ubuntu. https://bugs.launchpad.net/bugs/1829749 Title: Please add support for zipl signing Status in Launchpad itself: Fix Released Status in linux-signed package in Ubuntu: New Status in s390-tools package in Ubuntu: Fix Committed Bug description: Please add support for zipl ("z/ecureBoot") signing. It should be similar to opal signing, but using the new zipl signing key. I am expecting to sign s390-tools stage3.bin and kernel images using this key. s390-tools -> can be signed already kernels -> should only sign v5.2+ To manage notifications about this bug go to: https://bugs.launchpad.net/launchpad/+bug/1829749/+subscriptions -- Mailing list: https://launchpad.net/~kernel-packages Post to : kernel-packages@lists.launchpad.net Unsubscribe : https://launchpad.net/~kernel-packages More help : https://help.launchpad.net/ListHelp
[Kernel-packages] [Bug 1829749] Re: Please add support for zipl signing
** Changed in: launchpad Status: Fix Committed => Fix Released -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux-signed in Ubuntu. https://bugs.launchpad.net/bugs/1829749 Title: Please add support for zipl signing Status in Launchpad itself: Fix Released Status in linux-signed package in Ubuntu: New Status in s390-tools package in Ubuntu: In Progress Bug description: Please add support for zipl ("z/ecureBoot") signing. It should be similar to opal signing, but using the new zipl signing key. I am expecting to sign s390-tools stage3.bin and kernel images using this key. s390-tools -> can be signed already kernels -> should only sign v5.2+ To manage notifications about this bug go to: https://bugs.launchpad.net/launchpad/+bug/1829749/+subscriptions -- Mailing list: https://launchpad.net/~kernel-packages Post to : kernel-packages@lists.launchpad.net Unsubscribe : https://launchpad.net/~kernel-packages More help : https://help.launchpad.net/ListHelp
[Kernel-packages] [Bug 1829749] Re: Please add support for zipl signing
tested s390-tools packages on dogfood which look correct. ** Changed in: s390-tools (Ubuntu) Status: New => In Progress -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux-signed in Ubuntu. https://bugs.launchpad.net/bugs/1829749 Title: Please add support for zipl signing Status in Launchpad itself: Fix Committed Status in linux-signed package in Ubuntu: New Status in s390-tools package in Ubuntu: In Progress Bug description: Please add support for zipl ("z/ecureBoot") signing. It should be similar to opal signing, but using the new zipl signing key. I am expecting to sign s390-tools stage3.bin and kernel images using this key. s390-tools -> can be signed already kernels -> should only sign v5.2+ To manage notifications about this bug go to: https://bugs.launchpad.net/launchpad/+bug/1829749/+subscriptions -- Mailing list: https://launchpad.net/~kernel-packages Post to : kernel-packages@lists.launchpad.net Unsubscribe : https://launchpad.net/~kernel-packages More help : https://help.launchpad.net/ListHelp
[Kernel-packages] [Bug 1829749] Re: Please add support for zipl signing
Worked with ~cjwatson to add Secure Initial Program Load signing to launchpad. Changes deployed to dogfood and test packages uploaded. This results in a vmlinuz.sipl gaining a vmlinuz.sipl.sig, and an appropriate control/sipl.x509 file. The signed binary validates correctly using the public key. Looks good. -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux-signed in Ubuntu. https://bugs.launchpad.net/bugs/1829749 Title: Please add support for zipl signing Status in Launchpad itself: Fix Committed Status in linux-signed package in Ubuntu: New Status in s390-tools package in Ubuntu: New Bug description: Please add support for zipl ("z/ecureBoot") signing. It should be similar to opal signing, but using the new zipl signing key. I am expecting to sign s390-tools stage3.bin and kernel images using this key. s390-tools -> can be signed already kernels -> should only sign v5.2+ To manage notifications about this bug go to: https://bugs.launchpad.net/launchpad/+bug/1829749/+subscriptions -- Mailing list: https://launchpad.net/~kernel-packages Post to : kernel-packages@lists.launchpad.net Unsubscribe : https://launchpad.net/~kernel-packages More help : https://help.launchpad.net/ListHelp
[Kernel-packages] [Bug 1829749] Re: Please add support for zipl signing
** Changed in: launchpad Importance: Undecided => High ** Changed in: launchpad Status: New => Fix Committed ** Changed in: launchpad Assignee: (unassigned) => Andy Whitcroft (apw) ** Branch linked: lp:~apw/launchpad/signing-sipl -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux-signed in Ubuntu. https://bugs.launchpad.net/bugs/1829749 Title: Please add support for zipl signing Status in Launchpad itself: Fix Committed Status in linux-signed package in Ubuntu: New Status in s390-tools package in Ubuntu: New Bug description: Please add support for zipl ("z/ecureBoot") signing. It should be similar to opal signing, but using the new zipl signing key. I am expecting to sign s390-tools stage3.bin and kernel images using this key. s390-tools -> can be signed already kernels -> should only sign v5.2+ To manage notifications about this bug go to: https://bugs.launchpad.net/launchpad/+bug/1829749/+subscriptions -- Mailing list: https://launchpad.net/~kernel-packages Post to : kernel-packages@lists.launchpad.net Unsubscribe : https://launchpad.net/~kernel-packages More help : https://help.launchpad.net/ListHelp
[Kernel-packages] [Bug 1829749] Re: Please add support for zipl signing
I do wonder, if we can somehow arch-specify opal signing. Cause it's opal for power, zipl for s390x, yet both just use kmodsign. Just a different key. Not sure if i want to copy&paste all the methods, and tests. -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux-signed in Ubuntu. https://bugs.launchpad.net/bugs/1829749 Title: Please add support for zipl signing Status in Launchpad itself: New Status in linux-signed package in Ubuntu: New Status in s390-tools package in Ubuntu: New Bug description: Please add support for zipl ("z/ecureBoot") signing. It should be similar to opal signing, but using the new zipl signing key. I am expecting to sign s390-tools stage3.bin and kernel images using this key. s390-tools -> can be signed already kernels -> should only sign v5.2+ To manage notifications about this bug go to: https://bugs.launchpad.net/launchpad/+bug/1829749/+subscriptions -- Mailing list: https://launchpad.net/~kernel-packages Post to : kernel-packages@lists.launchpad.net Unsubscribe : https://launchpad.net/~kernel-packages More help : https://help.launchpad.net/ListHelp