Re: verified boot: semantics of multiple required keys

2020-01-29 Thread Simon Glass
Hi Rasmus, On Thu, 16 Jan 2020 at 03:52, Rasmus Villemoes wrote: > > Hi > > I'm wondering a bit about the semantics of having multiple keys with the > 'required = "conf"' property. Currently, the fit image (or rather the > chosen configuration) must be signed by all such keys. I assume this is >

verified boot: semantics of multiple required keys

2020-01-16 Thread Rasmus Villemoes
Hi I'm wondering a bit about the semantics of having multiple keys with the 'required = "conf"' property. Currently, the fit image (or rather the chosen configuration) must be signed by all such keys. I assume this is for the case where multiple parties (vendor, subvendor, customer?) all have to s