This bug was fixed in the package sbsigntool - 0.9.2-2ubuntu1~18.04.2
---
sbsigntool (0.9.2-2ubuntu1~18.04.2) bionic; urgency=medium
* Enable signing riscv64 EFI binaries (LP: #1964510)
-- Heinrich Schuchardt Thu, 10 Mar
2022 20:41:04 +0100
** Changed in: sbsigntool (Ubuntu
This bug was fixed in the package sbsigntool - 0.9.2-2ubuntu1.1
---
sbsigntool (0.9.2-2ubuntu1.1) focal; urgency=medium
* Enable signing riscv64 EFI binaries (LP: #1964510)
-- Heinrich Schuchardt Thu, 10 Mar
2022 20:41:04 +0100
** Changed in: sbsigntool (Ubuntu Focal)
root@ethical-catfish:~# dpkg-query -W sbsigntool
sbsigntool 0.9.2-2ubuntu1~18.04.2
root@ethical-catfish:~# sbverify --cert db.crt test-arm64.efi.signed
warning: data remaining[5112 vs 6104]: gaps between PE/COFF sections?
Signature verification OK
root@ethical-catfish:~# sbverify --cert
# dpkg-query -W sbsigntool
sbsigntool 0.9.2-2ubuntu1.1
# sbverify --cert ./db.crt test-arm64.efi.signed
warning: data remaining[5112 vs 6104]: gaps between PE/COFF sections?
Signature verification OK
# sbverify --cert ./db.crt test-riscv64.efi.signed
warning: data remaining[5112 vs
Hello Heinrich, or anyone else affected,
Accepted sbsigntool into focal-proposed. The package will build now and
be available at
https://launchpad.net/ubuntu/+source/sbsigntool/0.9.2-2ubuntu1.1 in a
few hours, and then in the -proposed repository.
Please help us by testing this new package. See
** Attachment added: "test-riscv64.efi"
https://bugs.launchpad.net/ubuntu/+source/sbsigntool/+bug/1964510/+attachment/5586224/+files/test-riscv64.efi
--
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
I just added an arm64 and a riscv64 EFI binary for testing. These are
just the helloworld.efi files produced by building U-Boot for qemu-
riscv64_defconfig and qemu_arm64_defconfig.
--
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
** Attachment added: "test-arm64.efi"
https://bugs.launchpad.net/ubuntu/+source/sbsigntool/+bug/1964510/+attachment/5586223/+files/test-arm64.efi
--
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
Note that the version number in the focal diff is wrong; focal already
has 0.9.2-2ubuntu1, so needs to have a version number that sorts later
than this such as 0.9.2-2ubuntu1.1.
https://wiki.ubuntu.com/SecurityTeam/UpdatePreparation#Update_the_packaging
provides recommendations for the version
Please include in the test case a pointer to a specific riscv64 EFI
binary that should be used for testing.
** Changed in: sbsigntool (Ubuntu Bionic)
Status: Confirmed => Incomplete
--
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to
** Patch added: "sbsigntool_0.9.2-2ubuntu1~20.04.1.debdiff"
https://bugs.launchpad.net/ubuntu/+source/sbsigntool/+bug/1964510/+attachment/5567907/+files/sbsigntool_0.9.2-2ubuntu1~20.04.1.debdiff
** Changed in: sbsigntool (Ubuntu Bionic)
Status: Triaged => Confirmed
** Changed in:
https://bugs.launchpad.net/ubuntu/+source/sbsigntool/+bug/1964519 has
the corresponding debdiff for focal; I've consolidated these into a
single bug with two open tasks.
(https://bugs.launchpad.net/ubuntu/+source/sbsigntool/+bug/1938438 added
the support to impish.)
** Also affects: sbsigntool
To verify use:
sbverify --cert db.crt test.efi.signed
** Patch added: "sbsigntool-0.9.2-2ubuntu1~18.04.2.debdiff"
https://bugs.launchpad.net/ubuntu/+source/sbsigntool/+bug/1964510/+attachment/5567798/+files/sbsigntool-0.9.2-2ubuntu1~18.04.2.debdiff
** Changed in: sbsigntool (Ubuntu)
13 matches
Mail list logo