mirror of
https://github.com/jiazhang0/meta-secure-core.git
synced 2026-05-07 02:08:20 +00:00
create-user-key-store.sh: self-sign KEK and DB
UEFI spec never ask for the fact that KEK must be signed by PK and DB must be signed by KEK. Signed-off-by: Lans Zhang <jia.zhang@windriver.com>
This commit is contained in:
@@ -148,9 +148,9 @@ create_uefi_sb_user_keys() {
|
|||||||
|
|
||||||
ca_sign "$key_dir" PK "$key_dir" PK \
|
ca_sign "$key_dir" PK "$key_dir" PK \
|
||||||
"/CN=PK Certificate/"
|
"/CN=PK Certificate/"
|
||||||
ca_sign "$key_dir" KEK "$key_dir" PK \
|
ca_sign "$key_dir" KEK "$key_dir" KEK \
|
||||||
"/CN=KEK Certificate"
|
"/CN=KEK Certificate"
|
||||||
ca_sign "$key_dir" DB "$key_dir" KEK \
|
ca_sign "$key_dir" DB "$key_dir" DB \
|
||||||
"/CN=DB Certificate"
|
"/CN=DB Certificate"
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user