create-user-key-store.sh: self-sign KEK and DB

UEFI spec never ask for the fact that KEK must be signed by PK and
DB must be signed by KEK.

Signed-off-by: Lans Zhang <jia.zhang@windriver.com>
This commit is contained in:
Lans Zhang
2017-08-01 10:40:59 +08:00
parent 45748a09ef
commit 7f3143523d
@@ -148,9 +148,9 @@ create_uefi_sb_user_keys() {
ca_sign "$key_dir" PK "$key_dir" PK \ ca_sign "$key_dir" PK "$key_dir" PK \
"/CN=PK Certificate/" "/CN=PK Certificate/"
ca_sign "$key_dir" KEK "$key_dir" PK \ ca_sign "$key_dir" KEK "$key_dir" KEK \
"/CN=KEK Certificate" "/CN=KEK Certificate"
ca_sign "$key_dir" DB "$key_dir" KEK \ ca_sign "$key_dir" DB "$key_dir" DB \
"/CN=DB Certificate" "/CN=DB Certificate"
} }