Unverified Commit ccc162c6 authored by Sherif Nagy's avatar Sherif Nagy
Browse files

Updating Rocky testing certs and restructuring

parent 4558293d
# TODO
# Check boot*.CVS and how they are created.
patch {
file: "ROCKY/_supporting/shim-15-16-rocky-branding-rpmmacros.patch"
file: "ROCKY/_supporting/0001-Adding-rocky-certs.patch"
}
delete {
......@@ -14,11 +11,11 @@ delete {
}
add {
file: "ROCKY/_supporting/rockylinuxsecurebootcert101test.der"
file: "ROCKY/_supporting/rocky-root-ca.der"
}
add {
file: "ROCKY/_supporting/rockylinuxsecurebootca101test.der"
file: "ROCKY/_supporting/rocky-signing.der"
}
replace {
......@@ -49,24 +46,17 @@ spec_change {
delete: true
}
file {
name: "rockylinuxsecurebootcert101test.der"
type: Source
add: true
}
file {
name: "rockylinuxsecurebootca101test.der"
type: Source
add: true
}
append {
field: "Release"
value: ".rocky"
}
changelog {
author_name: "Sherif Nagy"
author_email: "sherif@disroot.org"
message: "Updating Rocky testing certs and restructuring"
}
changelog {
author_name: "Sherif Nagy"
author_email: "sherif@disroot.org"
......
diff --git a/SOURCES/shim.rpmmacros b/SOURCES/shim.rpmmacros
index ec33c1d..0f0fad9 100644
--- a/SOURCES/shim.rpmmacros
+++ b/SOURCES/shim.rpmmacros
@@ -1,7 +1,7 @@
%global debug_package %{nil}
%global __brp_mangle_shebangs_exclude_from_file %{expand:%{_builddir}/shim-%{efi_arch}-%{version}-%{release}.%{_target_cpu}-shebangs.txt}
%global vendor_token_str %{expand:%%{nil}%%{?vendor_token_name:-t "%{vendor_token_name}"}}
-%global vendor_cert_str %{expand:%%{!?vendor_cert_nickname:-c "Red Hat Test Certificate"}%%{?vendor_cert_nickname:-c "%%{vendor_cert_nickname}"}}
+%global vendor_cert_str %{expand:%%{!?vendor_cert_nickname:-c "Rocky Test Cert - Rocky Enterprise Software Foundation"}%%{?vendor_cert_nickname:-c "%%{vendor_cert_nickname}"}}
%global bootcsvaa64 %{expand:%{SOURCE10}}
%global bootcsvia32 %{expand:%{SOURCE11}}
@@ -90,7 +90,7 @@ version signed by the UEFI signing service. \
# -i <input>
%define distrosign(b:a:d:) \
cp -av %{-d*}/%{-b*}%{-a*}.efi %{-b*}%{-a*}-unsigned.efi \
- %{expand:%%sign -i %{-b*}%{-a*}-unsigned.efi -o %{-b*}%{-a*}-signed.efi -n redhatsecureboot501 -a %{SOURCE2} -c %{SOURCE1} }\
+ %{expand:%%sign -i %{-b*}%{-a*}-unsigned.efi -o %{-b*}%{-a*}-signed.efi -n rockylinuxsecurebootcert101test -a %{SOURCE2} -c %{SOURCE1} }\
%{nil}
# -a <efiarch>
Markdown is supported
0% or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment