diff options
author | Lans Zhang <jia.zhang@windriver.com> | 2017-08-01 10:40:59 +0800 |
---|---|---|
committer | Lans Zhang <jia.zhang@windriver.com> | 2017-08-01 10:40:59 +0800 |
commit | 7f3143523d107826a92a500455531cfe5da03422 (patch) | |
tree | 01ec22890f7bc9ea950779c30a99985d8f8732cb | |
parent | 45748a09ef9e1435e8834c720763ff80cae80f08 (diff) | |
download | meta-secure-core-7f3143523d107826a92a500455531cfe5da03422.tar.gz |
create-user-key-store.sh: self-sign KEK and DB
UEFI spec never ask for the fact that KEK must be signed by PK and
DB must be signed by KEK.
Signed-off-by: Lans Zhang <jia.zhang@windriver.com>
-rwxr-xr-x | meta-signing-key/scripts/create-user-key-store.sh | 4 |
1 files changed, 2 insertions, 2 deletions
diff --git a/meta-signing-key/scripts/create-user-key-store.sh b/meta-signing-key/scripts/create-user-key-store.sh index dea4fa6..e5f754a 100755 --- a/meta-signing-key/scripts/create-user-key-store.sh +++ b/meta-signing-key/scripts/create-user-key-store.sh | |||
@@ -148,9 +148,9 @@ create_uefi_sb_user_keys() { | |||
148 | 148 | ||
149 | ca_sign "$key_dir" PK "$key_dir" PK \ | 149 | ca_sign "$key_dir" PK "$key_dir" PK \ |
150 | "/CN=PK Certificate/" | 150 | "/CN=PK Certificate/" |
151 | ca_sign "$key_dir" KEK "$key_dir" PK \ | 151 | ca_sign "$key_dir" KEK "$key_dir" KEK \ |
152 | "/CN=KEK Certificate" | 152 | "/CN=KEK Certificate" |
153 | ca_sign "$key_dir" DB "$key_dir" KEK \ | 153 | ca_sign "$key_dir" DB "$key_dir" DB \ |
154 | "/CN=DB Certificate" | 154 | "/CN=DB Certificate" |
155 | } | 155 | } |
156 | 156 | ||