summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorLans Zhang <jia.zhang@windriver.com>2017-08-01 10:40:59 +0800
committerLans Zhang <jia.zhang@windriver.com>2017-08-01 10:40:59 +0800
commit7f3143523d107826a92a500455531cfe5da03422 (patch)
tree01ec22890f7bc9ea950779c30a99985d8f8732cb
parent45748a09ef9e1435e8834c720763ff80cae80f08 (diff)
downloadmeta-secure-core-7f3143523d107826a92a500455531cfe5da03422.tar.gz
create-user-key-store.sh: self-sign KEK and DB
UEFI spec never ask for the fact that KEK must be signed by PK and DB must be signed by KEK. Signed-off-by: Lans Zhang <jia.zhang@windriver.com>
-rwxr-xr-xmeta-signing-key/scripts/create-user-key-store.sh4
1 files changed, 2 insertions, 2 deletions
diff --git a/meta-signing-key/scripts/create-user-key-store.sh b/meta-signing-key/scripts/create-user-key-store.sh
index dea4fa6..e5f754a 100755
--- a/meta-signing-key/scripts/create-user-key-store.sh
+++ b/meta-signing-key/scripts/create-user-key-store.sh
@@ -148,9 +148,9 @@ create_uefi_sb_user_keys() {
148 148
149 ca_sign "$key_dir" PK "$key_dir" PK \ 149 ca_sign "$key_dir" PK "$key_dir" PK \
150 "/CN=PK Certificate/" 150 "/CN=PK Certificate/"
151 ca_sign "$key_dir" KEK "$key_dir" PK \ 151 ca_sign "$key_dir" KEK "$key_dir" KEK \
152 "/CN=KEK Certificate" 152 "/CN=KEK Certificate"
153 ca_sign "$key_dir" DB "$key_dir" KEK \ 153 ca_sign "$key_dir" DB "$key_dir" DB \
154 "/CN=DB Certificate" 154 "/CN=DB Certificate"
155} 155}
156 156