On Fri, Apr 23, 2021 at 08:07:50AM +0200, Michael Olbrich wrote: > On Mon, Apr 12, 2021 at 06:18:59PM +0200, Marc Kleine-Budde wrote: > > This patch converts barebox and the barebox template to make use of code > > signing groups as introduced in the previous patch. > > > > Signed-off-by: Marc Kleine-Budde <[email protected]> > > --- > > .../ptxdist-set-keys-hsm.sh | 6 ++- > > .../templates/template-barebox-imx-habv4-make | 2 +- > > scripts/lib/ptxd_lib_imx_hab.sh | 44 ++++++++++++++----- > > 3 files changed, 39 insertions(+), 13 deletions(-) > > > > diff --git a/rules/templates/code-signing-provider/ptxdist-set-keys-hsm.sh > > b/rules/templates/code-signing-provider/ptxdist-set-keys-hsm.sh > > index bcd531d69572..b94eff049eac 100755 > > --- a/rules/templates/code-signing-provider/ptxdist-set-keys-hsm.sh > > +++ b/rules/templates/code-signing-provider/ptxdist-set-keys-hsm.sh > > @@ -18,7 +18,7 @@ set_rauc_keys() { > > } > > > > set_imx_habv4_keys() { > > - local r > > + local r g > > > > # HSM use case, assuming it contains only 1st CSF/IMG key > > for i in 1 2 3 4; do > > @@ -28,6 +28,10 @@ set_imx_habv4_keys() { > > cs_append_ca_from_uri "${r}" > > done > > > > + g="imx-habv4-srk" > > + cs_define_group "${g}" > > + cs_group_add_roles "${g}" "imx-habv4-srk1" "imx-habv4-srk2" > > "imx-habv4-srk3" "imx-habv4-srk4" > > + > > r="imx-habv4-csf1" > > cs_define_role ${r} > > cs_set_uri "${r}" "pkcs11:token=foo;object=csf1" > > diff --git a/rules/templates/template-barebox-imx-habv4-make > > b/rules/templates/template-barebox-imx-habv4-make > > index eb752c8349d9..cc825dc90292 100644 > > --- a/rules/templates/template-barebox-imx-habv4-make > > +++ b/rules/templates/template-barebox-imx-habv4-make > > @@ -74,7 +74,7 @@ $(STATEDIR)/barebox-@[email protected]: > > @$(call targetinfo) > > > > @$(call world/env, BAREBOX_@PACKAGE@) \ > > - ptxd_make_imx_habv4_gen_table "imx-habv4-srk%d" 4 > > + ptxd_make_imx_habv4_gen_table imx-habv4-srk > > For this to work with the devel provider, host-ptx-code-signing-dev must be > updated to create this group. I needs the same changes that you made to the > code-signing-provider template above, right? > Can you please add that and provide a new version for the PTXdist package?
And could you also add a bit of trivial documentation to doc/dev_code_signing.rst so people see that it exists? - Roland -- Roland Hieber, Pengutronix e.K. | [email protected] | Steuerwalder Str. 21 | https://www.pengutronix.de/ | 31137 Hildesheim, Germany | Phone: +49-5121-206917-0 | Amtsgericht Hildesheim, HRA 2686 | Fax: +49-5121-206917-5555 | _______________________________________________ ptxdist mailing list [email protected] To unsubscribe, send a mail with subject "unsubscribe" to [email protected]
