Thanks, applied as f1fc06cd534092bd1a4ae84917ecfc33d5ddb2c2.

Michael

[sent from post-receive hook]

On Tue, 20 Jul 2021 13:48:40 +0200, Roland Hieber <[email protected]> wrote:
> Existing barebox-imx-habv4 recipes can still use the indexed
> 'imx-habv4-srk%d ' roles to fetch the SRK keys, but for compatibility
> with HSM use cases that don't supported indexed role names, set up a new
> role group that contains the roles.
> 
> Signed-off-by: Marc Kleine-Budde <[email protected]>
> Signed-off-by: Roland Hieber <[email protected]>
> Message-Id: <[email protected]>
> Signed-off-by: Michael Olbrich <[email protected]>
> 
> diff --git a/rules/templates/code-signing-provider/ptxdist-set-keys-hsm.sh 
> b/rules/templates/code-signing-provider/ptxdist-set-keys-hsm.sh
> index bcd531d69572..b94eff049eac 100755
> --- a/rules/templates/code-signing-provider/ptxdist-set-keys-hsm.sh
> +++ b/rules/templates/code-signing-provider/ptxdist-set-keys-hsm.sh
> @@ -18,7 +18,7 @@ set_rauc_keys() {
>  }
>  
>  set_imx_habv4_keys() {
> -     local r
> +     local r g
>  
>       # HSM use case, assuming it contains only 1st CSF/IMG key
>       for i in 1 2 3 4; do
> @@ -28,6 +28,10 @@ set_imx_habv4_keys() {
>               cs_append_ca_from_uri "${r}"
>       done
>  
> +     g="imx-habv4-srk"
> +     cs_define_group "${g}"
> +     cs_group_add_roles "${g}" "imx-habv4-srk1" "imx-habv4-srk2" 
> "imx-habv4-srk3" "imx-habv4-srk4"
> +
>       r="imx-habv4-csf1"
>       cs_define_role ${r}
>       cs_set_uri "${r}" "pkcs11:token=foo;object=csf1"

_______________________________________________
ptxdist mailing list
[email protected]
To unsubscribe, send a mail with subject "unsubscribe" to 
[email protected]

Reply via email to