[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Please upload signed kernel images at the same time as unsigned ones



On 01/17/2017 02:16 PM, Julien Aubin wrote:
> Hi,
> 
> Signed linux kernel images tend to become the default as package
> linux-latest is updated when linux-signed is updated.
> 
> The problem is that when there are security fixes like the ones for
> kernel 4.8.x the unsigned images are pushed well before signed images,
> putting most of the users (w/ default config) at security risk.
> 
> So could you please publish both signed and unsigned kernels at the same
> time ? (As of now 4.8.15)
> 
That would be hard, seeing how that would mean signing content before
that content even exists.

Cheers,
Julien


Reply to: