[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Changes in fwupd and signing...



Hi again!

On Tue, Nov 02, 2021 at 09:48:16AM +0100, Ansgar wrote:
>Steve McIntyre writes:
>> However, I'm more worried about the effects on our SB signing
>> setup. We'll be moving from the fwupd source package making the
>> fwupd-ARCH-signed-template template package to a new setup. We're
>> planning for the new fwupd-efi source package to take over the
>> fwupd-ARCH-signed-template template package (and so on down the
>> chain). However, I'm not sure that will work OK. Looking at
>> config/debian/external-signatures.conf in DAK, will we be able to have
>> two different source packages building the same binary like this
>> (obviously targeting different releases!) ?
>
>I think that should be fine.  dak checks that the pair (source, binary)
>is whitelisted; having multiple entries for the same binary by different
>source packages should work as is.
>
>The code is question is [1].

Awesome, thanks! :-)

So I *think* we're ready to upload and do the switcheroo. I've filed
#998861 with more details. I hope I's suggesting the right path -
could you take a look please?

Cheers,

Steve

-- 
Steve McIntyre, Cambridge, UK.                                steve@einval.com
"When C++ is your hammer, everything looks like a thumb." -- Steven M. Haflich


Reply to: