From 0b261033bdce1c4bf5e2f50c17976e1a85f7d6cd Mon Sep 17 00:00:00 2001 From: Karanbir Singh Date: Jun 24 2014 00:36:26 +0000 Subject: Patch in CentOS SecureBoot keys --- diff --git a/SOURCES/centos.cer b/SOURCES/centos.cer new file mode 100644 index 0000000..00a5580 Binary files /dev/null and b/SOURCES/centos.cer differ diff --git a/SOURCES/secureboot.cer b/SOURCES/secureboot.cer deleted file mode 100644 index 4ff8b79..0000000 Binary files a/SOURCES/secureboot.cer and /dev/null differ diff --git a/SOURCES/securebootca.cer b/SOURCES/securebootca.cer deleted file mode 100644 index b235400..0000000 Binary files a/SOURCES/securebootca.cer and /dev/null differ diff --git a/SPECS/kernel.spec b/SPECS/kernel.spec index 9c791f5..70e9473 100644 --- a/SPECS/kernel.spec +++ b/SPECS/kernel.spec @@ -338,8 +338,7 @@ Source10: sign-modules %define modsign_cmd %{SOURCE10} Source11: x509.genkey Source12: extra_certificates -Source13: securebootca.cer -Source14: secureboot.cer +Source13: centos.cer Source15: rheldup3.x509 Source16: rhelkpatch1.x509 @@ -828,7 +827,7 @@ BuildKernel() { fi # EFI SecureBoot signing, x86_64-only %ifarch x86_64 - %pesign -s -i $KernelImage -o $KernelImage.signed -a %{SOURCE13} -c %{SOURCE14} -n redhatsecureboot301 + %pesign -s -i $KernelImage -o $KernelImage.signed -a %{SOURCE13} -c %{SOURCE13} -n redhatsecureboot301 mv $KernelImage.signed $KernelImage %endif $CopyKernel $KernelImage $RPM_BUILD_ROOT/%{image_install_path}/$InstallName-$KernelVer @@ -1473,6 +1472,10 @@ fi %kernel_variant_files %{with_kdump} kdump %changelog +* Tue Jun 24 2014 Karanbir Singh [3.10.0-123.1.2.el7.centos] +- Patch in CentOS SecureBoot certs +- Add in debranding patches + * Wed Jun 4 2014 Phillip Lougher [3.10.0-123.1.2.el7] - [tty] n_tty: Fix n_tty_write crash when echoing in raw mode (Aristeu Rozanski) [1094241 1094242] {CVE-2014-0196}