Please provide dual-signed shim chained to both MS & Canonical certificates

Bug #1884566 reported by Dimitri John Ledkov
14
This bug affects 1 person
Affects Status Importance Assigned to Milestone
shim-signed (Ubuntu)
Fix Released
High
Unassigned

Bug Description

Please provide dual-signed shim chained to both MS & Canonical certificates

Implementation provided as:
 - shim-canonical => to submit shim for signing (ideally this portion of code should be merged into the src:shim package, when we rebuild it from scratch next)

 - shim-signed => to construct dual-signed shim

This also makes it easier to test shim uploads, as a PPA built of shim-canonical, produces signed shim, for which one can import a certificate and use straight away.

See:
https://code.launchpad.net/~xnox/ubuntu/+source/shim-signed/+git/shim-signed/+merge/386190

https://launchpad.net/ubuntu/groovy/+queue?queue_state=0&queue_text=shim-canonical

This work is required for UC20 1.0 release

Tags: uc20
information type: Public → Private Security
information type: Private Security → Public Security
Steve Langasek (vorlon)
information type: Public Security → Public
Revision history for this message
Steve Langasek (vorlon) wrote :

Regarding shim-canonical, this looks to me like it should be a one-off, and future signing requests should be done through the shim package itself. Can you raise an MP for that?

Also, is it really the Ubuntu online signing key that you want to be signing this shim, and not the UC20 online signing key?

Revision history for this message
Dimitri John Ledkov (xnox) wrote :

Will raise the MP for the shim.

I want it with both keys, both in the archive with Ubuntu key; and in UC20 with UC20 key. For example openSUSE/SUSE are providing that, and I would like us be on par.

Once this is in the shim package it will be useful for testing, and also very useful for UEFI VMs deployed with Openstack, Maas, LXD, multipass.

Changed in shim-signed (Ubuntu):
status: New → Incomplete
Changed in shim-signed (Ubuntu):
status: Incomplete → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.