Comment 12 for bug 1928434

Revision history for this message
Julian Andres Klode (juliank) wrote :

This is trying to mirror our insanely large MokListX to MokListXRT, which is so large due to COVID related travel restrictions preventing the generation of a new signing key, and having to revoke all binaries this way instead.

However, we do not actually need to mirror that list AFAIUI, because the kernel, which would consume the list, does not actually support revoking binaries by hash (and it can kexec kernels, but not the grubs we worry about).

On other platforms, this just causes a warning followed by a 10s wait.