From dd042e76cef194b66ae1c042b1ee91ec8f124095 Mon Sep 17 00:00:00 2001 From: Andrew Lukoshko Date: Wed, 18 Mar 2026 10:32:25 +0000 Subject: [PATCH] Update config for c10 spec: use system-sb-certs instead of bundled certs The c10 spec no longer bundles Red Hat cert files as Source300-503. It uses system-sb-certs with sb_ca/sb_cer/sb_key macros and CentOS/RHEL conditionals. Update actions to replace the conditionals with AlmaLinux values and remove bundled cert files. --- config.yaml | 54 +++++++++++-------------------- files/almalinuxsecureboot0.cer | Bin 999 -> 0 bytes files/almalinuxsecurebootca0.cer | Bin 970 -> 0 bytes 3 files changed, 19 insertions(+), 35 deletions(-) delete mode 100644 files/almalinuxsecureboot0.cer delete mode 100644 files/almalinuxsecurebootca0.cer diff --git a/config.yaml b/config.yaml index 769fae0..497ffaa 100644 --- a/config.yaml +++ b/config.yaml @@ -3,29 +3,6 @@ actions: - suffix: ".alma.1" enabled: true - - add_files: - - type: "source" - name: "almalinuxsecurebootca0.cer" - number: 300 - - type: "source" - name: "almalinuxsecureboot0.cer" - number: 301 - - - delete_files: - - file_name: "redhatsecurebootca3.cer" - - file_name: "redhatsecureboot301.cer" - - file_name: "redhatsecurebootca5.cer" - - file_name: "redhatsecureboot503.cer" - - - delete_line: - - target: "spec" - lines: - - | - Source300: redhatsecurebootca3.cer - Source301: redhatsecureboot301.cer - Source500: redhatsecurebootca5.cer - Source503: redhatsecureboot503.cer - - replace: - target: "spec" find: "%global debug_package %{nil}" @@ -33,27 +10,34 @@ actions: %global efi_vendor almalinux %global efidir almalinux %global efi_esp_dir /boot/efi/EFI/%{efidir} - + %global debug_package %{nil} count: 1 - target: "spec" find: | - -Defi_sbat_distro_id="fedora" \ - -Defi_sbat_distro_summary="The Fedora Project" \ + %if 0%{?centos} + %define sb_key centossecureboot202 + %else + %define sb_key redhatsecureboot802 + %endif replace: | - -Defi_sbat_distro_id="almalinux" \ - -Defi_sbat_distro_summary="AlmaLinux" \ - count: 1 - - target: "spec" - find: "-Defi_sbat_distro_url=\"https://src.fedoraproject.org/rpms/%{name}\"" - replace: "-Defi_sbat_distro_url=\"https://git.almalinux.org/rpms/%{name}\"" + %define sb_key almalinuxsecureboot0 count: 1 - target: "spec" find: | - %pesign -s -i %{fwup_efi_fn} -o %{fwup_efi_fn}.tmp -a %{SOURCE300} -c %{SOURCE301} -n redhatsecureboot301 - %pesign -s -i %{fwup_efi_fn}.tmp -o %{fwup_efi_fn}.signed -a %{SOURCE500} -c %{SOURCE503} -n redhatsecureboot503 + %if 0%{?centos} + -Defi_sbat_distro_id="centos" \ + -Defi_sbat_distro_summary="The Fedora Project" \ + -Defi_sbat_distro_url="https://www.centos.org/" \ + %else + -Defi_sbat_distro_id="rhel" \ + -Defi_sbat_distro_summary="Red Hat Enterprise Linux" \ + -Defi_sbat_distro_url="mailto:secalert@redhat.com" \ + %endif replace: | - %pesign -s -i %{fwup_efi_fn} -o %{fwup_efi_fn}.signed -a %{SOURCE300} -c %{SOURCE301} -n almalinuxsecureboot0 + -Defi_sbat_distro_id="almalinux" \ + -Defi_sbat_distro_summary="AlmaLinux" \ + -Defi_sbat_distro_url="https://git.almalinux.org/rpms/%{name}" \ count: 1 - changelog_entry: diff --git a/files/almalinuxsecureboot0.cer b/files/almalinuxsecureboot0.cer deleted file mode 100644 index e6bb9db458dcdd38c1d601a5160ce8464ad028e0..0000000000000000000000000000000000000000 GIT binary patch literal 0 HcmV?d00001 literal 999 zcmXqLVt#DU#B_QAGZP~dlSq=$x3`I_j%l#2FGy70?o}0&^C`xFmyJ`a&7`|WU>24@s0aobma5>CpI@Tj>}Vh-&TC|9U~Ft?Xklb& zVh|5{Q*3?l-?gr~{?8kbg0b5t?lBx5kIj7}g65w>>_kj-vx$A0zuP(QmrG2u2oc z48%ZuRS=)YfQyYon~jl`m7ST{Ko%s<$0Eie@_$b83%6N8)15EgoM>+NBkWY&gl=$> zkyU1qFc51HIoS8|=e1RqCd=#0HZEQp>z27>$v)(`0j5`A+%Ph@OKKIL-ult%`<1Av z5-(2v5nVsM&G$=Ot(U)hQd!P8?3PlTo-)sPC%) z%GRv~6F;VMvx!~hPrProZ&#m`UU0&*YmVC)`!Achh~HyQ{q4DbyFt~aQ_2ejlC}W= DeSwFp diff --git a/files/almalinuxsecurebootca0.cer b/files/almalinuxsecurebootca0.cer deleted file mode 100644 index d086cd53c500ca15c889ff2b32c5b6167e162cb5..0000000000000000000000000000000000000000 GIT binary patch literal 0 HcmV?d00001 literal 970 zcmXqLVm@Zj#I$Y!GZP~dlOV(4Zs(9&d=69Em3g11sAkV^L6cZ~>O)f3UEU9!z%*jp6$;>OQ(917MH&if?V`C0w;Sv^i1d98B#1;I5 z72NVm^HLH^GV}8c6%FJ;Dwu^O5GsN}hNUVv<>!|uI6E51iSrtn7#JIx7#Nxw8X8B5 z^BN;_>Fk;&MkVCnU}R-rZerwTFlb`rVrpV!WY}_t7Ne;@l2>AiQadDHC2MrTVB zO(Lpfw^>Si%esGJa$bBkT4%~@SA&z4SLRpsX_nubYp1hTKIzu}WsAQ2p~ zvdSzH24W2&2m4H!6-7=Rf*=N89jCompM#ldvEWm`W}#J zxk}xi#o5);HktIgnC#)1`JOlE+oS{&KE=3)&u#8$74Y|m%cOL+Z;IVzN<(T-->Cg@tAgaZeR7U zoO6kLraH9v^FEAbn0rzC{=8|?{>9&=0(}ZDUbr5qpi+Ngkv!MxEhXG;4@Gr@<_V~8 hz1^Yl@Bi1C6W7#=r%k@Xm3H;jpD6o4&JuOO^8kV}d_DjG