commit 028a6e3cbd3121e627371ff9645b6923b69caa5e Author: Sofia Boldyreva Date: Wed Jan 15 22:28:20 2025 +0100 Initial commit diff --git a/config.yaml b/config.yaml new file mode 100644 index 0000000..43f5869 --- /dev/null +++ b/config.yaml @@ -0,0 +1,52 @@ +actions: + - replace: + - target: "spec" + find: "%global glib2_version 2.45.8" + replace: | + %global efi_vendor almalinux + %global efidir almalinux + %global efi_esp_dir /boot/efi/EFI/%{efidir} + + %global glib2_version 2.45.8 + count: 1 + - target: "spec" + find: | + -Dfwupd-efi:efi_sbat_distro_id="rhel" \ + -Dfwupd-efi:efi_sbat_distro_summary="Red Hat Enterprise Linux" \ + replace: | + -Dfwupd-efi:efi_sbat_distro_id="almalinux" \ + -Dfwupd-efi:efi_sbat_distro_summary="AlmaLinux" \ + count: 1 + - target: "spec" + find: "-Dfwupd-efi:efi_sbat_distro_url=\"mail:secalert@redhat.com\" \\" + replace: "-Dfwupd-efi:efi_sbat_distro_url=\"mailto:security@almalinux.org\" \\" + count: 1 + - target: "spec" + find: | + %pesign -s -i %{fwup_efi_fn} -o %{fwup_efi_fn}.tmp -a %{SOURCE300} -c %{SOURCE301} -n redhatsecureboot301 + %pesign -s -i %{fwup_efi_fn}.tmp -o %{fwup_efi_fn}.signed -a %{SOURCE500} -c %{SOURCE503} -n redhatsecureboot503 + replace: | + %pesign -s -i %{fwup_efi_fn} -o %{fwup_efi_fn}.tmp -a %{SOURCE300} -c %{SOURCE301} -n almalinuxsecurebootca0 + %pesign -s -i %{fwup_efi_fn}.tmp -o %{fwup_efi_fn}.signed -a %{SOURCE500} -c %{SOURCE503} -n almalinuxsecurebootca0 + count: 1 + + - modify_release: + - suffix: ".alma.1" + enabled: true + + - changelog_entry: + - name: "Eduard Abdullin" + email: "eabdullin@almalinux.org" + line: + - "Use AlmaLinux cert" + + - add_files: + - type: "source" + name: "almalinuxsecurebootca0.cer" + number: 300 + + - delete_files: + - file_name: "redhatsecurebootca3.cer" + - file_name: "redhatsecureboot301.cer" + - file_name: "redhatsecurebootca5.cer" + - file_name: "redhatsecureboot503.cer" diff --git a/files/almalinuxsecurebootca0.cer b/files/almalinuxsecurebootca0.cer new file mode 100644 index 0000000..6a4e99b Binary files /dev/null and b/files/almalinuxsecurebootca0.cer differ