From 19a0d5c0273efc864b79f4e46ff0ec67c96e2891 Mon Sep 17 00:00:00 2001 From: Andrew Lukoshko Date: Sun, 8 Mar 2026 23:14:45 +0000 Subject: [PATCH] Update secure boot certs: ca0 as Source2, boot0 as Source1 --- SOURCES/almalinuxsecureboot0.cer | Bin 0 -> 999 bytes SOURCES/almalinuxsecurebootca0.cer | Bin 1787 -> 970 bytes SOURCES/shim.rpmmacros | 2 +- SPECS/shim.spec | 3 ++- 4 files changed, 3 insertions(+), 2 deletions(-) create mode 100644 SOURCES/almalinuxsecureboot0.cer diff --git a/SOURCES/almalinuxsecureboot0.cer b/SOURCES/almalinuxsecureboot0.cer new file mode 100644 index 0000000000000000000000000000000000000000..e6bb9db458dcdd38c1d601a5160ce8464ad028e0 GIT binary patch literal 999 zcmXqLVt#DU#B_QAGZP~dlSq=$x3`I_j%l#2FGy70?o}0&^C`xFmyJ`a&7`|WU>24@s0aobma5>CpI@Tj>}Vh-&TC|9U~Ft?Xklb& zVh|5{Q*3?l-?gr~{?8kbg0b5t?lBx5kIj7}g65w>>_kj-vx$A0zuP(QmrG2u2oc z48%ZuRS=)YfQyYon~jl`m7ST{Ko%s<$0Eie@_$b83%6N8)15EgoM>+NBkWY&gl=$> zkyU1qFc51HIoS8|=e1RqCd=#0HZEQp>z27>$v)(`0j5`A+%Ph@OKKIL-ult%`<1Av z5-(2v5nVsM&G$=Ot(U)hQd!P8?3PlTo-)sPC%) z%GRv~6F;VMvx!~hPrProZ&#m`UU0&*YmVC)`!Achh~HyQ{q4DbyFt~aQ_2ejlC}W= DeSwFp literal 0 HcmV?d00001 diff --git a/SOURCES/almalinuxsecurebootca0.cer b/SOURCES/almalinuxsecurebootca0.cer index 6a4e99b9ed921c4af3db55a619260f1ab76110dc..d086cd53c500ca15c889ff2b32c5b6167e162cb5 100644 GIT binary patch literal 970 zcmXqLVm@Zj#I$Y!GZP~dlOV(4Zs(9&d=69Em3g11sAkV^L6cZ~>O)f3UEU9!z%*jp6$;>OQ(917MH&if?V`C0w;Sv^i1d98B#1;I5 z72NVm^HLH^GV}8c6%FJ;Dwu^O5GsN}hNUVv<>!|uI6E51iSrtn7#JIx7#Nxw8X8B5 z^BN;_>Fk;&MkVCnU}R-rZerwTFlb`rVrpV!WY}_t7Ne;@l2>AiQadDHC2MrTVB zO(Lpfw^>Si%esGJa$bBkT4%~@SA&z4SLRpsX_nubYp1hTKIzu}WsAQ2p~ zvdSzH24W2&2m4H!6-7=Rf*=N89jCompM#ldvEWm`W}#J zxk}xi#o5);HktIgnC#)1`JOlE+oS{&KE=3)&u#8$74Y|m%cOL+Z;IVzN<(T-->Cg@tAgaZeR7U zoO6kLraH9v^FEAbn0rzC{=8|?{>9&=0(}ZDUbr5qpi+Ngkv!MxEhXG;4@Gr@<_V~8 hz1^Yl@Bi1C6W7#=r%k@Xm3H;jpD6o4&JuOO^8kV}d_DjG literal 1787 zcmb7Edpy%?9NzEu+YQ4qp+X~z$hNhS)Qi`TME^-dksg&-Xq2Cz{bpoK?*v3Lr+#1l0EMjD_^(GTMD zB!UPL)n5=TknqD$I+(55K`6BGoxr#aQ34*7AqwMDg9H&mfiQx~@Sw6ns4M2o1LnrM zj*bAGgM!g7R1KZf5ID|pa&dAA1xdG2GSJgV;wS_sr+Fwqoly#ygx9gdLs&@Wya0v} z3LG4SP65Uf7hwvK$&cd3bH#kr3{2A~=u->>#eywd37;Auj^GLf30#RlB%EMPEi-l+ zkwox{5{U(2T$BpTN6nIqJ))wy{sLj#R%$>H)k_p74EruH#z6j)0c5b{#3zMt7(@o^ zW7O-~undMU6>I1J?%P(;)EDTd~@7#vAD%qZ-ufkhh?j~ zapii8FZ6l4l2j4>$6Kvd%=FCfQ#Hi8bqZPzauDLVg0k(jF6nNqtfiz|Wxur8bX2ad zdVcV5sacnCY_nO@_S&kodX}Gu=_h9qjw-&C&Q?YW8|~hwL@-lYMZxo*mT|n_rq!Dq zNO?Kr*Z&ajuCl*+CptA}bH}3+sZUn7lNIOqU@O10Y8v~wWKcZqMh{nDsrrHAqC?Fn zC5Od?^TaPN9vZwE>ENKiT9WIkzve%`+%Pg-+wtWhW?EoI?ykMo1m;;krtqoqrdY(Z z>AG~nTPIVAdtr9e$os^OcI}Pat4B7uw#bZr_Ev0CoO20G4yS!W8C%*eNtWAYpL#d* zedparl{a8zs7XrL79O+)cgO3rRq(Xe?bv+=_YavC&C0sI{5@^Isw>gKnC3h)7Af**$k{YWr>DKj@ce|HuYY$w-4X7busAnE?sO0 z%rpc&tP$2Q5p}pRNtx`QBY$$Hy}hi^EzC7xG%sfQ5Hy0tA}}ElkTi6P2EzaYC>lh= zl7Kdzs16YhM?esDptRPfdPAw7JRwLkg(U+Y4UdZT1n$5IPa2Kec@%;nJOpT9#`r7@ z85u`PBr&nB4i2&3%Ye=kMLRG8g8%`Ki%23t2=LQLO~*2UT1>u3z97|AGoqg0iKFNf zr^ZU-duM1WW2`Y49;^^`UC`BhARRwieNz#L243SBz!P*O|5I1;uO$Gbj#^URPsEFj znJ5J48Yh#m)_^Ae=Lv|2+!#zIQG$c)nJj+~w#N#V{a95^486KX5gC+(`LS(LuYLx& zmK=g#7W3C{btC1qgXHu|&hAt1mVpg9@qz7)LQjirTbE=%tB>VaJ{w|W+SRlqtM=qq z`BZ#(0JZP>i7X28yp;YFwn*+V^|hB(LiOc)PaARBXXK%~jS_tFjUyY$QX;*+r0V45 zkE=pT=tBm1C+#j}43w`s`%TdlzpX-LE<>U=F6|4*<{yn&V-xIkW##-D?u9_i{=os1 zQ~fq=HHqcUdPH1KbNZa$#kq3WF+jPXnVa;%`a)vjg(LknHdCYpovzocJ`VZSGQKX% z9VuvTNmoc+L-8N(4b3q2QAF;sQhj@I*nzv-=TicK8=0_FUZQQx>WuhjaYMX_P|t&zHv TseG#v;Fg#3=RT@0&At3@_pP4Z diff --git a/SOURCES/shim.rpmmacros b/SOURCES/shim.rpmmacros index bd69620..a022b1e 100644 --- a/SOURCES/shim.rpmmacros +++ b/SOURCES/shim.rpmmacros @@ -123,7 +123,7 @@ version signed by the UEFI signing service. \ else \ cp -av %{-d*}/%{-b*}%{-a*}.efi %{-b*}%{-a*}-unsigned.efi \ fi \ - %{expand:%%sign -i %{-b*}%{-a*}-unsigned.efi -o %{-b*}%{-a*}-signed.efi -n redhatsecureboot501 -a %{SOURCE2} -c %{SOURCE1} } \ + %{expand:%%sign -i %{-b*}%{-a*}-unsigned.efi -o %{-b*}%{-a*}-signed.efi -n almalinuxsecureboot0 -a %{SOURCE2} -c %{SOURCE1} } \ %{nil} # -a diff --git a/SPECS/shim.spec b/SPECS/shim.spec index c5f5bfb..62e9f33 100644 --- a/SPECS/shim.spec +++ b/SPECS/shim.spec @@ -16,7 +16,8 @@ ExclusiveArch: %{efi} ExcludeArch: %{arm} %{ix86} Source0: shim.rpmmacros -Source1: almalinuxsecurebootca0.cer +Source1: almalinuxsecureboot0.cer +Source2: almalinuxsecurebootca0.cer # keep these two lists of sources synched up arch-wise. That is 0 and 10 # match, 1 and 11 match, ...