From faf0e35f09e764a8c87bc6a5bd180b214036ba1a Mon Sep 17 00:00:00 2001 From: Andrew Lukoshko Date: Sun, 8 Mar 2026 23:02:19 +0000 Subject: [PATCH] Update secure boot certs: ca0 as Source2, boot0 as Source1 --- almalinuxsecureboot0.cer | Bin 0 -> 999 bytes almalinuxsecurebootca0.cer | Bin 0 -> 970 bytes shim.rpmmacros | 2 +- shim.spec | 3 ++- 4 files changed, 3 insertions(+), 2 deletions(-) create mode 100644 almalinuxsecureboot0.cer create mode 100644 almalinuxsecurebootca0.cer diff --git a/almalinuxsecureboot0.cer b/almalinuxsecureboot0.cer new file mode 100644 index 0000000000000000000000000000000000000000..e6bb9db458dcdd38c1d601a5160ce8464ad028e0 GIT binary patch literal 999 zcmXqLVt#DU#B_QAGZP~dlSq=$x3`I_j%l#2FGy70?o}0&^C`xFmyJ`a&7`|WU>24@s0aobma5>CpI@Tj>}Vh-&TC|9U~Ft?Xklb& zVh|5{Q*3?l-?gr~{?8kbg0b5t?lBx5kIj7}g65w>>_kj-vx$A0zuP(QmrG2u2oc z48%ZuRS=)YfQyYon~jl`m7ST{Ko%s<$0Eie@_$b83%6N8)15EgoM>+NBkWY&gl=$> zkyU1qFc51HIoS8|=e1RqCd=#0HZEQp>z27>$v)(`0j5`A+%Ph@OKKIL-ult%`<1Av z5-(2v5nVsM&G$=Ot(U)hQd!P8?3PlTo-)sPC%) z%GRv~6F;VMvx!~hPrProZ&#m`UU0&*YmVC)`!Achh~HyQ{q4DbyFt~aQ_2ejlC}W= DeSwFp literal 0 HcmV?d00001 diff --git a/almalinuxsecurebootca0.cer b/almalinuxsecurebootca0.cer new file mode 100644 index 0000000000000000000000000000000000000000..d086cd53c500ca15c889ff2b32c5b6167e162cb5 GIT binary patch literal 970 zcmXqLVm@Zj#I$Y!GZP~dlOV(4Zs(9&d=69Em3g11sAkV^L6cZ~>O)f3UEU9!z%*jp6$;>OQ(917MH&if?V`C0w;Sv^i1d98B#1;I5 z72NVm^HLH^GV}8c6%FJ;Dwu^O5GsN}hNUVv<>!|uI6E51iSrtn7#JIx7#Nxw8X8B5 z^BN;_>Fk;&MkVCnU}R-rZerwTFlb`rVrpV!WY}_t7Ne;@l2>AiQadDHC2MrTVB zO(Lpfw^>Si%esGJa$bBkT4%~@SA&z4SLRpsX_nubYp1hTKIzu}WsAQ2p~ zvdSzH24W2&2m4H!6-7=Rf*=N89jCompM#ldvEWm`W}#J zxk}xi#o5);HktIgnC#)1`JOlE+oS{&KE=3)&u#8$74Y|m%cOL+Z;IVzN<(T-->Cg@tAgaZeR7U zoO6kLraH9v^FEAbn0rzC{=8|?{>9&=0(}ZDUbr5qpi+Ngkv!MxEhXG;4@Gr@<_V~8 hz1^Yl@Bi1C6W7#=r%k@Xm3H;jpD6o4&JuOO^8kV}d_DjG literal 0 HcmV?d00001 diff --git a/shim.rpmmacros b/shim.rpmmacros index 09abd69..fb8463f 100644 --- a/shim.rpmmacros +++ b/shim.rpmmacros @@ -125,7 +125,7 @@ version signed by the UEFI signing service. \ else \ cp -av %{-d*}/%{-b*}%{-a*}.efi %{-b*}%{-a*}-unsigned.efi \ fi \ - %{expand:%%sign -i %{-b*}%{-a*}-unsigned.efi -o %{-b*}%{-a*}-signed.efi -n centossecureboot201 -a %{SOURCE2} -c %{SOURCE1} } \ + %{expand:%%sign -i %{-b*}%{-a*}-unsigned.efi -o %{-b*}%{-a*}-signed.efi -n almalinuxsecureboot0 -a %{SOURCE2} -c %{SOURCE1} } \ %{nil} # -a diff --git a/shim.spec b/shim.spec index d52e2f9..19a6737 100644 --- a/shim.spec +++ b/shim.spec @@ -16,7 +16,8 @@ ExclusiveArch: %{efi} ExcludeArch: %{arm} %{ix86} Source0: shim.rpmmacros -Source1: almalinuxsecurebootca0.cer +Source1: almalinuxsecureboot0.cer +Source2: almalinuxsecurebootca0.cer Source5: shim.conf # keep these two lists of sources synched up arch-wise. That is 0 and 10