mirror of
https://github.com/flatcar/scripts.git
synced 2025-09-22 06:01:41 +02:00
Merge pull request #842 from ajeddeloh/signing-server
signing/sign.sh: update to use correct keys/ips
This commit is contained in:
commit
057a085057
@ -10,7 +10,7 @@ fi
|
|||||||
DATA_DIR="$(readlink -f "$1")"
|
DATA_DIR="$(readlink -f "$1")"
|
||||||
KEYS_DIR="$(readlink -f "$(dirname "$0")")"
|
KEYS_DIR="$(readlink -f "$(dirname "$0")")"
|
||||||
SIGS_DIR="$(readlink -f "$2")"
|
SIGS_DIR="$(readlink -f "$2")"
|
||||||
SERVER_ADDR="${3:-10.7.16.138}"
|
SERVER_ADDR="${3:-10.7.68.100}"
|
||||||
SERVER_PORT="${4:-50051}"
|
SERVER_PORT="${4:-50051}"
|
||||||
|
|
||||||
echo "=== Verifying update payload... ==="
|
echo "=== Verifying update payload... ==="
|
||||||
@ -32,7 +32,7 @@ pushd "${DATA_DIR}"
|
|||||||
--image "${DATA_DIR}/coreos_production_update.bin" \
|
--image "${DATA_DIR}/coreos_production_update.bin" \
|
||||||
--kernel "${DATA_DIR}/coreos_production_image.vmlinuz" \
|
--kernel "${DATA_DIR}/coreos_production_image.vmlinuz" \
|
||||||
--output "${DATA_DIR}/coreos_production_update.gz" \
|
--output "${DATA_DIR}/coreos_production_update.gz" \
|
||||||
--private_keys "${KEYS_DIR}/devel.key.pem+fero:coreos-update-prod" \
|
--private_keys "${KEYS_DIR}/devel.key.pem+fero:coreos-image-signing-key" \
|
||||||
--public_keys "${KEYS_DIR}/devel.pub.pem+${KEYS_DIR}/prod-2.pub.pem" \
|
--public_keys "${KEYS_DIR}/devel.pub.pem+${KEYS_DIR}/prod-2.pub.pem" \
|
||||||
--keys_separator "+" \
|
--keys_separator "+" \
|
||||||
--signing_server_address "$SERVER_ADDR" \
|
--signing_server_address "$SERVER_ADDR" \
|
||||||
@ -53,7 +53,7 @@ fero-client \
|
|||||||
sign \
|
sign \
|
||||||
--file "${DATA_DIR}/torcx_manifest.json" \
|
--file "${DATA_DIR}/torcx_manifest.json" \
|
||||||
--output "${DATA_DIR}/torcx_manifest.json.sig-fero" \
|
--output "${DATA_DIR}/torcx_manifest.json.sig-fero" \
|
||||||
--secret-key coreos-torcx \
|
--secret-key coreos-app-signing-key \
|
||||||
${torcx_signature_arg}
|
${torcx_signature_arg}
|
||||||
gpg2 --enarmor \
|
gpg2 --enarmor \
|
||||||
--output "${DATA_DIR}/torcx_manifest.json.asc" \
|
--output "${DATA_DIR}/torcx_manifest.json.asc" \
|
||||||
|
Loading…
x
Reference in New Issue
Block a user