diff --git a/sdk_container/src/third_party/coreos-overlay/coreos-base/coreos-sb-keys/coreos-sb-keys-0.0.2.ebuild b/sdk_container/src/third_party/coreos-overlay/coreos-base/coreos-sb-keys/coreos-sb-keys-0.0.2.ebuild index cc8a4ffefe..f2933ee722 100644 --- a/sdk_container/src/third_party/coreos-overlay/coreos-base/coreos-sb-keys/coreos-sb-keys-0.0.2.ebuild +++ b/sdk_container/src/third_party/coreos-overlay/coreos-base/coreos-sb-keys/coreos-sb-keys-0.0.2.ebuild @@ -21,5 +21,8 @@ src_install() { newins "${FILESDIR}/KEK.crt" KEK.crt newins "${FILESDIR}/DB.key" DB.key newins "${FILESDIR}/DB.crt" DB.crt - newins "${FILESDIR}/DB.der" DB.der + newins "${FILESDIR}/ca.key" ca.key + newins "${FILESDIR}/ca.der" ca.der + newins "${FILESDIR}/ca.pem" ca.pem + newins " } diff --git a/sdk_container/src/third_party/coreos-overlay/coreos-base/coreos-sb-keys/files/DB.der b/sdk_container/src/third_party/coreos-overlay/coreos-base/coreos-sb-keys/files/DB.der deleted file mode 100644 index 2ec1eaf3c3..0000000000 Binary files a/sdk_container/src/third_party/coreos-overlay/coreos-base/coreos-sb-keys/files/DB.der and /dev/null differ diff --git a/sdk_container/src/third_party/coreos-overlay/coreos-base/coreos-sb-keys/files/DB.pem b/sdk_container/src/third_party/coreos-overlay/coreos-base/coreos-sb-keys/files/DB.pem deleted file mode 100644 index e621892143..0000000000 --- a/sdk_container/src/third_party/coreos-overlay/coreos-base/coreos-sb-keys/files/DB.pem +++ /dev/null @@ -1,19 +0,0 @@ ------BEGIN CERTIFICATE----- -MIIDBTCCAe2gAwIBAgIJALVWTDRRd7EnMA0GCSqGSIb3DQEBCwUAMBkxFzAVBgNV -BAMMDkNvcmVPUyB0ZXN0IERCMB4XDTE1MDQxMzE4MzM0NloXDTE1MDUxMzE4MzM0 -NlowGTEXMBUGA1UEAwwOQ29yZU9TIHRlc3QgREIwggEiMA0GCSqGSIb3DQEBAQUA -A4IBDwAwggEKAoIBAQCwQoQNxPH1ei+RNEcxmdn8cCNc/tYXuLObAUHtTp9AqCYr -BkZiFZ25RmujfmJDdK4fPN81tpNC0aKKr71UYgcj13noHmOgR9Rv3rRxwBib3n7S -K4RjnpW6V2aRDYNo0BH25lk/5M8IE6SX0SIuG1vCFavAj5s0dg5ycPHkDj1Ypbmv -Q6froIdCVX3fSNXSgPY812Eb36yNyZFybetQupfVRsl0auCUNh3anNLPCFre1oZf -lkx+U3BFXDZ0k8Fjq+fzvKxu4ef9XpZmXieow5YCwemCRItl+ftBeWD/OjXoNXBR -sij3QNi/CxrO59DiklpGolPaCVA0oJYWL5XkWI/dAgMBAAGjUDBOMB0GA1UdDgQW -BBRmPA/wBsfGI3EH2/X5W/SuwY1NOzAfBgNVHSMEGDAWgBRmPA/wBsfGI3EH2/X5 -W/SuwY1NOzAMBgNVHRMEBTADAQH/MA0GCSqGSIb3DQEBCwUAA4IBAQCW9TbpGhGv -ZPPlb0X05wXYnzKUUq6U3IlxGVghwjLeE6/IIQvWn+sl7l9PNainzPATx1jZ7YSR -HTCXhtfbnM9WICOV/h4Vztt7Z2m65gDa+/5679VpQfrqG5oV7FhucmPiMNbiy92Y -F5SjB/HmRaSfimew3RmnOVUeUySW7Nw7tA5ka/nG0U9hXd296z7ghJlZQj1qTYtr -1Y2yv4QSiRWNZcJSOq79tdGbAJqkqibo775UH6sj/UfHMoDQTvAenF8H/4F80r+6 -X2pgnX96ihshJ2MAXQnhbLLmPtXn/pV122xis/177yrefavHFTp14KPbnU1K3jeW -hoLJhYcZKXdz ------END CERTIFICATE----- diff --git a/sdk_container/src/third_party/coreos-overlay/sys-boot/shim/files/shim.der b/sdk_container/src/third_party/coreos-overlay/coreos-base/coreos-sb-keys/files/flatcar-stg-ca.der similarity index 100% rename from sdk_container/src/third_party/coreos-overlay/sys-boot/shim/files/shim.der rename to sdk_container/src/third_party/coreos-overlay/coreos-base/coreos-sb-keys/files/flatcar-stg-ca.der diff --git a/sdk_container/src/third_party/coreos-overlay/sys-boot/shim/files/shim.rsa b/sdk_container/src/third_party/coreos-overlay/coreos-base/coreos-sb-keys/files/flatcar-stg-ca.key similarity index 100% rename from sdk_container/src/third_party/coreos-overlay/sys-boot/shim/files/shim.rsa rename to sdk_container/src/third_party/coreos-overlay/coreos-base/coreos-sb-keys/files/flatcar-stg-ca.key diff --git a/sdk_container/src/third_party/coreos-overlay/sys-boot/shim/files/shim.pem b/sdk_container/src/third_party/coreos-overlay/coreos-base/coreos-sb-keys/files/flatcar-stg-ca.pem similarity index 100% rename from sdk_container/src/third_party/coreos-overlay/sys-boot/shim/files/shim.pem rename to sdk_container/src/third_party/coreos-overlay/coreos-base/coreos-sb-keys/files/flatcar-stg-ca.pem diff --git a/sdk_container/src/third_party/coreos-overlay/sys-boot/shim/shim-9999.ebuild b/sdk_container/src/third_party/coreos-overlay/sys-boot/shim/shim-9999.ebuild index 2ee87857e1..0b82ae152b 100644 --- a/sdk_container/src/third_party/coreos-overlay/sys-boot/shim/shim-9999.ebuild +++ b/sdk_container/src/third_party/coreos-overlay/sys-boot/shim/shim-9999.ebuild @@ -55,7 +55,7 @@ src_compile() { emake_args+=( ARCH=aarch64 ) fi emake_args+=( ENABLE_SBSIGN=1 ) - emake_args+=( VENDOR_CERT_FILE="${SYSROOT}/usr/share/sb_keys/shim.der" ) + emake_args+=( VENDOR_CERT_FILE="${FILESDIR}/shim.der" ) emake "${emake_args[@]}" || die }