From a3e20e8bc5fa3a26842fb640be3c39724d86647f Mon Sep 17 00:00:00 2001 From: Kai Lueke Date: Thu, 11 Aug 2022 15:27:24 +0200 Subject: [PATCH] coreos-base/coreos-init: Add new image signing key to flatcar-install This pulls in https://github.com/flatcar-linux/init/pull/79 to updated the embedded pub key in flatcar-install to include the new subkey that is used for signing new releases. --- .../changelog/changes/2022-08-11-new-image-signing-subkey.md | 1 + .../coreos-base/coreos-init/coreos-init-9999.ebuild | 2 +- 2 files changed, 2 insertions(+), 1 deletion(-) create mode 100644 sdk_container/src/third_party/coreos-overlay/changelog/changes/2022-08-11-new-image-signing-subkey.md diff --git a/sdk_container/src/third_party/coreos-overlay/changelog/changes/2022-08-11-new-image-signing-subkey.md b/sdk_container/src/third_party/coreos-overlay/changelog/changes/2022-08-11-new-image-signing-subkey.md new file mode 100644 index 0000000000..6a37f7604b --- /dev/null +++ b/sdk_container/src/third_party/coreos-overlay/changelog/changes/2022-08-11-new-image-signing-subkey.md @@ -0,0 +1 @@ +- The new image signing subkey was added to the public key embedded into `flatcar-install` (the old expired on 10th August 2022), only an updated `flatcar-install` script can verify releases signed with the new key ([init#79](https://github.com/flatcar-linux/init/pull/79)) diff --git a/sdk_container/src/third_party/coreos-overlay/coreos-base/coreos-init/coreos-init-9999.ebuild b/sdk_container/src/third_party/coreos-overlay/coreos-base/coreos-init/coreos-init-9999.ebuild index aad1302735..e952cb10ee 100644 --- a/sdk_container/src/third_party/coreos-overlay/coreos-base/coreos-init/coreos-init-9999.ebuild +++ b/sdk_container/src/third_party/coreos-overlay/coreos-base/coreos-init/coreos-init-9999.ebuild @@ -10,7 +10,7 @@ CROS_WORKON_REPO="https://github.com" if [[ "${PV}" == 9999 ]]; then KEYWORDS="~amd64 ~arm ~arm64 ~x86" else - CROS_WORKON_COMMIT="2e0b31dc3aed008550489151143e761d4ebeead0" # flatcar-master + CROS_WORKON_COMMIT="0a77e274e05a4db82d18ad6d20d23b3cbdf31e2f" # flatcar-master KEYWORDS="amd64 arm arm64 x86" fi