From c1bdbd9d90e2ccd53d5c28fcfb8691dbc0c6636a Mon Sep 17 00:00:00 2001 From: Sayan Chowdhury Date: Wed, 3 Jan 2024 21:32:15 +0530 Subject: [PATCH] build_image_util: Sign the vmlinuz with the shim key Signed-off-by: Sayan Chowdhury --- build_library/build_image_util.sh | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/build_library/build_image_util.sh b/build_library/build_image_util.sh index 570743c239..64a7a89b86 100755 --- a/build_library/build_image_util.sh +++ b/build_library/build_image_util.sh @@ -828,8 +828,8 @@ EOF # Sign the kernel after /usr is in a consistent state and verity is calculated if [[ ${COREOS_OFFICIAL:-0} -ne 1 ]]; then - sudo sbsign --key /usr/share/sb_keys/DB.key \ - --cert /usr/share/sb_keys/DB.crt \ + sudo sbsign --key /usr/share/sb_keys/shim.key \ + --cert /usr/share/sb_keys/shim.pem \ "${root_fs_dir}/boot/flatcar/vmlinuz-a" sudo mv "${root_fs_dir}/boot/flatcar/vmlinuz-a.signed" \ "${root_fs_dir}/boot/flatcar/vmlinuz-a"