tag | 8cc9bdc0b1f8f52ec5ab8006ae5c4bbc7269639b | |
---|---|---|
tagger | Paul Nardini <nardini@google.com> | Fri Sep 10 21:48:20 2021 |
object | f34eb7f47ef89c8c565108a53742404cdaee7c8f |
Chrome OS Submission w/5 year cert
commit | f34eb7f47ef89c8c565108a53742404cdaee7c8f | [log] [tgz] |
---|---|---|
author | Paul Nardini <nardini@google.com> | Fri Sep 10 18:47:26 2021 |
committer | Paul Nardini <nardini@google.com> | Fri Sep 10 18:47:26 2021 |
tree | 5d9e3f22617f18734b543b85dc955e41fa7d760b | |
parent | dc8f032627b3a3ae8c24a1d66385941f415d2b38 [diff] |
Update public certificate with new Google-generated public key The certificate currently embedded in shim builds doesn't match what is used for signing grub. This new cert has a 5 year validity period; the old one had a 2 year validity period. BUG=b:195737944 TEST=make build & make cert-info Change-Id: Icdf6ad422781589defd861f2fb446e3494dca244
Build shim in a Docker container.
Build shim in a Docker container:
make build
Build with the cache turned off to get the full build log:
make build-no-cache
Copy the shim builds from the container to the host:
make copy
View details of the public certificate:
make cert-info
View SBAT section of the shim binaries:
make dump-sbat