Skip to content

Commit 2b7380f

Browse files
committed
Limit chain of signing to z16 only
genprotimg currently only allows one signing key
1 parent 084d20f commit 2b7380f

File tree

1 file changed

+5
-2
lines changed

1 file changed

+5
-2
lines changed

build-tests/s390/tumbleweed/test-image-MicroOS/appliance.kiwi

Lines changed: 5 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -44,15 +44,18 @@
4444
</oemconfig>
4545
<bootloader name="zipl" timeout="10">
4646
<securelinux>
47+
<!-- gen2 z16 certificates -->
4748
<hkd_cert name="/var/lib/se-certs/HKD-3932-02967D8.crt"/>
4849
<hkd_cert name="/var/lib/se-certs/HKD-3932-02967F8.crt"/>
4950
<hkd_cert name="/var/lib/se-certs/HKD-3932-0296878.crt"/>
51+
<hkd_sign_cert name="/var/lib/se-certs/ibm-z-host-key-signing-gen2.crt"/>
52+
<!-- gen1 z15 certificates
5053
<hkd_cert name="/var/lib/se-certs/HKD-8562-024B858.crt"/>
5154
<hkd_cert name="/var/lib/se-certs/HKD-8562-024B868.crt"/>
5255
<hkd_cert name="/var/lib/se-certs/HKD-8562-024B878.crt"/>
53-
<hkd_ca_cert name="/var/lib/se-certs/DigiCertCA.crt"/>
54-
<hkd_sign_cert name="/var/lib/se-certs/ibm-z-host-key-signing-gen2.crt"/>
5556
<hkd_sign_cert name="/var/lib/se-certs/ibm-z-host-key-signing.crt"/>
57+
-->
58+
<hkd_ca_cert name="/var/lib/se-certs/DigiCertCA.crt"/>
5659
<hkd_revocation_list name="/var/lib/se-certs/ibm-z-host-key.crl"/>
5760
<hkd_revocation_list name="/var/lib/se-certs/ibm-z-host-key-gen2.crl"/>
5861
<hkd_revocation_list name="/var/lib/se-certs/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl"/>

0 commit comments

Comments
 (0)