Skip to content
  • Anton Hvornum's avatar
    Add the ability to generate rootfs signatures using openssl CMS module if ``-c`` is given. · 326cfed7
    Anton Hvornum authored and David Runge's avatar David Runge committed
    (gitlab ci)
    
    Added a CA structure to the codesigning certificates.
    This to test the functionality of optional CA being in the signing message.
    
    (mkarchiso)
    Removed the ``sign_netboot_artifacts`` variable and instead
    we'll now rely on ``if [[ -v cert_list ]]; then``.
    
    Added ``ARCHISO_TLS_FD`` and ``ARCHISO_TLSCA_FD`` environment variables
    to override the certificates used. This is so that third party CA's can
    be used during building in a meaningful way without distrupting the
    CA trust that is shipped by default.
    
    _cms_sign_artifact() was added which signs the rootfs using OpenSSL CMS.
    The files will be saved as "${artifact}.cms.sig". That would be for instance
    "${isofs_dir}/${install_dir}/${arch}/airootfs.sfs.cms.sig".
    326cfed7