embed another developer's certificate in ipxe-arch.*
Task Info (Flyspray) | |
---|---|
Opened By | nl6720 (nl6720) |
Task ID | 80243 |
Type | Feature Request |
Project | Arch Linux |
Category | Packages: Extra |
Version | None |
OS | All |
Opened | 2023-11-13 12:50:06 UTC |
Status | Assigned |
Assignee | David Runge (dvzrv) |
Details
Description: ipxe-arch.efi, ipxe-arch.lkrn and ipxe-arch.pxe embed codesigning_pierre_archlinux.pem. This causes issues when the owner of that codesigning certificate is not able to release the monthly ISO & netboot artifacts for one reason or another.
A simple solution would be to additionally embed another developer's codesigning certificate in the iPXE builds. Afterwards, the images and signatures in https://github.com/archlinux/archweb/tree/master/sitestatic/netboot will need to be updated.
Additional info:
- package version(s)
- config and/or log files etc.
- link to upstream bug report, if any ipxe 1.21.1-5
Steps to reproduce: