<feed xmlns='http://www.w3.org/2005/Atom'>
<title>efi-boot-shim.git/debian/generate_dbx_list, branch master</title>
<subtitle> (mirror of https://github.com/vyos/efi-boot-shim.git)
</subtitle>
<id>https://git.amelek.net/vyos/efi-boot-shim.git/atom?h=master</id>
<link rel='self' href='https://git.amelek.net/vyos/efi-boot-shim.git/atom?h=master'/>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos/efi-boot-shim.git/'/>
<updated>2024-05-02T21:13:14+00:00</updated>
<entry>
<title>Tweak the UUID handling to be clearer</title>
<updated>2024-05-02T21:13:14+00:00</updated>
<author>
<name>Steve McIntyre</name>
<email>steve@einval.com</email>
</author>
<published>2024-02-17T17:19:57+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos/efi-boot-shim.git/commit/?id=3cf4042d82ef314f19e9f7bd4f86c4b59efd8233'/>
<id>urn:sha1:3cf4042d82ef314f19e9f7bd4f86c4b59efd8233</id>
<content type='text'>
</content>
</entry>
<entry>
<title>generate_dbx_list: pick a fixed UUID</title>
<updated>2024-01-20T23:15:22+00:00</updated>
<author>
<name>Steve McIntyre</name>
<email>steve@einval.com</email>
</author>
<published>2024-01-20T22:40:27+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos/efi-boot-shim.git/commit/?id=f4f4e39e16af685d5d6de16c4fcc0e04f651ab70'/>
<id>urn:sha1:f4f4e39e16af685d5d6de16c4fcc0e04f651ab70</id>
<content type='text'>
otherwise our build won't be reproducible, doh!
</content>
</entry>
<entry>
<title>Tweak building with pesign changes</title>
<updated>2023-11-02T00:47:18+00:00</updated>
<author>
<name>Steve McIntyre</name>
<email>steve@einval.com</email>
</author>
<published>2023-11-01T23:37:50+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos/efi-boot-shim.git/commit/?id=7686debad858ce35d7b393a424f9b684120c778c'/>
<id>urn:sha1:7686debad858ce35d7b393a424f9b684120c778c</id>
<content type='text'>
We used to use efisiglist to generate the DBX list. Newer versions of
the pesign package don't include it any more, and the recommended
replacement tool is now efisecdb from efivar. Tweak the
generate_dbx_list script to work with both old and new. Let's make
backports easy...
</content>
</entry>
<entry>
<title>Improve how the dbx hashes are handled</title>
<updated>2021-03-23T23:33:04+00:00</updated>
<author>
<name>Steve McIntyre</name>
<email>steve@einval.com</email>
</author>
<published>2021-03-14T16:04:15+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos/efi-boot-shim.git/commit/?id=de3def7f5365e0b567606c3b7b63df2f0525af35'/>
<id>urn:sha1:de3def7f5365e0b567606c3b7b63df2f0525af35</id>
<content type='text'>
Only include the hashes for the architecture we're building for - no
point in adding bloat and delay here.

Add a script "block_signed_deb" to scan a set of .deb files, extract
the hashes for .efi binaries and list them in the format wanted for
the dbx hashes file.

Split out the code to use that file from the rules file into a
separate helper.
</content>
</entry>
</feed>
