summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorPeter Jones <pjones@redhat.com>2025-02-04 10:59:06 -0500
committerPeter Jones <pjones@redhat.com>2025-02-05 09:18:45 -0500
commit7ae0ee698a7e65057bb4d5322d3aabe2f435954e (patch)
treee3e4298744608c50a607b076f3b566b992710eae
parenteb02afc6f822576b73b7added3966ad7e72fd342 (diff)
downloadefi-boot-shim-7ae0ee698a7e65057bb4d5322d3aabe2f435954e.tar.gz
efi-boot-shim-7ae0ee698a7e65057bb4d5322d3aabe2f435954e.zip
Add docs for ENABLE_CODESIGN_EKU
This adds documentation for the ENABLE_CODESIGN_EKU build option. Signed-off-by: Peter Jones <pjones@redhat.com>
-rw-r--r--BUILDING3
1 files changed, 3 insertions, 0 deletions
diff --git a/BUILDING b/BUILDING
index 17cd98d3..bdd98dd4 100644
--- a/BUILDING
+++ b/BUILDING
@@ -81,6 +81,9 @@ Variables you could set to customize the build:
- POST_PROCESS_PE_FLAGS
This allows you to add flags to the invocation of "post-process-pe", for
example to disable the NX compatibility flag.
+- ENABLE_CODESIGN_EKU
+ This changes the certificate validation logic to require Extended Key
+ Usage 1.3.6.1.5.5.7.3.3 ("Code Signing").
Vendor SBAT data:
It will sometimes be requested by reviewers that a build includes extra