diff options
| author | Christian Breunig <christian@breunig.cc> | 2026-10-05 23:06:19 +0200 |
|---|---|---|
| committer | Christian Breunig <christian@breunig.cc> | 2026-10-05 23:06:19 +0200 |
| commit | 4b5d6c035bf808fc4689f7db958c3ce15e534d73 (patch) | |
| tree | 85f8dce8b46667c0fe72d8235931edf1dbfbf354 /scripts/package-build | |
| parent | 414b5ae6d9f568d218880b1a3c4293f7ef193df7 (diff) | |
| download | vyos-build-4b5d6c035bf808fc4689f7db958c3ce15e534d73.tar.gz vyos-build-4b5d6c035bf808fc4689f7db958c3ce15e534d73.zip | |
Testsuite: T861: boot VyOS CA signed images as-is in Secure Boot test
The Secure Boot test always disabled Secure Boot in the UEFI and enrolled a
Machine Owner Key. That only applies to images signed with a custom
certificate - an image signed by the VyOS CA is already trusted and must boot
without any firmware changes.
If the custom signing key pair is present in the build tree, the MOK workflow
is used as before. Otherwise the image boots with Secure Boot enabled from the
start, and the Kernel signature is verified against the VyOS CA issuer and
signer via "show secure-boot detail", which requires a matching vyos-1x.
The make target is renamed from testsb to test-secure-boot.
Diffstat (limited to 'scripts/package-build')
0 files changed, 0 insertions, 0 deletions
