/srv/irclogs.ubuntu.com/2013/10/03/#ubuntu-installer.txt

psivaacjwatson: apw: UEFI shim signature verification (?) fails with todays images..10:50
psivaareported bug against linux-signed: bug #123464910:51
ubot2Launchpad bug 1234649 in linux-signed (Ubuntu) "UEFI shim verification against microsoft-uefica-public.pem fails with 20131003 images" [Undecided,New] https://launchpad.net/bugs/123464910:51
psivaanot sure if that's the right package tough10:51
cjwatsonNothing I can help with10:52
cjwatsonReassigned to shim-signed - you want slangasek10:53
psivaacjwatson: ack, thanks10:53
cjwatson(Though could also be the fault of sbsigntool or utah itself)10:54
cjwatsonWhat release are you running this on?10:54
cjwatsonI mean, utah itself10:54
psivaathis is saucy10:55
cjwatsonOK, no idea why anything would've changed recently then10:55
* xnox ponders if this is my check failing. I've written tests to verify sb signatures, statically.10:57
apwsbsigntool changed, but a month back, and (cjwatson) isn't the sbsigntool we use on the backend at least separatly manually upgraded10:58
apwxnox, you added a new test ?10:59
cjwatsonapw: Dunno10:59
xnoxapw: i added the test, way back when, to utah static tests to extract signed things from the .iso and execute sbverify on them.11:00
psivaaapw: 0.6-0ubuntu1~12.04.1 is the version of sbsigntool that's being used for this test11:04
xnox$ sbverify --cert microsoft-uefica-public.pem /mnt/EFI/BOOT/BOOTx64.EFI11:05
xnoxwarning: data remaining[1230256 vs 1355656]: gaps between PE/COFF sections?11:05
xnoxPKCS7 verification failed11:05
xnox139756278539968:error:21075075:PKCS7 routines:PKCS7_verify:certificate verify error:pk7_smime.c:342:Verify error:certificate has expired11:05
xnoxSignature verification failed11:05
xnoxhas microsoft certificate got updated?! /me goes to poke slangasek / jdstrand / et al11:06
* apw would expect the public ones to change over time, like they do on websites11:07
xnoxapw: well, the microsoft cert is listed as valid for 15 years, until 202611:10
apwwell doh11:10
apwxnox, but they may use an intermediate cert from that master one11:15
apwi would expect them to get the master out yearly and make a cert for that year11:15
xnoxpsivaa: raring iso also failing verification.11:51
xnoxapw: did microsoft sign us for 2 years only =/ O_o11:51
=== psivaa is now known as psivaa-afk
=== psivaa-afk is now known as psivaa
xnoxapw: extracted certs from the signature, there is intermediate cert which expired today, and it only lasts 15months, vs all other certs last for 15 years.15:10
=== mpt_ is now known as mpt
apwhmmm i wonder if they missed15:16
apwxnox, ^^15:16
apwxnox, is that one ours or one of m$'s15:16
xnoxapw: m$'s15:16

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!