/srv/irclogs.ubuntu.com/2018/05/04/#ubuntu-kernel.txt

=== himcesjf_ is now known as him-cesjf
leitaocascardo, 17:16
leitaoOn ppc64el kernel, we are seeing "PKCS#7 signature not signed with a trusted key". Do you know if something changed?17:17
leitaomainly because now I see the unsigned kernels. 17:18
cascardoleitao: hum, don't really know much about it18:43
cascardoapw: ^18:43
apwleitao, this would be because the primary binaries are now signed, they should be signed with the official key20:41
leitaoapw, that is why we have the signed and unsiged kernels?20:42
apwleitao, we have unsigned packages because otherwise there is no delivery mechanism for test kernels (which are not signed)20:43
leitaoapw, let me ask a more silly question. What is the difference between signed and unsigned kernels? If I plan to use dkms, should I move to unsigned?20:44
apwleitao, for ppc64el it all depends how enforced things are; in an efi world we would either load a personal key, or disable signature enforcement20:45
leitaoapw, how do I disable enforcement?20:46
apwleitao, i am not sure i know the answer to that20:47
leitaowe rebuilt a custom kernel and now we see a lot of "PKCS#7 signature not signed with a trusted key". If I disable enforcement, will it not happen?20:47
apwis that built in a PPA ?20:48
apwas those would be signed by the per PPA key20:48
apwi am slightly confused, i assume there is something more amiss when the signature is present over when the image unsigned20:52
leitaoapw, no, we did a in-house custom built20:52
leitaoapw, I am wondering if we missed some step as adding our key somewhere.20:53
apwprevious images would have been completely unsigned, how is it behaving different ?20:53
apwperhaps you could enumerate that for me in a bug so we can better understand20:54
=== himcesjf_ is now known as him-cesjf

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!