Actions
action #164982
openImplement check that changes in https://progress.opensuse.org/issues/164150 are not used in official product
Start date:
2024-08-06
Due date:
% Done:
0%
Estimated time:
Difficulty:
Description
Slack discussion: https://suse.slack.com/archives/C03G45KTP6W/p1722850993683269
Summary: Stagings for SLFO don't use the official key, so secure boot doesn't work. Fabian came up with a workaround.
For stagings a firmware is used that accepts the components signed with the unofficial key.
Ask: Have a test that ensures that for SLFO non-staging environments these keys are not accepted.
Take one of the binaries signed by the unofficial key and try to use it, it should fail
Actions