diff options
author | Reka Norman <rekanorman@google.com> | 2023-04-20 15:50:06 +1000 |
---|---|---|
committer | Chromeos LUCI <chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com> | 2023-04-21 10:41:09 +0000 |
commit | 350498f03a000e43a2a39100c7722997ba0db074 (patch) | |
tree | 73c6e0d28201a6130815c93e1ed71651f6eb4d99 /scripts/image_signing/ensure_not_tainted_license.sh | |
parent | 0b0a37ea56a90c0ff396f476adf3fd814af789cc (diff) | |
download | vboot-350498f03a000e43a2a39100c7722997ba0db074.tar.gz |
sign_official_build: Add support for a second miniOS key
For recovery images, if minios_kernel.v1.keyblock exists, sign
- MINIOS-A with minios_kernel.v1.keyblock
- MINIOS-B with minios_kernel.keyblock
Otherwise, sign both with minios_kernel.keyblock.
BRANCH=None
BUG=b:266502803
TEST=- Run replace_recovery_key.sh in devkeys directory to get test keys
- Run sign_official_build.sh on a nissa recovery image
- Set recovery_key.v1.vbpubk in GBB and run recovery. After recovery
completes, check NBR still works.
- Repeat with recovery_key.vbpubk.
Change-Id: I2336e5261ef24114c5fee302ed95b4dfa1f67c11
Signed-off-by: Reka Norman <rekanorman@google.com>
Reviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform/vboot_reference/+/4452079
Tested-by: Reka Norman <rekanorman@chromium.org>
Commit-Queue: Reka Norman <rekanorman@chromium.org>
Reviewed-by: Julius Werner <jwerner@chromium.org>
Diffstat (limited to 'scripts/image_signing/ensure_not_tainted_license.sh')
0 files changed, 0 insertions, 0 deletions