CBL-Mariner/SPECS/shim-unsigned-x64
Christopher Co 8d6824e872
[main] shim: update shim bootloader (#2173)
* [1.0] shim: update shim bootloader (#2157)

* shim: update key used

Our current keys have a 1 year expiration time, and it will expire
shortly. Update the key to one that will expire in 10/13/22. Ultimately
we plan to move to a longer lived CA cert once that is made available.

* shim: Add critical patches

* shim: Update to new signed shim bootloader binary

New shim bootloader contains the renewed Mariner Secure Boot Production
key embedded inside. And this shim binary itself is signed with the MS
UEFI CA.

* grub: bump release number to force re-signing

In order to not regress current users of the grub2-2.06~rc1-7 package,
bump release number which will cause the newer grubx64.efi inside the
grub2-efi-binary-2.06~rc1-8 package to be signed with the updated secure
boot key that matches with the one embedded in the 15.4-2 shim binary.

* License verified

Signed-off-by: Chris Co <chrco@microsoft.com>
2022-02-09 18:35:20 -08:00
..
Don-t-call-QueryVariableInfo-on-EFI-1.10-machines.patch [main] shim: update shim bootloader (#2173) 2022-02-09 18:35:20 -08:00
Fix-a-broken-file-header-on-ia32.patch [main] shim: update shim bootloader (#2173) 2022-02-09 18:35:20 -08:00
Fix-handling-of-ignore_db-and-user_insecure_mode.patch [main] shim: update shim bootloader (#2173) 2022-02-09 18:35:20 -08:00
Relax-the-check-for-import_mok_state.patch [main] shim: update shim bootloader (#2173) 2022-02-09 18:35:20 -08:00
cbl-mariner-ca-20211013.der [main] shim: update shim bootloader (#2173) 2022-02-09 18:35:20 -08:00
mok-allocate-MOK-config-table-as-BootServicesData.patch [main] shim: update shim bootloader (#2173) 2022-02-09 18:35:20 -08:00
sbat.csv.in shim-unsigned: update to shim-15.4 release (#819) 2021-04-05 16:05:55 -07:00
shim-another-attempt-to-fix-load-options-handling.patch [main] shim: update shim bootloader (#2173) 2022-02-09 18:35:20 -08:00
shim-unsigned-x64.signatures.json [main] shim: update shim bootloader (#2173) 2022-02-09 18:35:20 -08:00
shim-unsigned-x64.spec [main] shim: update shim bootloader (#2173) 2022-02-09 18:35:20 -08:00