From patchwork Fri Oct 1 15:44:32 2021 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Dimitri John Ledkov X-Patchwork-Id: 1535397 Return-Path: X-Original-To: incoming@patchwork.ozlabs.org Delivered-To: patchwork-incoming@bilbo.ozlabs.org Authentication-Results: bilbo.ozlabs.org; dkim=fail reason="signature verification failed" (2048-bit key; unprotected) header.d=canonical.com header.i=@canonical.com header.a=rsa-sha256 header.s=20210705 header.b=WJKn8Jn8; dkim-atps=neutral Authentication-Results: ozlabs.org; spf=none (no SPF record) smtp.mailfrom=lists.ubuntu.com (client-ip=91.189.94.19; helo=huckleberry.canonical.com; envelope-from=kernel-team-bounces@lists.ubuntu.com; receiver=) Received: from huckleberry.canonical.com (huckleberry.canonical.com [91.189.94.19]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by bilbo.ozlabs.org (Postfix) with ESMTPS id 4HLZFf0LTgz9t0T for ; Sat, 2 Oct 2021 01:45:42 +1000 (AEST) Received: from localhost ([127.0.0.1] helo=huckleberry.canonical.com) by huckleberry.canonical.com with esmtp (Exim 4.86_2) (envelope-from ) id 1mWKj6-0008TZ-7I; Fri, 01 Oct 2021 15:45:32 +0000 Received: from smtp-relay-internal-0.internal ([10.131.114.225] helo=smtp-relay-internal-0.canonical.com) by huckleberry.canonical.com with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.86_2) (envelope-from ) id 1mWKik-00089d-6P for kernel-team@lists.ubuntu.com; Fri, 01 Oct 2021 15:45:10 +0000 Received: from mail-wm1-f72.google.com (mail-wm1-f72.google.com [209.85.128.72]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by smtp-relay-internal-0.canonical.com (Postfix) with ESMTPS id 4ECE1405FA for ; Fri, 1 Oct 2021 15:45:09 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=canonical.com; s=20210705; t=1633103109; bh=80J4PpGQRYWfHq3uf4ZxDNjkBVI3oCCtpivvaF1mWqU=; h=From:To:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=WJKn8Jn8VlklWizmGq9JzlNOpAqKipTCYSMse00qOb61YE585rcYHFbnsrzxffJ8m uAqDO+KTTU37BzPa8XPFRCso4YeQ3tPGOw7n1OBmmapm971M3ThB/NzC/mODkQ7Rms IriHQntKfEuc/qfMmkTdCSJGAt9SEUtRZUTvBFG9sPkfMwJF82XjeVTjd1cNX+CuzQ ysn0ZN1QRXiTbypoKZaoiOGvauEG54rfs2LcQaQa10UWTomX2UeIB+4O5PtqRDSEMy vDqRZC7yb6XrKdxAjVbL2I5aWQpUJ9lPfc7aDiLO9LsdKBNTJHRTl2S0o9VGykpOCd FUtMApgz1sppg== Received: by mail-wm1-f72.google.com with SMTP id 10-20020a05600c240a00b0030d403f24e2so1990133wmp.9 for ; Fri, 01 Oct 2021 08:45:09 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=x-gm-message-state:from:to:subject:date:message-id:in-reply-to :references:mime-version:content-transfer-encoding; bh=80J4PpGQRYWfHq3uf4ZxDNjkBVI3oCCtpivvaF1mWqU=; b=l5zh9EVl3OBbTA/3729xFv3Mqhs8Kcb35LoSPJ35MJ0fzAB8M9mSrcECB0UalVfMoC TWVIxjwsVkrA4KLvRc6O8apSLMIpic5Njbt00Gefyi8OpIYWJO3oaaGMC2SmkCSS42Rl L14Mkz0Q/cRzahqQ87wNAXdVe7d5NxOkSeoer5Bxppv5SYmN3b1r3qCTpZbeTWLyVPl3 vGFgvX7dPTHWOGdPixR9wCnH2LuDtNr773CMUm743QzrK7yujOU3zloL/f519fvAwCxz 16nfoDSDlp6nlzVWUjkOz3Dmy/OKKewbEgo4fHwg4cwOGPhFiPepGsv6k9yFWvzNoQB3 bpyg== X-Gm-Message-State: AOAM533jhXc+0LlPmkWphMf6aFz/BnxbTuroHCoTsCwojsiNyE893W4g gT7yuNkqb2KLtft+po2TUUxXNZW3Qs7Jx2qXmQ45tHMP14AdKCUEPrSVRSxL6Ar51faA7riMlnV evZ3nTXzXEJXtdKFW51TPKj11aMEYWXztVm95ZRjvBA== X-Received: by 2002:adf:f789:: with SMTP id q9mr13396882wrp.367.1633103108735; Fri, 01 Oct 2021 08:45:08 -0700 (PDT) X-Google-Smtp-Source: ABdhPJw3Y7/ftCnl51Fp0SPeRBztk1+B0nHLM5sqeLDINR0lA4IATv/OyyZ96LWY5KqFohbQAfJzLA== X-Received: by 2002:adf:f789:: with SMTP id q9mr13396859wrp.367.1633103108501; Fri, 01 Oct 2021 08:45:08 -0700 (PDT) Received: from localhost ([2a01:4b00:85fd:d700:dd38:5596:506f:f213]) by smtp.gmail.com with ESMTPSA id u1sm7604533wmc.29.2021.10.01.08.45.07 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 01 Oct 2021 08:45:08 -0700 (PDT) From: Dimitri John Ledkov To: kernel-team@lists.ubuntu.com Subject: [SRU][FOCAL][PATCH 16/16] UBUNTU: [Config] Configure CONFIG_SYSTEM_REVOCATION_KEYS with revoked keys Date: Fri, 1 Oct 2021 16:44:32 +0100 Message-Id: <20211001154432.20287-17-dimitri.ledkov@canonical.com> X-Mailer: git-send-email 2.30.2 In-Reply-To: <20211001154432.20287-1-dimitri.ledkov@canonical.com> References: <20211001154432.20287-1-dimitri.ledkov@canonical.com> MIME-Version: 1.0 X-BeenThere: kernel-team@lists.ubuntu.com X-Mailman-Version: 2.1.20 Precedence: list List-Id: Kernel team discussions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: kernel-team-bounces@lists.ubuntu.com Sender: "kernel-team" BugLink: https://bugs.launchpad.net/bugs/1932029 Signed-off-by: Dimitri John Ledkov Signed-off-by: Andrea Righi (cherry picked from commit 741f622c4dbc162b82f8c9045f9c6c6446f57eb5) (xnox: cherry-pick is from impish:linux) Signed-off-by: Dimitri John Ledkov --- debian.master/config/annotations | 1 + debian.master/config/config.common.ubuntu | 1 + 2 files changed, 2 insertions(+) diff --git a/debian.master/config/annotations b/debian.master/config/annotations index b23d62dbd7..03b21b4d88 100644 --- a/debian.master/config/annotations +++ b/debian.master/config/annotations @@ -364,6 +364,7 @@ CONFIG_SYSTEM_TRUSTED_KEYRING policy<{'amd64': 'y', 'arm64': ' CONFIG_SYSTEM_TRUSTED_KEYS policy<{'amd64': '"debian/canonical-certs.pem"', 'arm64': '"debian/canonical-certs.pem"', 'armhf': '"debian/canonical-certs.pem"', 'i386': '"debian/canonical-certs.pem"', 'ppc64el': '"debian/canonical-certs.pem"', 's390x': '"debian/canonical-certs.pem"'}> CONFIG_SYSTEM_EXTRA_CERTIFICATE policy<{'amd64': 'y', 'arm64': 'y', 'armhf': 'y', 'i386': 'y', 'ppc64el': 'y', 's390x': 'y'}> CONFIG_SYSTEM_EXTRA_CERTIFICATE_SIZE policy<{'amd64': '4096', 'arm64': '4096', 'armhf': '4096', 'i386': '4096', 'ppc64el': '4096', 's390x': '4096'}> +CONFIG_SYSTEM_REVOCATION_KEYS policy<{'amd64': '"debian/canonical-revoked-certs.pem"', 'arm64': '"debian/canonical-revoked-certs.pem"', 'armhf': '"debian/canonical-revoked-certs.pem"', 'ppc64el': '"debian/canonical-revoked-certs.pem"', 's390x': '"debian/canonical-revoked-certs.pem"'}> CONFIG_SECONDARY_TRUSTED_KEYRING policy<{'amd64': 'y', 'arm64': 'y', 'armhf': 'y', 'i386': 'y', 'ppc64el': 'y', 's390x': 'y'}> # Menu: Cryptographic API >> Hardware crypto devices diff --git a/debian.master/config/config.common.ubuntu b/debian.master/config/config.common.ubuntu index c6bb6db066..bc171d7f06 100644 --- a/debian.master/config/config.common.ubuntu +++ b/debian.master/config/config.common.ubuntu @@ -9925,6 +9925,7 @@ CONFIG_SYSTEM_BLACKLIST_KEYRING=y CONFIG_SYSTEM_DATA_VERIFICATION=y CONFIG_SYSTEM_EXTRA_CERTIFICATE=y CONFIG_SYSTEM_EXTRA_CERTIFICATE_SIZE=4096 +CONFIG_SYSTEM_REVOCATION_KEYS="debian/canonical-revoked-certs.pem" CONFIG_SYSTEM_REVOCATION_LIST=y CONFIG_SYSTEM_TRUSTED_KEYRING=y CONFIG_SYSTEM_TRUSTED_KEYS="debian/canonical-certs.pem"