From 668a99da6e6843f84cfdaff97f38ee184dec45e5 Mon Sep 17 00:00:00 2001 From: Eugene Zamriy Date: Wed, 22 Mar 2023 22:42:30 +0300 Subject: [PATCH] Use MSVSphere vendor certificate and SBAT entry --- SOURCES/redhatsecurebootca5.cer | Bin 920 -> 0 bytes SOURCES/sbat.msvsphere.csv | 1 + SOURCES/sbat.redhat.csv | 1 - SOURCES/spheresecurebootca.cer | Bin 0 -> 1124 bytes SPECS/shim-unsigned-x64.spec | 13 +++++++------ 5 files changed, 8 insertions(+), 7 deletions(-) delete mode 100644 SOURCES/redhatsecurebootca5.cer create mode 100644 SOURCES/sbat.msvsphere.csv delete mode 100644 SOURCES/sbat.redhat.csv create mode 100644 SOURCES/spheresecurebootca.cer diff --git a/SOURCES/redhatsecurebootca5.cer b/SOURCES/redhatsecurebootca5.cer deleted file mode 100644 index dfb0284954861282d1a0ce16c8c5cdc71c27659f..0000000000000000000000000000000000000000 GIT binary patch literal 0 HcmV?d00001 literal 920 zcmXqLVxD5q#8k6@nTe5!iIbtZm{+@~;bN2lFB_*;n@8JsUPeZ4RtAH3LoovpHs(+k zE*{>X)D#7e#1b6^&%9(kLq!95kT^4s1XNrhI5oMnC{@8JKfgr5*-^pNP{}|6ZW6NxP$#b?ru1p1aqn$3D)YB{Qqo zjCvjz?|=HkE#3AN-xTZpws*U~)f@DZ{t~uwMZy8<;F%jD%$u6!n#qYzp^Sryh{C;x9qf@!N=T4ui@b#({ zSD&^p3kNZ=9lAQ9%xdfP9doNToV+k2^LHOFD{5oE&78StJa^8n7$i2k94PWc<&xr*# z`sciS&XK#@>h!OC8{=mczNLHbADCJ+pE=-CsaDOF#s}?5Q)1qq&%R~#cz>QmiAiVx zk5XXYstAL9d+iK-w@u$FESybMIPOFY~9lmn~9nUf%vMc88@((p0B(#qL+!COmt7`j5IhPVzo{cRPw} Pd!}BnFF!b8N6JS4>O*3Z diff --git a/SOURCES/sbat.msvsphere.csv b/SOURCES/sbat.msvsphere.csv new file mode 100644 index 0000000..604d3dc --- /dev/null +++ b/SOURCES/sbat.msvsphere.csv @@ -0,0 +1 @@ +shim.msvsphere,2,MSVSphere,shim,15.6,security@msvsphere.ru diff --git a/SOURCES/sbat.redhat.csv b/SOURCES/sbat.redhat.csv deleted file mode 100644 index 2135543..0000000 --- a/SOURCES/sbat.redhat.csv +++ /dev/null @@ -1 +0,0 @@ -shim.redhat,1,Red Hat Inc,shim,15.5,secalert@redhat.com diff --git a/SOURCES/spheresecurebootca.cer b/SOURCES/spheresecurebootca.cer new file mode 100644 index 0000000000000000000000000000000000000000..4db57d718fca340fe0ff696e62220d884a018630 GIT binary patch literal 1124 zcmXqLVo5M)V)j_T%*4pVB*@UFZ|Ac~&52=$)koFJd47%tylk9WZ60mkc^MhGSs4r( zw;O61Xs|JdvTzG4`UZyu7i6Rsr7Ae57L{bCWhN(Uj`GK|oO=K5l^UW_#&M$`vaKHt)4LCt6*o2vaLJb8C z_(2>lVGcj%U>5}+A7?{F19^}Tv#jE#&8%}k6; zO`;_DjSNhY1%|NSni!RkBZ`rgfw_s1pTVGsk&CH`k&)qy#MZ1z^zt>jxZ94nKTmE^M<0hY`(;FOC{bDXmj@ll5 zfzjN*!#8iq-SrRJ&rNO1i(h$uf^v=AmSPQI2j8je@7>NHb$k}P{9#zWL2vOg@9*K9 zjO%9{d3Pge!>XJ6vM)!7&t(*OQ4{$w<(~J>hlM=vh56>){P8m(X&Rr;uXyg5M_=aF zd#c!cIl(KUeOi9wq&poe9vyE}JQ=WZwvhcDaW<#01Nk%5*d9vS-aEhO#K!LpZFb*{ zFP{1_H<)#oj*G%$*%tn!Bohs^qCQPsfM5ln%Bn(kS{dtCESCk%4h> zvOyv^naC=$NEnDUhL)qojD8OVYZ@Ue)oVAqeDUx3lT$WR?%Tx=Jgvr|UhKjU<`Mb-E4!#Sr9##LD_ zyRdQN$y&*e4)&ZXzdvy--#x{_H}-6Sn*7cAbGPT!_Uu_z-?h)_K+o-_?6n*g+8Y-h z>G{I3^L6cuh4-1=pUQbp_4i-G>a=%G{)fG9{r7*rvUchFJejrg((d}cw%c;yfu;7` zqMidQ`kKxve{oL^tnfPfBE+3@;o0}w_a8NQrowmlYpQqT|B^Ogwv}317JFH}z6-s+ z_4eVyYL!jFN+&&+hCk5h{FgL!Q;!#W?}?3 o*v!l5eqe(MqtJoFZrNUcvI?gcr!@R*dbc-^q4#{~_u5O(04vs^n*aa+ literal 0 HcmV?d00001 diff --git a/SPECS/shim-unsigned-x64.spec b/SPECS/shim-unsigned-x64.spec index c5317bc..bac5fc1 100644 --- a/SPECS/shim-unsigned-x64.spec +++ b/SPECS/shim-unsigned-x64.spec @@ -1,7 +1,7 @@ %global pesign_vre 0.106-1 %global openssl_vre 1.0.2j -%global efidir %(eval echo $(grep ^ID= /etc/os-release | sed -e 's/^ID=//' -e 's/rhel/redhat/')) +%global efidir msvsphere %global shimrootdir %{_datadir}/shim/ %global shimversiondir %{shimrootdir}/%{version}-%{release} %global efiarch x64 @@ -20,17 +20,17 @@ Name: shim-unsigned-%{efiarch} Version: 15.6 -Release: 1.el9 +Release: 1.el9.inferit Summary: First-stage UEFI bootloader ExclusiveArch: x86_64 License: BSD URL: https://github.com/rhboot/shim Source0: https://github.com/rhboot/shim/releases/download/%{version}/shim-%{version}.tar.bz2 -Source1: redhatsecurebootca5.cer +Source1: spheresecurebootca.cer %if 0%{?dbxfile} Source2: %{dbxfile} %endif -Source3: sbat.redhat.csv +Source3: sbat.msvsphere.csv Source4: shim.patches Source100: shim-find-debuginfo.sh @@ -158,8 +158,9 @@ cd .. %files debugsource -f build-%{efiarch}/debugsource.list %changelog -* Wed Mar 15 2023 MSVSphere Packaging Team - 15.6-1 -- Rebuilt for MSVSphere 9.1. +* Wed Mar 22 2023 Eugene Zamriy - 15.6-1.inferit +- Use MSVSphere vendor certificate and SBAT entry +- Rebuilt for MSVSphere 9.1 * Wed Jun 01 2022 Peter Jones - 15.6-1.el9 - Update to shim-15.6