]> git.proxmox.com Git - proxmox-secure-boot-support.git/log
proxmox-secure-boot-support.git
2 months agobump version to 1.0.8 master
Fabian Grünbichler [Wed, 3 Jul 2024 10:15:56 +0000 (12:15 +0200)]
bump version to 1.0.8

Signed-off-by: Fabian Grünbichler <f.gruenbichler@proxmox.com>
2 months agobump version to 1.0.7
Fabian Grünbichler [Fri, 28 Jun 2024 08:06:16 +0000 (10:06 +0200)]
bump version to 1.0.7

Signed-off-by: Fabian Grünbichler <f.gruenbichler@proxmox.com>
2 months agobump shim-signed to 1.42
Fabian Grünbichler [Fri, 28 Jun 2024 08:02:07 +0000 (10:02 +0200)]
bump shim-signed to 1.42

Debian did another bump, ensure we are higher than it.

Signed-off-by: Fabian Grünbichler <f.gruenbichler@proxmox.com>
2 months agobump version to 1.0.6
Fabian Grünbichler [Thu, 27 Jun 2024 09:23:41 +0000 (11:23 +0200)]
bump version to 1.0.6

Signed-off-by: Fabian Grünbichler <f.gruenbichler@proxmox.com>
2 months agobump shim-signed to 1.41
Fabian Grünbichler [Thu, 27 Jun 2024 09:22:27 +0000 (11:22 +0200)]
bump shim-signed to 1.41

Signed-off-by: Fabian Grünbichler <f.gruenbichler@proxmox.com>
2 months agobump version to 1.0.3
Thomas Lamprecht [Fri, 21 Jun 2024 09:14:43 +0000 (11:14 +0200)]
bump version to 1.0.3

Signed-off-by: Thomas Lamprecht <t.lamprecht@proxmox.com>
2 months agod/lintian: add override fir package-installs-apt-preferences
Thomas Lamprecht [Fri, 21 Jun 2024 09:10:12 +0000 (11:10 +0200)]
d/lintian: add override fir package-installs-apt-preferences

it's indeed not really nice that we have to resort to this but we
found no good alternative so this is by design -> avoid erroring out
on lintian checking.

Signed-off-by: Thomas Lamprecht <t.lamprecht@proxmox.com>
2 months agoship apt pinning snippet
Fabian Grünbichler [Fri, 21 Jun 2024 07:04:17 +0000 (09:04 +0200)]
ship apt pinning snippet

this should ensure that a shim-signed package from a non-Proxmox repository
cannot overtake ours, even if the version is newer. since
proxmox-secure-boot-support is optional, this is entirely opt-in.

Signed-off-by: Fabian Grünbichler <f.gruenbichler@proxmox.com>
3 months agobump version to 1.0.4
Fabian Grünbichler [Wed, 5 Jun 2024 10:49:43 +0000 (12:49 +0200)]
bump version to 1.0.4

Signed-off-by: Fabian Grünbichler <f.gruenbichler@proxmox.com>
3 months agobump shim-signed to 15.8
Fabian Grünbichler [Wed, 5 Jun 2024 10:49:20 +0000 (12:49 +0200)]
bump shim-signed to 15.8

Signed-off-by: Fabian Grünbichler <f.gruenbichler@proxmox.com>
4 months agobump version to 1.0.3
Fabian Grünbichler [Fri, 10 May 2024 07:41:37 +0000 (09:41 +0200)]
bump version to 1.0.3

Signed-off-by: Fabian Grünbichler <f.gruenbichler@proxmox.com>
4 months agobump version to 1.0.3~presign2
Fabian Grünbichler [Fri, 10 May 2024 07:36:06 +0000 (09:36 +0200)]
bump version to 1.0.3~presign2

Signed-off-by: Fabian Grünbichler <f.gruenbichler@proxmox.com>
4 months agobump version to 1.0.3~presign1
Fabian Grünbichler [Fri, 10 May 2024 07:32:26 +0000 (09:32 +0200)]
bump version to 1.0.3~presign1

Signed-off-by: Fabian Grünbichler <f.gruenbichler@proxmox.com>
4 months agod/control: support last two grub versions as valid dependency
Thomas Lamprecht [Fri, 19 Apr 2024 08:41:51 +0000 (10:41 +0200)]
d/control: support last two grub versions as valid dependency

Uploading grub is a two-step process, where code-signing is done
through an HSM on a separate, isolated, and secured host.
So, it happens that the repo contains the newer proxmox-grub already
but still the old signed shim, with throws of our check that ensures
installability w.r.t. dependency constraints in the whole repo.

Allowing both versions is additionally providing some slightly better
UX, as users can more easily downgrade (without scary apt removal
warnings).

We might to have to do the same for the shim, but wait for that until
we actually have a newer version that is supported and asses then if
that's OK w.r.t. security promises to factory provided secure boot
project.

Signed-off-by: Thomas Lamprecht <t.lamprecht@proxmox.com>
4 months agod/control: wrap-and-sort -tkn
Thomas Lamprecht [Fri, 19 Apr 2024 08:39:33 +0000 (10:39 +0200)]
d/control: wrap-and-sort -tkn

Signed-off-by: Thomas Lamprecht <t.lamprecht@proxmox.com>
4 months agobump version to 1.0.2
Thomas Lamprecht [Fri, 19 Apr 2024 08:35:34 +0000 (10:35 +0200)]
bump version to 1.0.2

Signed-off-by: Thomas Lamprecht <t.lamprecht@proxmox.com>
4 months agod/control: bump depedency for signed grub meta package to 2.06-13+pmx2
Thomas Lamprecht [Fri, 19 Apr 2024 08:35:00 +0000 (10:35 +0200)]
d/control: bump depedency for signed grub meta package to 2.06-13+pmx2

Signed-off-by: Thomas Lamprecht <t.lamprecht@proxmox.com>
4 months agobump version to 1.0.1
Thomas Lamprecht [Fri, 19 Apr 2024 08:24:58 +0000 (10:24 +0200)]
bump version to 1.0.1

Signed-off-by: Thomas Lamprecht <t.lamprecht@proxmox.com>
4 months agod/control: bump dependency for our grub meta package to 2.06-13+pmx2
Thomas Lamprecht [Fri, 19 Apr 2024 08:19:37 +0000 (10:19 +0200)]
d/control: bump dependency for our grub meta package to 2.06-13+pmx2

Got recently bumped for an opt-in quirk added to grub-mkrescue to
support installing the secure boot shim on our ISO.

Signed-off-by: Thomas Lamprecht <t.lamprecht@proxmox.com>
5 months agobuildsys: fix DEB variable name, just one package now
Thomas Lamprecht [Thu, 11 Apr 2024 10:46:56 +0000 (12:46 +0200)]
buildsys: fix DEB variable name, just one package now

earlier this was part of another repo, now it's separate and there is
just one package anymore, so use the correct DEB variable to refer to
the binary debian packages that get build.

Signed-off-by: Thomas Lamprecht <t.lamprecht@proxmox.com>
5 months agoInitial release
Fabian Grünbichler [Thu, 11 Apr 2024 08:35:07 +0000 (10:35 +0200)]
Initial release

Signed-off-by: Fabian Grünbichler <f.gruenbichler@proxmox.com>