From cf67f01008fbc06064ffbc4e99043a8363bdaada Mon Sep 17 00:00:00 2001 From: Adriana Kobylak Date: Mon, 7 May 2018 13:31:10 -0500 Subject: Witherspoon: Enable PNOR signature verification Enable signature verification in the openpower-software-manager code for witherspoon. This causes an error to be logged if updating to an unsigned image, or image signed with a different key than the one on the system, and if field mode is set, it'll stop the activation process. Tested: PNOR signature verification is enforced on witherspoon, verified error is logged with and without field mode enabled, and activation is prevented with field mode enabled. Change-Id: I6b8b74f146066da058e137779faf9af157f7131b Signed-off-by: Adriana Kobylak --- .../recipes-phosphor/flash/openpower-software-manager.bbappend | 1 + 1 file changed, 1 insertion(+) create mode 100644 meta-openbmc-machines/meta-openpower/meta-ibm/meta-witherspoon/recipes-phosphor/flash/openpower-software-manager.bbappend (limited to 'meta-openbmc-machines/meta-openpower/meta-ibm/meta-witherspoon/recipes-phosphor') diff --git a/meta-openbmc-machines/meta-openpower/meta-ibm/meta-witherspoon/recipes-phosphor/flash/openpower-software-manager.bbappend b/meta-openbmc-machines/meta-openpower/meta-ibm/meta-witherspoon/recipes-phosphor/flash/openpower-software-manager.bbappend new file mode 100644 index 000000000..3dcc25dd7 --- /dev/null +++ b/meta-openbmc-machines/meta-openpower/meta-ibm/meta-witherspoon/recipes-phosphor/flash/openpower-software-manager.bbappend @@ -0,0 +1 @@ +PACKAGECONFIG_append_df-openpower-ubi-fs = " verify_pnor_signature" -- cgit v1.2.3