From 9c8c27be725df83963ff8a188d33e20a4a3d7043 Mon Sep 17 00:00:00 2001 From: Alexander Filippov Date: Wed, 27 May 2020 14:57:27 +0300 Subject: meta-nicole: Add image signature verification Adds a firmware image signature verification. This brings: - The key is stored in `/etc/activationdata` folder. - The software item activation now begins with signature verification. The verification failure stops the activation only when the `fieldMode` is set to true. See https://github.com/openbmc/phosphor-dbus-interfaces/blob/master/xyz/openbmc_project/Control/FieldMode.interface.yaml (From meta-yadro rev: f9e0ad9f1bb2a2520651f771e2b873bef384423a) Change-Id: I91cf92d15d29737a9cd05120b194189eb767636e Signed-off-by: Alexander Filippov Signed-off-by: Andrew Geissler --- .../recipes-phosphor/flash/openpower-software-manager_%.bbappend | 1 + .../recipes-phosphor/flash/phosphor-software-manager_%.bbappend | 1 + 2 files changed, 2 insertions(+) create mode 100644 meta-yadro/meta-nicole/recipes-phosphor/flash/openpower-software-manager_%.bbappend create mode 100644 meta-yadro/meta-nicole/recipes-phosphor/flash/phosphor-software-manager_%.bbappend (limited to 'meta-yadro/meta-nicole/recipes-phosphor/flash') diff --git a/meta-yadro/meta-nicole/recipes-phosphor/flash/openpower-software-manager_%.bbappend b/meta-yadro/meta-nicole/recipes-phosphor/flash/openpower-software-manager_%.bbappend new file mode 100644 index 000000000..a2df9cf70 --- /dev/null +++ b/meta-yadro/meta-nicole/recipes-phosphor/flash/openpower-software-manager_%.bbappend @@ -0,0 +1 @@ +PACKAGECONFIG_append = " verify_pnor_signature" diff --git a/meta-yadro/meta-nicole/recipes-phosphor/flash/phosphor-software-manager_%.bbappend b/meta-yadro/meta-nicole/recipes-phosphor/flash/phosphor-software-manager_%.bbappend new file mode 100644 index 000000000..c92b1a89c --- /dev/null +++ b/meta-yadro/meta-nicole/recipes-phosphor/flash/phosphor-software-manager_%.bbappend @@ -0,0 +1 @@ +PACKAGECONFIG_append = " verify_signature" -- cgit v1.2.3