Index | index by Group | index by Distribution | index by Vendor | index by creation date | index by Name | Mirrors | Help | Search |
Name: mokutil | Distribution: SUSE Linux Enterprise 15 |
Version: 0.5.0 | Vendor: SUSE LLC <https://www.suse.com/> |
Release: 150600.8.3 | Build date: Thu May 9 17:11:08 2024 |
Group: Productivity/Security | Build host: ibs-power9-12 |
Size: 110434 | Source RPM: mokutil-0.5.0-150600.8.3.src.rpm |
Packager: https://www.suse.com/ | |
Url: https://github.com/lcp/mokutil | |
Summary: Tools for manipulating machine owner keys |
This program provides the means to enroll and erase the machine owner keys (MOK) stored in the database of shim.
GPL-3.0-only
* Thu May 05 2022 jlee@suse.com - Add the following patches against bsc#1198458 mokutil-enable-setting-fallback-verbosity-and-norebo.patch mokutil-SBAT-revocation-update-support.patch * Thu Jul 15 2021 glin@suse.com - Update to 0.5.0 + mokutil: delete key/hash from the reverse request + efi_x509: fix an error handling in is_immediate_ca() + efi_x509: fix certificates fingerprint calculation + efi_x509: use EVP_Digest()* functions instead of the deprecated SHA1_*() + src/util.c: fix NULL pointer dereference in mok_get_variable + mokutil: Read the SbatLevelRT variable to get the SBAT entries + mokutil: add mok-variables parsing support + mokutil: Add option to print the UEFI SBAT variable content + mokutil: only check for Secure Boot support in options that need it + efi_x509: add the function to fetch SKID + keyring: add the function to check kernel keyring + mokutil: initialize data for efi_get_variable() + mokutil: correct the data for efi_set_variable() in set_password() + mokutil: improve the readability of issue_mok_request() + mokutil: drop the checks for PK and KEK + mokutil: check the blocklists before enrolling a key + mokutil: adjust the command bits + mokutil: remove "--simple-hash" + make CA check non-fatal + mokutil: close file in the error path + mokutil: do the CA check + efi_x509: add the function to check immediate CA + efi_x509: use d2i_X509() to create X509 handling + mokutil: rename hash_file as pw_hash_file + password-crypt: update the function names + password-crypt: fix the types of several functions + mokutil: fix the error message in sb_state() + mokutil: move x509 functions to efi_x509.c + mokutil: move the hash functions to efi_hash.c + util: add functions for db_var_name and db_friendly_name + Remove the SHA1 code from identify_hash_type() + Map the UEFI variable names with a function + Fix -Wcast-align warnings + Fix 32 bit build + Add --timeout to manpage and other corrections. + mokutil.c: fix typo enrollement -> enrollment + Avoid taking pointer to packed struct + Fix name of --enable-validation in the description + Remove shebang from bash-completion/mokutil - Add mokutil-fix-missing-header.patch to fix the compilation error due to the missing header - Refresh mokutil-remove-libkeyutils-check.patch and only apply it to openSUSE Leap 15.* - Drop upstreamed patches: + mokutil-remove-shebang-from-bash-completion-file.patch + mokutil-bsc1173115-add-ca-and-keyring-checks.patch - Drop mokutil-support-revoke-builtin-cert.patch since we don't use the builtin cert prompt patch in shim anymore. * Tue May 04 2021 dmueller@suse.com - spec file cleanup * Wed Sep 16 2020 glin@suse.com - Add mokutil-bsc1173115-add-ca-and-keyring-checks.patch to add options for CA and kernel keyring checks (bsc#1173115) + Add new BuildRequires: keyutils-devel + Add mokutil-remove-libkeyutils-check.patch to disable the version check of libkeyutils - Refresh mokutil-support-revoke-builtin-cert.patch * Fri Aug 14 2020 glin@suse.com - Update mokutil-support-revoke-builtin-cert.patch + Add "--revoke-cert" to the man page * Fri Dec 13 2019 normand@linux.vnet.ibm.com - Add build for ppc64/ppc64le * Tue May 28 2019 glin@suse.com - Update to 0.4.0 + Rename export_moks as export_db_keys + Add support for exporting other keys + add new --mok argument + set list-enrolled command as default for some arguments + Add more info to --sb-state: show when we're in SetupMode or with shim validation disabled + Correct help: --set-timeout is really --timeout + generate_hash() / generate_pw_hash(): don't use strlen() for strncpy bounds + Add the type casting to silence the warning + Add a way for mokutil to configure a timeout for MokManager's prompt + list_keys_in_var(): check errno correctly, not ret twice + Fix typo in error message when the system lacks Secure Boot support + Add bash completion file + mokutil: be explicit about file modes in all cases + Make all efi_guid_t const + Don't allow sha1 on the mokutil command line + Build with -fshort-wchar so toggle passwords work right + Fix the 32bit signedness comparison + Fix the potential buffer overflow - Add mokutil-remove-shebang-from-bash-completion-file.patch to remove shebang from bash-completion/mokutil - Drop upstreamed patches + mokutil-constify-efi-guid.patch + mokutil-fix-overflow.patch + mokutil-fshort-wchar.patch + mokutil-set-efi-variable-file-mode.patch - Refresh mokutil-support-revoke-builtin-cert.patch - Install bash-completion/mokutil * Thu Mar 21 2019 glin@suse.com - Add modhash to calculate the hash of kernel module (SLE-5661) + Also add openssl to Requires since the script needs it * Fri Nov 23 2018 glin@suse.com - Enable AArch64 build (bsc#1119769, fate#326541) * Tue Mar 27 2018 kukuk@suse.de - Use %license instead of %doc [bsc#1082318] * Wed Jul 13 2016 glin@suse.com - Patches for efivar 0.24 + Add mokutil-set-efi-variable-file-mode.patch to set the file mode explicitly. + Add mokutil-constify-efi-guid.patch to make all efi_guild_t variables const. + Refresh mokutil-support-revoke-builtin-cert.patch for the change of efi_set_variable() * Tue Jun 30 2015 glin@suse.com - Add mokutil-fshort-wchar.patch to make sure the UEFI strings are UCS-2 encoding. * Tue Nov 04 2014 glin@suse.com - Update to 0.3.0 - Add mokutil-fix-overflow.patch to fix the buffer overflow - Drop upstreamed patches + mokutil-upstream-fixes.patch + mokutil-mokx-support.patch + mokutil-check-corrupted-key-list.patch + mokutil-check-secure-boot-support.patch + mokutil-clean-request.patch + mokutil-fix-hash-file-read.patch + mokutil-fix-hash-list-size.patch + mokutil-more-details-for-skipped-keys.patch + mokutil-no-invalid-x509.patch - Refresh mokutil-support-revoke-builtin-cert.patch
/usr/bin/modhash /usr/bin/mokutil /usr/share/bash-completion/completions /usr/share/bash-completion/completions/mokutil /usr/share/licenses/mokutil /usr/share/licenses/mokutil/COPYING /usr/share/man/man1/mokutil.1.gz
Generated by rpm2html 1.8.1
Fabrice Bellet, Tue Jul 9 19:51:39 2024