Adding keys to BMC production build

Bruce Mitchell Bruce.Mitchell at ibm.com
Fri Mar 12 01:57:22 AEDT 2021



-----"openbmc" <openbmc-bounces+bruce.mitchell=ibm.com at lists.ozlabs.org> wrote: -----

>To: Patrick Voelker <Patrick_Voelker at phoenix.com>, "OpenBMC
>(openbmc at lists.ozlabs.org)" <openbmc at lists.ozlabs.org>
>From: Troy Lee
>Sent by: "openbmc"
>Date: 03/10/2021 18:35
>Subject: [EXTERNAL] RE: Adding keys to BMC production build
>
> Hi Patrick, You could assign SIGNING_KEY
>to your private key for signing image. If it is not set,
>meta-phosphor/recipes-phosphor/flash/phosphor-insecure-signing-key
>-native.bb will be applied. Thanks, ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍
>‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍
>
>
> Hi Patrick,
>  
> You could assign SIGNING_KEY to your private key for signing
>image.
> If it is not set,
>meta-phosphor/recipes-phosphor/flash/phosphor-insecure-signing-key
>-native.bb will be applied.
>  
> Thanks,
> Troy Lee
>  
>
>
> From: openbmc
><openbmc-bounces+troy_lee=aspeedtech.com at lists.ozlabs.org> On
>Behalf Of Patrick Voelker
> Sent: Thursday, March 11, 2021 10:18 AM
> To: OpenBMC (openbmc at lists.ozlabs.org) <openbmc at lists.ozlabs.org>
> Subject: Adding keys to BMC production build
>  
> Is there a page or document with instructions for adding a custom
>key for signing the production BMC build? I haven't had any luck
>finding it yet.
>

Hi Patrick,

Also check with Klaus as well.

--
Bruce




More information about the openbmc mailing list