From mboxrd@z Thu Jan 1 00:00:00 1970 Return-path: From: Bastian Krause Date: Mon, 8 Jun 2020 10:53:04 +0200 Message-Id: <20200608085305.30964-5-bst@pengutronix.de> In-Reply-To: <20200608085305.30964-1-bst@pengutronix.de> References: <20200608085305.30964-1-bst@pengutronix.de> MIME-Version: 1.0 Subject: [ptxdist] [PATCH 4/5] doc: dev_code_signing: rework and extend code signing section List-Id: PTXdist Development Mailing List List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Reply-To: ptxdist@pengutronix.de Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: base64 Errors-To: ptxdist-bounces@pengutronix.de Sender: "ptxdist" To: ptxdist@pengutronix.de Cc: rhi@pengutronix.de, Bastian Krause U2lnbmVkLW9mZi1ieTogQmFzdGlhbiBLcmF1c2UgPGJzdEBwZW5ndXRyb25peC5kZT4KLS0tCiBk b2MvZGV2X2NvZGVfc2lnbmluZy5yc3QgfCAxMzkgKysrKysrKysrKysrKysrKysrKysrKysrKysr KysrKystLS0tLS0tCiAxIGZpbGUgY2hhbmdlZCwgMTE2IGluc2VydGlvbnMoKyksIDIzIGRlbGV0 aW9ucygtKQoKZGlmZiAtLWdpdCBhL2RvYy9kZXZfY29kZV9zaWduaW5nLnJzdCBiL2RvYy9kZXZf Y29kZV9zaWduaW5nLnJzdAppbmRleCBkZTAwODdmOGIuLmM1YjU3ODZmOSAxMDA2NDQKLS0tIGEv ZG9jL2Rldl9jb2RlX3NpZ25pbmcucnN0CisrKyBiL2RvYy9kZXZfY29kZV9zaWduaW5nLnJzdApA QCAtMywzNCArMywxMjcgQEAKIENvZGUgU2lnbmluZwogLS0tLS0tLS0tLS0tCiAKLVRoaXMgaXMg YW4gb3ZlcnZpZXcgb3ZlciB0aGUgcHR4ZGlzdCBzaWduaW5nIGluZnJhc3RydWN0dXJlLgotcHR4 ZGlzdCB1c2VzIFBLQ1MjMTEgaW50ZXJuYWxseSBmb3IgcHJvdmlkaW5nIGFjY2VzcyB0byBrZXlz IGFuZCBjZXJ0aWZpY2F0ZXMuCi1QYWNrYWdlcyB0aGF0IHdpc2ggdG8gc2lnbiBzb21ldGhpbmcg c2hvdWxkIGltcGxlbWVudCBhIFBLQ1MjMTEgaW50ZXJmYWNlLgorSW4gb3JkZXIgdG8gbWFrZSBz dXJlIGFuIGFydGlmYWN0IHdhcyBjcmVhdGVkIGJ5IGEga25vd24gYXV0aG9yaXR5IGFuZCB3YXMg bm90CithbHRlcmVkIGxhdGVyLCBkaWdpdGFsIHNpZ25hdHVyZXMgcGxheSBhIGtleSByb2xlIHdo ZW4gYnVpbGRpbmcgZmlybXdhcmUKK2ltYWdlcy4KK1RoaXMgaXMgYWxzbyBlc3NlbnRpYWwgd2hl biBhIHZlcmlmaWVkIGJvb3QgY2hhaW4gaXMgZXN0YWJsaXNoZWQsIGUuZy4gdmlhCisqSGlnaCBB c3N1cmFuY2UgQm9vdCogKEhBQiksIHNpZ25lZCBGSVQgaW1hZ2VzLCBhbmQgYSB2ZXJpZmllZCBy b290IGZpbGUKK3N5c3RlbS4KKworUFRYZGlzdCB1c2VzIGBQS0NTIzExIDxwa2NzMTEtZG9jXz5g XyBpbnRlcm5hbGx5IHRvIHByb3ZpZGUgYWNjZXNzIHRvIGtleXMgYW5kCitjZXJ0aWZpY2F0ZXMs IHRoZXJlZm9yZSBjb2RlIHNpZ25pbmcgY29uc3VtZXJzIHNob3VsZCBpbXBsZW1lbnQgYSBQS0NT IzExCitpbnRlcmZhY2UgdG8gbWFrZSB1c2Ugb2YgUFRYZGlzdCdzIGNvZGUgc2lnbmluZyBpbmZy YXN0cnVjdHVyZS4KIAogQXMgUEtDUyMxMSBVUklzIHVzdWFsbHkgZGlmZmVyIGJldHdlZW4gZGlm ZmVyZW50IHVzZWNhc2VzIChyZWxlYXNlIHZzLgotZGV2ZWxvcG1lbnQpIHRoZSBVUklzIG5vcm1h bGx5IGFyZSBub3QgaGFyZGNvZGVkIGluIHRoZSBwYWNrYWdlIGNvbmZpZ3VyYXRpb24uCi1JbnN0 ZWFkLCBwdHhkaXN0IGhhcyB0aGUgaWRlYSBvZiAicm9sZXMiIHdoaWNoIGFyZSBzdHJpbmcgaWRl bnRpZmllcnMgdXNlZCB0bworZGV2ZWxvcG1lbnQpIHRoZSBVUklzIGFyZSB1c3VhbGx5IG5vdCBo YXJkY29kZWQgaW4gdGhlIHBhY2thZ2UgY29uZmlndXJhdGlvbi4KK0luc3RlYWQsIFBUWGRpc3Qg aGFzIHRoZSBpZGVhIG9mICoqcm9sZXMqKiB3aGljaCBhcmUgc3RyaW5nIGlkZW50aWZpZXJzIHVz ZWQgdG8KIGFjY2VzcyBhIHNpbmdsZSBwcml2YXRlL3B1YmxpYyBrZXkgcGFpciBhbmQgYSBjZXJ0 aWZpY2F0ZS4KIAotcHR4ZGlzdCBzdXBwb3J0cyBIYXJkd2FyZSBTZWN1cml0eSBNb2R1bGVzIChI U00pLgotSW4gY2FzZSBhIEhTTSBpcyBub3QgcHJlc2VudCBvciBzaGFsbCBub3QgYmUgdXNlZCBT b2Z0SFNNIGlzIHVzZWQgaW50ZXJuYWxseSB0bwotdHJhbnNwYXJlbnRseSBwcm92aWRlIHRoZSBz YW1lIEFQSSBpbnRlcm5hbGx5LgorRmluYWxseSwgb25lIG9yIHNldmVyYWwgKipjb2RlIHNpZ25p bmcgcHJvdmlkZXJzKiogc3VwcGx5IHRoZSBtYXBwaW5nIGZyb20KK3JvbGVzIHRvIHRoZSByZXNw ZWN0aXZlIGtleSBtYXRlcmlhbCBvciBldmVuIHByb3ZpZGUgaXQgdGhlbXNlbHZlcyBmb3IKK2Rl dmVsb3BtZW50LgorCitQVFhkaXN0IHN1cHBvcnRzICpIYXJkd2FyZSBTZWN1cml0eSBNb2R1bGVz KiAoSFNNKS4KK0luIGNhc2UgYW4gSFNNIGlzIG5vdCBwcmVzZW50IG9yIHNoYWxsIG5vdCBiZSB1 c2VkLCBQVFhkaXN0IGNhbiBlbXVsYXRlIGl0Cit1c2luZyBgU29mdEhTTSA8c29mdGhzbV8+YF8s IHdoaWxlIHN0aWxsIHRyYW5zcGFyZW50bHkgcHJvdmlkaW5nIHRoZSBzYW1lIEFQSQordG8gY29k ZSBzaWduaW5nIGNvbnN1bWVycy4KKworLi4gX3BrY3MxMS1kb2M6IGh0dHBzOi8vd3d3LmNyeXB0 c29mdC5jb20vcGtjczExZG9jLworLi4gX3NvZnRoc206IGh0dHBzOi8vd3d3Lm9wZW5kbnNzZWMu b3JnL3NvZnRoc20vCiAKLUZvciBlYWNoIHJvbGUgYSBQS0NTIzExIFVSSSBtdXN0IGJlIGtub3du IGJ5IHB0eGRpc3QuCi1JbiBjYXNlIG9mIGEgSFNNIHRoZSBrZXlzIGFuZCBjZXJ0aWZpY2F0ZXMg YXJlIHN0b3JlZCBpbiB0aGUgSFNNLCBidXQgcHR4ZGlzdAorLi4gX2NvZGVfc2lnbmluZ19wcm92 aWRlcnM6CisKK0NvZGUgU2lnbmluZyBQcm92aWRlcnMKK35+fn5+fn5+fn5+fn5+fn5+fn5+fn4K KworRm9yIGVhY2ggcm9sZSBhIFBLQ1MjMTEgVVJJIG11c3QgYmUga25vd24gYnkgUFRYZGlzdC4K K0luIGNhc2Ugb2YgYW4gSFNNIHRoZSBrZXlzIGFuZCBjZXJ0aWZpY2F0ZXMgYXJlIHN0b3JlZCBp biB0aGUgSFNNLCBidXQgUFRYZGlzdAogbmVlZHMgdG8ga25vdyB0aGUgUEtDUyMxMSBVUkkgdG8g YWNjZXNzIHRoZSBrZXlzLgotVGhpcyBpcyBkb25lIGluIHB0eGRpc3QgcnVsZSBmaWxlcyBjYWxs aW5nIGNzX3NldF91cmkgPHJvbGU+IDx1cmk+LgotRm9yIFNvZnRIU00gdGhlIFVSSSBpcyBnZW5l cmF0ZWQgaW50ZXJuYWxseSBieSBwdHhkaXN0LCBidXQgaW5zdGVhZCB0aGUKLWtleXMvY2VydGlm aWNhdGVzIGZvciBlYWNoIHJvbGUgaGF2ZSBoYXZlIHRvIGJlIGltcG9ydGVkLgotVGhpcyBpcyBk b25lIHdpdGggdGhlIGNzX2ltcG9ydF8qIGZ1bmN0aW9ucyBiZWxvdy4KLQotRHVyaW5nIGVhY2gg aW52b2NhdGlvbiBvZiBwdHhkaXN0IGV4YWN0bHkgb25lIGtleSBwcm92aWRlciBpcyBhY3RpdmUu Ci1UaGUgY29kZSBzaWduaW5nIHByb3ZpZGVyIGNhbiBiZSBjaG9zZW4gd2l0aCB0aGUgUFRYQ09O Rl9DT0RFX1NJR05JTkdfUFJPVklERVIKLXZhcmlhYmxlLgotQSBjb2RlIHNpZ25pbmcgcHJvdmlk ZXIgaXMgYSBwYWNrYWdlIHJlc3Bvc2libGUgZm9yIHByb3ZpZGluZyB0aGUgcm9sZSA8LT4KLVBL Q1MjMTEgVVJJIHJlbGF0aW9uc2hpcHMgaW4gY2FzZSBhIEhTTSBpcyB1c2VkIG9yIGZvciBwcm92 aWRpbmcgdGhlIGtleQorRm9yIFNvZnRIU00gdGhlIFVSSSBpcyBnZW5lcmF0ZWQgaW50ZXJuYWxs eSBieSBQVFhkaXN0LCBidXQgaW5zdGVhZCB0aGUKK2tleXMvY2VydGlmaWNhdGVzIGZvciBlYWNo IHJvbGUgaGF2ZSB0byBiZSBpbXBvcnRlZCBieSB0aGUgY29kZSBzaWduaW5nCitwcm92aWRlciBp bnRvIHRoZSBTb2Z0SFNNLgorCitBIGNvZGUgc2lnbmluZyBwcm92aWRlciBpcyBhIHBhY2thZ2Ug cmVzcG9uc2libGUgZm9yIHByb3ZpZGluZyB0aGUgcm9sZSDihpQKK1BLQ1MjMTEgVVJJIHJlbGF0 aW9uc2hpcHMgaW4gY2FzZSBhbiBIU00gaXMgdXNlZCwgb3IgZm9yIHByb3ZpZGluZyB0aGUga2V5 CiBtYXRlcmlhbCBpbiBjYXNlIFNvZnRIU00gaXMgdXNlZC4KIAotQSBwYWNrYWdlIHdoaWNoIHdh bnRzIHRvIHNpZ24gc29tZXRoaW5nIG9yIHdoaWNoIG5lZWRzIGFjY2VzcyB0byBrZXlzIGhhcyB0 bwotc2VsZWN0IENPREVfU0lHTklORy4KLVRoaXMgbWFrZXMgc3VyZSB0aGUga2V5cyBhcmUgcmVh ZHkgd2hlbiB0aGUgcGFja2FnZSBpcyBiZWluZyBidWlsdC4KK1doZW4gYGBQVFhDT05GX0NPREVf U0lHTklOR2BgIGlzIGVuYWJsZWQgZXhhY3RseSBvbmUgY29kZSBzaWduaW5nIHByb3ZpZGVyIGlz CithY3RpdmUgZHVyaW5nIGVhY2ggaW52b2NhdGlvbiBvZiBQVFhkaXN0LgorCitQVFhkaXN0IGNv bWVzIGVxdWlwcGVkIHdpdGggYSBkZXZlbG9wbWVudCBjb2RlIHNpZ25pbmcgcHJvdmlkZXIgImRl dmVsIgoraW1wbGVtZW50ZWQgdmlhIHRoZSBwYWNrYWdlIGBgaG9zdC1wdHgtY29kZS1zaWduaW5n LWRldmBgLgorSXQgaW1wb3J0cyBwdWJsaWNseSBhdmFpbGFibGUgZGV2ZWxvcG1lbnQga2V5cyBm b3IgZWFjaCByb2xlIGludG8gdGhlIFNvZnRIU00uCisKKy4uIGltcG9ydGFudDo6IFRoZSBgYGhv c3QtcHR4LWNvZGUtc2lnbmluZy1kZXZgYCBjb2RlIHNpZ25pbmcgcHJvdmlkZXIgY2FuIGJlCisg IHVzZWQgdG8gc2lnbiBhcnRpZmFjdHMgZm9yIGRldmVsb3BtZW50IHB1cnBvc2VzLCBidXQgKipt dXN0IG5vdCoqIGJlIHVzZWQgZm9yCisgIHByb2R1Y3Rpb24uCisKK0NyZWF0aW5nIEN1c3RvbSBD b2RlIFNpZ25pbmcgUHJvdmlkZXJzCiteXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5e Xl5eXgorCitXaGVuIGEgc2V0IG9mIHJlbGVhc2Uga2V5cyBvciBwcm9qZWN0LXNwZWNpZmljIGRl dmVsb3BtZW50IGtleXMgc2hvdWxkIGJlCit1c2VkIChlLmcuIHRvIGFjaGlldmUgYmFja3dhcmQg Y29tcGF0aWJpbGl0eSkgYSBuZXcgY29kZSBzaWduaW5nIHByb3ZpZGVyCittdXN0IGJlIGludHJv ZHVjZWQuCisKK1VzZSBgYHB0eGRpc3QgbmV3cGFja2FnZSBjb2RlLXNpZ25pbmctcHJvdmlkZXJg YCB0byBnZW5lcmF0ZSBzdWNoIGEgbmV3IGNvZGUKK3NpZ25pbmcgcHJvdmlkZXIuCitUaGUgZ2Vu ZXJhdGVkIGZpbGVzIG11c3Qgbm93IGJlIGFkanVzdGVkIHRvIHRoZSB1c2UgY2FzZSwgZGVwZW5k aW5nIG9uIHdoZXRoZXIKK2Egc3BlY2lmaWMgSFNNIG9yIFNvZnRIU00gc2hvdWxkIGJlIHVzZWQu CitUaGUgZ2VuZXJhdGVkIHNoZWxsIHNjcmlwdCBpbiBgYGxvY2FsX3NyYy88bmFtZT4tY29kZS1z aWduaW5nL2BgIGNvbnRhaW5zCitleGFtcGxlcyBmb3IgYm90aCB1c2UgY2FzZXMuCitTZWUgOnJl ZjpgY29kZV9zaWduaW5nX2hlbHBlcl9mdW5jdGlvbnNgIGZvciBhbiBleHBsYW5hdGlvbiBvZiB0 aGUgYXZhaWxhYmxlCitjb2RlIHNpZ25pbmcgaGVscGVycy4KK0l0IGlzIHRoZSBjb2RlIHNpZ25p bmcgcHJvdmlkZXIncyByZXNwb25zaWJpbGl0eSB0byBzZWxlY3QgdGhlIGhvc3QKK3Rvb2xzIHJl cXVpcmVkIGJ5IHRoZSBjb2RlIHNpZ25pbmcgaGVscGVyIGZ1bmN0aW9ucyBpdCB1c2VzLgorSW4g Y2FzZSBvZiBTb2Z0SFNNIHVzZSBjYXNlcyB0aGUga2V5cyBzaG91bGQgYWxzbyBiZSBwbGFjZWQg aW5zaWRlCitgYGxvY2FsX3NyYy88bmFtZT4tY29kZS1zaWduaW5nL2BgCisKK0luIGNhc2UgYW4g SFNNIGlzIHVzZWQgaXQgaXMgcmVxdWlyZWQgdG8gZXh0ZW5kIHRoZSBgYENPREVfU0lHTklOR19F TlZgYCB3aXRoCithZGRpdGlvbmFsIGVudmlyb25tZW50IHZhcmlhYmxlcyB2aWEgYSBwcmUgcnVs ZSBpbgorYGAkKFBUWERJU1RfUExBVEZPUk1DT05GSUdESVIpL3J1bGVzL3ByZS9gYC4KK0ZvciBl eGFtcGxlLCBmb3IgTml0cm9rZXkgSFNNcyB3aGljaCB1c2UgKk9wZW5TQyogdGhlIHByZSBydWxl IGNvdWxkIGxvb2sgbGlrZQordGhpczoKKworLi4gY29kZS1ibG9jazo6IG1ha2UKKworICAgIGlm ZGVmIFBUWENPTkZfQ09ERV9TSUdOSU5HX1BST1ZJREVSXzxOQU1FPgorICAgIENPREVfU0lHTklO R19FTlYgKz0gXAorICAgIAlQS0NTMTFfTU9EVUxFX1BBVEg9IiR7UFRYRElTVF9TWVNST09UX0hP U1R9L2xpYi9wa2NzMTEvb3BlbnNjLXBrY3MxMS5zbyIKKyAgICBlbmRpZgorCitOb3RlIHRoYXQg dGhlIG1vZHVsZSBpcyBidWlsdCBpbiB0aGUgQlNQIGluIHRoaXMgY2FzZSAodmlhCitgYHNlbGVj dCBIT1NUX09QRU5TQ19QQ1NDYGAgaW4gdGhlIGNvZGUgc2lnbmluZyBwcm92aWRlcidzIG1lbnUg ZmlsZSkuCitUaGlzIGlzIG5vdCBzdHJpY3RseSByZXF1aXJlZCwgaXQgaXMgYWxzbyBwb3NzaWJs ZSB0byB1c2UgYW4gb3RoZXJ3aXNlCitkaXN0cmlidXRlZCBtb2R1bGUsIGUuZy4gYnkgdGhlIEhT TSBtYW51ZmFjdHVyZXIuCisKK1N3aXRjaGluZyB0aGUgY29kZSBzaWduaW5nIHByb3ZpZGVyIGlz IG5vdyBwb3NzaWJsZSB3aXRoCitgYHB0eGRpc3QgcGxhdGZvcm1jb25maWdgYCwgdGhlbiBuYXZp Z2F0ZSB0byAqQ29kZSBzaWduaW5nKiDihpIgKkNvZGUgc2lnbmluZworcHJvdmlkZXIqLgorCitD b2RlIFNpZ25pbmcgQ29uc3VtZXJzCit+fn5+fn5+fn5+fn5+fn5+fn5+fn5+CisKK0EgcGFja2Fn ZSBoYXMgdG8gc2VsZWN0IGBgQ09ERV9TSUdOSU5HYGAgaWYgaXQgd2FudHMgdG8gc2lnbiBzb21l dGhpbmcsIG9yIGlmCitpdCBuZWVkcyBhY2Nlc3MgdG8ga2V5cyBhbmQvb3IgY2VydGlmaWNhdGVz LgorVGhlIGNvbmZpZyBzeW1ib2wgaXMgYXZhaWxhYmxlIGluIHB0eGNvbmZpZyBhcyB3ZWxsIGFz IGluIHBsYXRmb3JtY29uZmlnLgorU2VsZWN0aW5nIHRoaXMgc3ltYm9sIG1ha2VzIHN1cmUgdGhl IGtleXMgYW5kIGNlcnRpZmljYXRlcyBhcmUgcmVhZHkgd2hlbiB0aGUKK3BhY2thZ2UgaXMgYmVp bmcgYnVpbHQuCisKK0J5IGFkZGluZyBgYENPREVfU0lHTklOR19FTlZgYCB0byB0aGUgcGFja2Fn ZSdzIG1ha2UvY29uZi9pbWFnZSBlbnZpcm9ubWVudCBhCit0b29sIGltcGxlbWVudGluZyBhIFBL Q1MjMTEgaW50ZXJmYWNlIGNhbiBhY2Nlc3MgdGhlIEhTTSBvciBTb2Z0SFNNLgorVGhlIFBLQ1Mj MTEgVVJJIGNhbiBiZSByZXRyaWV2ZWQgdmlhIDpyZWY6YGNzX2dldF91cmlgIGFuZCBwYXNzZWQg b24sIHVzdWFsbHkKK2Fsc28gdmlhIGFuIGVudmlyb25tZW50IHZhcmlhYmxlLgorCis6cmVmOmBj c19nZXRfY2FgIGNhbiBiZSB1c2VkIHRvIGluc3RhbGwgYSBrZXlyaW5nIHRvIHRoZSByb290IGZp bGUgc3lzdGVtLCBlLmcuOgorCisuLiBjb2RlLWJsb2NrOjogbm9uZQorCisgICAgJChjYWxsIGlu c3RhbGxfY29weSwgcmF1YywgMCwgMCwgMDY0NCwgXAorICAgICAgJChzaGVsbCBjc19nZXRfY2Eg dXBkYXRlKSwgXAorICAgICAgL2V0Yy9yYXVjL2NhLmNlcnQucGVtKQorCisuLiBub3RlOjogV2hl biBjb2RlIHNpZ25pbmcgaGVscGVyIGZ1bmN0aW9ucyBhcmUgdXNlZCBpbiBtYWtlIHZhcmlhYmxl cyAoZS5nLgorICBmb3IgZW52aXJvbm1lbnQgZGVmaW5pdGlvbnMpIHJlY3Vyc2l2ZWx5IGV4cGFu ZGVkIHZhcmlhYmxlcyBtdXN0IGJlIHVzZWQKKyAgKGBgPWBgLCBub3QgYGA6PWBgKS4KKyAgT3Ro ZXJ3aXNlIHRoZSB2YXJpYWJsZSBpcyBleHBhbmRlZCBiZWZvcmUgYSBjb2RlIHNpZ25pbmcgcHJv dmlkZXIgY2FuIHBlcmZvcm0KKyAgaXRzIHNldHVwLgotLSAKMi4yNy4wCgoKX19fX19fX19fX19f X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18KcHR4ZGlzdCBtYWlsaW5nIGxpc3QK cHR4ZGlzdEBwZW5ndXRyb25peC5kZQpUbyB1bnN1YnNjcmliZSwgc2VuZCBhIG1haWwgd2l0aCBz dWJqZWN0ICJ1bnN1YnNjcmliZSIgdG8gcHR4ZGlzdC1yZXF1ZXN0QHBlbmd1dHJvbml4LmRlCg==