From mboxrd@z Thu Jan 1 00:00:00 1970 Return-path: From: Bastian Krause Date: Fri, 12 Jun 2020 12:52:30 +0200 Message-Id: <20200612105231.4318-5-bst@pengutronix.de> In-Reply-To: <20200612105231.4318-1-bst@pengutronix.de> References: <20200612105231.4318-1-bst@pengutronix.de> MIME-Version: 1.0 Subject: [ptxdist] [PATCH v2 4/5] doc: dev_code_signing: rework and extend code signing section List-Id: PTXdist Development Mailing List List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Reply-To: ptxdist@pengutronix.de Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: base64 Errors-To: ptxdist-bounces@pengutronix.de Sender: "ptxdist" To: ptxdist@pengutronix.de Cc: Bastian Krause , Roland Hieber U2lnbmVkLW9mZi1ieTogQmFzdGlhbiBLcmF1c2UgPGJzdEBwZW5ndXRyb25peC5kZT4KUmV2aWV3 ZWQtYnk6IFJvbGFuZCBIaWViZXIgPHJoaUBwZW5ndXRyb25peC5kZT4KVGVzdGVkLWJ5OiBMYWRp c2xhdiBNaWNobCA8bGFkaXNAbGludXgtbWlwcy5vcmc+Ci0tLQpDaGFuZ2VzIHNpbmNlIChpbXBs aWNpdCkgdjE6Ci0gYWRkIGh5cGVybGluayB0YXJnZXQgdG8gY29kZSBzaWduaW5nIGNvbnN1bWVy cyB0byBhbGxvdyByZWZlcmVuY2VzIGluCiAgYSBsYXRlciBjb21taXQKLS0tCiBkb2MvZGV2X2Nv ZGVfc2lnbmluZy5yc3QgfCAxNDEgKysrKysrKysrKysrKysrKysrKysrKysrKysrKysrKystLS0t LS0tCiAxIGZpbGUgY2hhbmdlZCwgMTE4IGluc2VydGlvbnMoKyksIDIzIGRlbGV0aW9ucygtKQoK ZGlmZiAtLWdpdCBhL2RvYy9kZXZfY29kZV9zaWduaW5nLnJzdCBiL2RvYy9kZXZfY29kZV9zaWdu aW5nLnJzdAppbmRleCBkZTAwODdmOGIuLmVhZTU3MjM3MyAxMDA2NDQKLS0tIGEvZG9jL2Rldl9j b2RlX3NpZ25pbmcucnN0CisrKyBiL2RvYy9kZXZfY29kZV9zaWduaW5nLnJzdApAQCAtMywzNCAr MywxMjkgQEAKIENvZGUgU2lnbmluZwogLS0tLS0tLS0tLS0tCiAKLVRoaXMgaXMgYW4gb3ZlcnZp ZXcgb3ZlciB0aGUgcHR4ZGlzdCBzaWduaW5nIGluZnJhc3RydWN0dXJlLgotcHR4ZGlzdCB1c2Vz IFBLQ1MjMTEgaW50ZXJuYWxseSBmb3IgcHJvdmlkaW5nIGFjY2VzcyB0byBrZXlzIGFuZCBjZXJ0 aWZpY2F0ZXMuCi1QYWNrYWdlcyB0aGF0IHdpc2ggdG8gc2lnbiBzb21ldGhpbmcgc2hvdWxkIGlt cGxlbWVudCBhIFBLQ1MjMTEgaW50ZXJmYWNlLgorSW4gb3JkZXIgdG8gbWFrZSBzdXJlIGFuIGFy dGlmYWN0IHdhcyBjcmVhdGVkIGJ5IGEga25vd24gYXV0aG9yaXR5IGFuZCB3YXMgbm90CithbHRl cmVkIGxhdGVyLCBkaWdpdGFsIHNpZ25hdHVyZXMgcGxheSBhIGtleSByb2xlIHdoZW4gYnVpbGRp bmcgZmlybXdhcmUKK2ltYWdlcy4KK1RoaXMgaXMgYWxzbyBlc3NlbnRpYWwgd2hlbiBhIHZlcmlm aWVkIGJvb3QgY2hhaW4gaXMgZXN0YWJsaXNoZWQsIGUuZy4gdmlhCisqSGlnaCBBc3N1cmFuY2Ug Qm9vdCogKEhBQiksIHNpZ25lZCBGSVQgaW1hZ2VzLCBhbmQgYSB2ZXJpZmllZCByb290IGZpbGUK K3N5c3RlbS4KKworUFRYZGlzdCB1c2VzIGBQS0NTIzExIDxwa2NzMTEtZG9jXz5gXyBpbnRlcm5h bGx5IHRvIHByb3ZpZGUgYWNjZXNzIHRvIGtleXMgYW5kCitjZXJ0aWZpY2F0ZXMsIHRoZXJlZm9y ZSBjb2RlIHNpZ25pbmcgY29uc3VtZXJzIHNob3VsZCBpbXBsZW1lbnQgYSBQS0NTIzExCitpbnRl cmZhY2UgdG8gbWFrZSB1c2Ugb2YgUFRYZGlzdCdzIGNvZGUgc2lnbmluZyBpbmZyYXN0cnVjdHVy ZS4KIAogQXMgUEtDUyMxMSBVUklzIHVzdWFsbHkgZGlmZmVyIGJldHdlZW4gZGlmZmVyZW50IHVz ZWNhc2VzIChyZWxlYXNlIHZzLgotZGV2ZWxvcG1lbnQpIHRoZSBVUklzIG5vcm1hbGx5IGFyZSBu b3QgaGFyZGNvZGVkIGluIHRoZSBwYWNrYWdlIGNvbmZpZ3VyYXRpb24uCi1JbnN0ZWFkLCBwdHhk aXN0IGhhcyB0aGUgaWRlYSBvZiAicm9sZXMiIHdoaWNoIGFyZSBzdHJpbmcgaWRlbnRpZmllcnMg dXNlZCB0bworZGV2ZWxvcG1lbnQpIHRoZSBVUklzIGFyZSB1c3VhbGx5IG5vdCBoYXJkY29kZWQg aW4gdGhlIHBhY2thZ2UgY29uZmlndXJhdGlvbi4KK0luc3RlYWQsIFBUWGRpc3QgaGFzIHRoZSBp ZGVhIG9mICoqcm9sZXMqKiB3aGljaCBhcmUgc3RyaW5nIGlkZW50aWZpZXJzIHVzZWQgdG8KIGFj Y2VzcyBhIHNpbmdsZSBwcml2YXRlL3B1YmxpYyBrZXkgcGFpciBhbmQgYSBjZXJ0aWZpY2F0ZS4K IAotcHR4ZGlzdCBzdXBwb3J0cyBIYXJkd2FyZSBTZWN1cml0eSBNb2R1bGVzIChIU00pLgotSW4g Y2FzZSBhIEhTTSBpcyBub3QgcHJlc2VudCBvciBzaGFsbCBub3QgYmUgdXNlZCBTb2Z0SFNNIGlz IHVzZWQgaW50ZXJuYWxseSB0bwotdHJhbnNwYXJlbnRseSBwcm92aWRlIHRoZSBzYW1lIEFQSSBp bnRlcm5hbGx5LgorRmluYWxseSwgb25lIG9yIHNldmVyYWwgKipjb2RlIHNpZ25pbmcgcHJvdmlk ZXJzKiogc3VwcGx5IHRoZSBtYXBwaW5nIGZyb20KK3JvbGVzIHRvIHRoZSByZXNwZWN0aXZlIGtl eSBtYXRlcmlhbCBvciBldmVuIHByb3ZpZGUgaXQgdGhlbXNlbHZlcyBmb3IKK2RldmVsb3BtZW50 LgorCitQVFhkaXN0IHN1cHBvcnRzICpIYXJkd2FyZSBTZWN1cml0eSBNb2R1bGVzKiAoSFNNKS4K K0luIGNhc2UgYW4gSFNNIGlzIG5vdCBwcmVzZW50IG9yIHNoYWxsIG5vdCBiZSB1c2VkLCBQVFhk aXN0IGNhbiBlbXVsYXRlIGl0Cit1c2luZyBgU29mdEhTTSA8c29mdGhzbV8+YF8sIHdoaWxlIHN0 aWxsIHRyYW5zcGFyZW50bHkgcHJvdmlkaW5nIHRoZSBzYW1lIEFQSQordG8gY29kZSBzaWduaW5n IGNvbnN1bWVycy4KKworLi4gX3BrY3MxMS1kb2M6IGh0dHBzOi8vd3d3LmNyeXB0c29mdC5jb20v cGtjczExZG9jLworLi4gX3NvZnRoc206IGh0dHBzOi8vd3d3Lm9wZW5kbnNzZWMub3JnL3NvZnRo c20vCiAKLUZvciBlYWNoIHJvbGUgYSBQS0NTIzExIFVSSSBtdXN0IGJlIGtub3duIGJ5IHB0eGRp c3QuCi1JbiBjYXNlIG9mIGEgSFNNIHRoZSBrZXlzIGFuZCBjZXJ0aWZpY2F0ZXMgYXJlIHN0b3Jl ZCBpbiB0aGUgSFNNLCBidXQgcHR4ZGlzdAorLi4gX2NvZGVfc2lnbmluZ19wcm92aWRlcnM6CisK K0NvZGUgU2lnbmluZyBQcm92aWRlcnMKK35+fn5+fn5+fn5+fn5+fn5+fn5+fn4KKworRm9yIGVh Y2ggcm9sZSBhIFBLQ1MjMTEgVVJJIG11c3QgYmUga25vd24gYnkgUFRYZGlzdC4KK0luIGNhc2Ug b2YgYW4gSFNNIHRoZSBrZXlzIGFuZCBjZXJ0aWZpY2F0ZXMgYXJlIHN0b3JlZCBpbiB0aGUgSFNN LCBidXQgUFRYZGlzdAogbmVlZHMgdG8ga25vdyB0aGUgUEtDUyMxMSBVUkkgdG8gYWNjZXNzIHRo ZSBrZXlzLgotVGhpcyBpcyBkb25lIGluIHB0eGRpc3QgcnVsZSBmaWxlcyBjYWxsaW5nIGNzX3Nl dF91cmkgPHJvbGU+IDx1cmk+LgotRm9yIFNvZnRIU00gdGhlIFVSSSBpcyBnZW5lcmF0ZWQgaW50 ZXJuYWxseSBieSBwdHhkaXN0LCBidXQgaW5zdGVhZCB0aGUKLWtleXMvY2VydGlmaWNhdGVzIGZv ciBlYWNoIHJvbGUgaGF2ZSBoYXZlIHRvIGJlIGltcG9ydGVkLgotVGhpcyBpcyBkb25lIHdpdGgg dGhlIGNzX2ltcG9ydF8qIGZ1bmN0aW9ucyBiZWxvdy4KLQotRHVyaW5nIGVhY2ggaW52b2NhdGlv biBvZiBwdHhkaXN0IGV4YWN0bHkgb25lIGtleSBwcm92aWRlciBpcyBhY3RpdmUuCi1UaGUgY29k ZSBzaWduaW5nIHByb3ZpZGVyIGNhbiBiZSBjaG9zZW4gd2l0aCB0aGUgUFRYQ09ORl9DT0RFX1NJ R05JTkdfUFJPVklERVIKLXZhcmlhYmxlLgotQSBjb2RlIHNpZ25pbmcgcHJvdmlkZXIgaXMgYSBw YWNrYWdlIHJlc3Bvc2libGUgZm9yIHByb3ZpZGluZyB0aGUgcm9sZSA8LT4KLVBLQ1MjMTEgVVJJ IHJlbGF0aW9uc2hpcHMgaW4gY2FzZSBhIEhTTSBpcyB1c2VkIG9yIGZvciBwcm92aWRpbmcgdGhl IGtleQorRm9yIFNvZnRIU00gdGhlIFVSSSBpcyBnZW5lcmF0ZWQgaW50ZXJuYWxseSBieSBQVFhk aXN0LCBidXQgaW5zdGVhZCB0aGUKK2tleXMvY2VydGlmaWNhdGVzIGZvciBlYWNoIHJvbGUgaGF2 ZSB0byBiZSBpbXBvcnRlZCBieSB0aGUgY29kZSBzaWduaW5nCitwcm92aWRlciBpbnRvIHRoZSBT b2Z0SFNNLgorCitBIGNvZGUgc2lnbmluZyBwcm92aWRlciBpcyBhIHBhY2thZ2UgcmVzcG9uc2li bGUgZm9yIHByb3ZpZGluZyB0aGUgcm9sZSDihpQKK1BLQ1MjMTEgVVJJIHJlbGF0aW9uc2hpcHMg aW4gY2FzZSBhbiBIU00gaXMgdXNlZCwgb3IgZm9yIHByb3ZpZGluZyB0aGUga2V5CiBtYXRlcmlh bCBpbiBjYXNlIFNvZnRIU00gaXMgdXNlZC4KIAotQSBwYWNrYWdlIHdoaWNoIHdhbnRzIHRvIHNp Z24gc29tZXRoaW5nIG9yIHdoaWNoIG5lZWRzIGFjY2VzcyB0byBrZXlzIGhhcyB0bwotc2VsZWN0 IENPREVfU0lHTklORy4KLVRoaXMgbWFrZXMgc3VyZSB0aGUga2V5cyBhcmUgcmVhZHkgd2hlbiB0 aGUgcGFja2FnZSBpcyBiZWluZyBidWlsdC4KK1doZW4gYGBQVFhDT05GX0NPREVfU0lHTklOR2Bg IGlzIGVuYWJsZWQgZXhhY3RseSBvbmUgY29kZSBzaWduaW5nIHByb3ZpZGVyIGlzCithY3RpdmUg ZHVyaW5nIGVhY2ggaW52b2NhdGlvbiBvZiBQVFhkaXN0LgorCitQVFhkaXN0IGNvbWVzIGVxdWlw cGVkIHdpdGggYSBkZXZlbG9wbWVudCBjb2RlIHNpZ25pbmcgcHJvdmlkZXIgImRldmVsIgoraW1w bGVtZW50ZWQgdmlhIHRoZSBwYWNrYWdlIGBgaG9zdC1wdHgtY29kZS1zaWduaW5nLWRldmBgLgor SXQgaW1wb3J0cyBwdWJsaWNseSBhdmFpbGFibGUgZGV2ZWxvcG1lbnQga2V5cyBmb3IgZWFjaCBy b2xlIGludG8gdGhlIFNvZnRIU00uCisKKy4uIGltcG9ydGFudDo6IFRoZSBgYGhvc3QtcHR4LWNv ZGUtc2lnbmluZy1kZXZgYCBjb2RlIHNpZ25pbmcgcHJvdmlkZXIgY2FuIGJlCisgIHVzZWQgdG8g c2lnbiBhcnRpZmFjdHMgZm9yIGRldmVsb3BtZW50IHB1cnBvc2VzLCBidXQgKiptdXN0IG5vdCoq IGJlIHVzZWQgZm9yCisgIHByb2R1Y3Rpb24uCisKK0NyZWF0aW5nIEN1c3RvbSBDb2RlIFNpZ25p bmcgUHJvdmlkZXJzCiteXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXl5eXgorCitX aGVuIGEgc2V0IG9mIHJlbGVhc2Uga2V5cyBvciBwcm9qZWN0LXNwZWNpZmljIGRldmVsb3BtZW50 IGtleXMgc2hvdWxkIGJlCit1c2VkIChlLmcuIHRvIGFjaGlldmUgYmFja3dhcmQgY29tcGF0aWJp bGl0eSkgYSBuZXcgY29kZSBzaWduaW5nIHByb3ZpZGVyCittdXN0IGJlIGludHJvZHVjZWQuCisK K1VzZSBgYHB0eGRpc3QgbmV3cGFja2FnZSBjb2RlLXNpZ25pbmctcHJvdmlkZXJgYCB0byBnZW5l cmF0ZSBzdWNoIGEgbmV3IGNvZGUKK3NpZ25pbmcgcHJvdmlkZXIuCitUaGUgZ2VuZXJhdGVkIGZp bGVzIG11c3Qgbm93IGJlIGFkanVzdGVkIHRvIHRoZSB1c2UgY2FzZSwgZGVwZW5kaW5nIG9uIHdo ZXRoZXIKK2Egc3BlY2lmaWMgSFNNIG9yIFNvZnRIU00gc2hvdWxkIGJlIHVzZWQuCitUaGUgZ2Vu ZXJhdGVkIHNoZWxsIHNjcmlwdCBpbiBgYGxvY2FsX3NyYy88bmFtZT4tY29kZS1zaWduaW5nL2Bg IGNvbnRhaW5zCitleGFtcGxlcyBmb3IgYm90aCB1c2UgY2FzZXMuCitTZWUgOnJlZjpgY29kZV9z aWduaW5nX2hlbHBlcl9mdW5jdGlvbnNgIGZvciBhbiBleHBsYW5hdGlvbiBvZiB0aGUgYXZhaWxh YmxlCitjb2RlIHNpZ25pbmcgaGVscGVycy4KK0l0IGlzIHRoZSBjb2RlIHNpZ25pbmcgcHJvdmlk ZXIncyByZXNwb25zaWJpbGl0eSB0byBzZWxlY3QgdGhlIGhvc3QKK3Rvb2xzIHJlcXVpcmVkIGJ5 IHRoZSBjb2RlIHNpZ25pbmcgaGVscGVyIGZ1bmN0aW9ucyBpdCB1c2VzLgorSW4gY2FzZSBvZiBT b2Z0SFNNIHVzZSBjYXNlcyB0aGUga2V5cyBzaG91bGQgYWxzbyBiZSBwbGFjZWQgaW5zaWRlCitg YGxvY2FsX3NyYy88bmFtZT4tY29kZS1zaWduaW5nL2BgCisKK0luIGNhc2UgYW4gSFNNIGlzIHVz ZWQgaXQgaXMgcmVxdWlyZWQgdG8gZXh0ZW5kIHRoZSBgYENPREVfU0lHTklOR19FTlZgYCB3aXRo CithZGRpdGlvbmFsIGVudmlyb25tZW50IHZhcmlhYmxlcyB2aWEgYSBwcmUgcnVsZSBpbgorYGAk KFBUWERJU1RfUExBVEZPUk1DT05GSUdESVIpL3J1bGVzL3ByZS9gYC4KK0ZvciBleGFtcGxlLCBm b3IgTml0cm9rZXkgSFNNcyB3aGljaCB1c2UgKk9wZW5TQyogdGhlIHByZSBydWxlIGNvdWxkIGxv b2sgbGlrZQordGhpczoKKworLi4gY29kZS1ibG9jazo6IG1ha2UKKworICAgIGlmZGVmIFBUWENP TkZfQ09ERV9TSUdOSU5HX1BST1ZJREVSXzxOQU1FPgorICAgIENPREVfU0lHTklOR19FTlYgKz0g XAorICAgIAlQS0NTMTFfTU9EVUxFX1BBVEg9IiR7UFRYRElTVF9TWVNST09UX0hPU1R9L2xpYi9w a2NzMTEvb3BlbnNjLXBrY3MxMS5zbyIKKyAgICBlbmRpZgorCitOb3RlIHRoYXQgdGhlIG1vZHVs ZSBpcyBidWlsdCBpbiB0aGUgQlNQIGluIHRoaXMgY2FzZSAodmlhCitgYHNlbGVjdCBIT1NUX09Q RU5TQ19QQ1NDYGAgaW4gdGhlIGNvZGUgc2lnbmluZyBwcm92aWRlcidzIG1lbnUgZmlsZSkuCitU aGlzIGlzIG5vdCBzdHJpY3RseSByZXF1aXJlZCwgaXQgaXMgYWxzbyBwb3NzaWJsZSB0byB1c2Ug YW4gb3RoZXJ3aXNlCitkaXN0cmlidXRlZCBtb2R1bGUsIGUuZy4gYnkgdGhlIEhTTSBtYW51ZmFj dHVyZXIuCisKK1N3aXRjaGluZyB0aGUgY29kZSBzaWduaW5nIHByb3ZpZGVyIGlzIG5vdyBwb3Nz aWJsZSB3aXRoCitgYHB0eGRpc3QgcGxhdGZvcm1jb25maWdgYCwgdGhlbiBuYXZpZ2F0ZSB0byAq Q29kZSBzaWduaW5nKiDihpIgKkNvZGUgc2lnbmluZworcHJvdmlkZXIqLgorCisuLiBfY29kZV9z aWduaW5nX2NvbnN1bWVyczoKKworQ29kZSBTaWduaW5nIENvbnN1bWVycworfn5+fn5+fn5+fn5+ fn5+fn5+fn5+fgorCitBIHBhY2thZ2UgaGFzIHRvIHNlbGVjdCBgYENPREVfU0lHTklOR2BgIGlm IGl0IHdhbnRzIHRvIHNpZ24gc29tZXRoaW5nLCBvciBpZgoraXQgbmVlZHMgYWNjZXNzIHRvIGtl eXMgYW5kL29yIGNlcnRpZmljYXRlcy4KK1RoZSBjb25maWcgc3ltYm9sIGlzIGF2YWlsYWJsZSBp biBwdHhjb25maWcgYXMgd2VsbCBhcyBpbiBwbGF0Zm9ybWNvbmZpZy4KK1NlbGVjdGluZyB0aGlz IHN5bWJvbCBtYWtlcyBzdXJlIHRoZSBrZXlzIGFuZCBjZXJ0aWZpY2F0ZXMgYXJlIHJlYWR5IHdo ZW4gdGhlCitwYWNrYWdlIGlzIGJlaW5nIGJ1aWx0LgorCitCeSBhZGRpbmcgYGBDT0RFX1NJR05J TkdfRU5WYGAgdG8gdGhlIHBhY2thZ2UncyBtYWtlL2NvbmYvaW1hZ2UgZW52aXJvbm1lbnQgYQor dG9vbCBpbXBsZW1lbnRpbmcgYSBQS0NTIzExIGludGVyZmFjZSBjYW4gYWNjZXNzIHRoZSBIU00g b3IgU29mdEhTTS4KK1RoZSBQS0NTIzExIFVSSSBjYW4gYmUgcmV0cmlldmVkIHZpYSA6cmVmOmBj c19nZXRfdXJpYCBhbmQgcGFzc2VkIG9uLCB1c3VhbGx5CithbHNvIHZpYSBhbiBlbnZpcm9ubWVu dCB2YXJpYWJsZS4KKworOnJlZjpgY3NfZ2V0X2NhYCBjYW4gYmUgdXNlZCB0byBpbnN0YWxsIGEg a2V5cmluZyB0byB0aGUgcm9vdCBmaWxlIHN5c3RlbSwgZS5nLjoKKworLi4gY29kZS1ibG9jazo6 IG5vbmUKKworICAgICQoY2FsbCBpbnN0YWxsX2NvcHksIHJhdWMsIDAsIDAsIDA2NDQsIFwKKyAg ICAgICQoc2hlbGwgY3NfZ2V0X2NhIHVwZGF0ZSksIFwKKyAgICAgIC9ldGMvcmF1Yy9jYS5jZXJ0 LnBlbSkKKworLi4gbm90ZTo6IFdoZW4gY29kZSBzaWduaW5nIGhlbHBlciBmdW5jdGlvbnMgYXJl IHVzZWQgaW4gbWFrZSB2YXJpYWJsZXMgKGUuZy4KKyAgZm9yIGVudmlyb25tZW50IGRlZmluaXRp b25zKSByZWN1cnNpdmVseSBleHBhbmRlZCB2YXJpYWJsZXMgbXVzdCBiZSB1c2VkCisgIChgYD1g YCwgbm90IGBgOj1gYCkuCisgIE90aGVyd2lzZSB0aGUgdmFyaWFibGUgaXMgZXhwYW5kZWQgYmVm b3JlIGEgY29kZSBzaWduaW5nIHByb3ZpZGVyIGNhbiBwZXJmb3JtCisgIGl0cyBzZXR1cC4KLS0g CjIuMjcuMAoKCl9fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19f CnB0eGRpc3QgbWFpbGluZyBsaXN0CnB0eGRpc3RAcGVuZ3V0cm9uaXguZGUKVG8gdW5zdWJzY3Jp YmUsIHNlbmQgYSBtYWlsIHdpdGggc3ViamVjdCAidW5zdWJzY3JpYmUiIHRvIHB0eGRpc3QtcmVx dWVzdEBwZW5ndXRyb25peC5kZQo=