diff --git a/debian/certs/debian-uefi-certs.pem b/debian/certs/debian-uefi-certs.pem index b16b0c93a..9834ea471 100644 --- a/debian/certs/debian-uefi-certs.pem +++ b/debian/certs/debian-uefi-certs.pem @@ -21,20 +21,21 @@ UdeTk566CA1Zl/LiKaBETeru+D4CYMoVz06aJZGEP7dax+68a4Cj2f2ybXoeYxTr 305gdrAGewiwbuNknyFWrTkP -----END CERTIFICATE----- -----BEGIN CERTIFICATE----- -MIIC/DCCAeSgAwIBAgIFAKdGje8wDQYJKoZIhvcNAQELBQAwIDEeMBwGA1UEAxMV -RGViaWFuIFNlY3VyZSBCb290IENBMB4XDTE2MDgxNjE4MjI1MFoXDTI2MDgxNjE4 -MjI1MFowJDEiMCAGA1UEAxMZRGViaWFuIFNlY3VyZSBCb290IFNpZ25lcjCCASIw -DQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBANPRg5AP2mWiLwdaYJXr98eGfCCG -2mWjphLrWzvOyPs/oXJLnt9QxQMzpAwrX9ZBBA22z5VI7YqyrdblATdOYM2ySjgE -s0SAlK+fblTbqB88t0sw3iGBbwmjZrpqK5bWmmF3DNTtPNBxu62M8CJcPiXMbSIu -YZeVr5suTVi2fngCww65+rJbJ959or4MFKxz7JewFV7t7eWldT944HHOL86D7VMx -MJhO5vkBooiIpiMIfA23VDoWle1eeV6QTv7Nqt6C/PaWcU5JSbnT6bCrf9cqR7dT -MCd83GaYCW/RfvV/PT7UomqIWQIvLz3IxijeQv7ZUj0kwvxAmBH2dr+Mu2UCAwEA -AaM5MDcwEQYJYIZIAYb4QgEBBAQDAgQQMBUGA1UdJQQOMAwGCisGAQQBgjcKAwEw -CwYDVR0PBAQDAgeAMA0GCSqGSIb3DQEBCwUAA4IBAQBXG6RgTCnp8n1rXJPbzGyf -GD9pSJp13mTzg0oJqSYh7ulWXeE+2XXLzH+/TeToiT1+EUKHQMPV4HF53ABs4XFi -x5jCyycLL5/M7PqLsvMLnvPyw8mf2yWTkKTNuwHljvTXVai0dUEx/U5dAxigwqzF -3kbn3BzPEtWd6Eedk4wyzUTVdMcwmlelVtB+zwURtPTzKfnbm1PSvS+tanUmRWS6 -uiiWh4638HlX+noOPEo4krzylfLnKND32JgaXjmetWWAvfPaEj9Qdmcpn9ELCh6H -l1xy2/MBdErdB7p26Wr83SLbRgLXrwrF7RW8Dyup242/f2+torfFTUpHs8FWkLYX +MIIDATCCAemgAwIBAgIFALVes7kwDQYJKoZIhvcNAQELBQAwIDEeMBwGA1UEAxMV +RGViaWFuIFNlY3VyZSBCb290IENBMB4XDTIwMDcyMTE1NTI1NFoXDTMwMDcyMTE1 +NTI1NFowKTEnMCUGA1UEAxMeRGViaWFuIFNlY3VyZSBCb290IFNpZ25lciAyMDIw +MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAzZTMfLXsQ7y5hYyNaA7R +0PFJ1xqStP93srUShRG1hT9FKMXk8Ylf8lgzuQzKfqiYIw3JTok6lgsWVKGIYrQO +oXGB3LcUB641onF6xzpdDDhqmupbhXoSYNTEnwg/3cHuoFwIbvpGEUKcbTANZ85e +kJUIgjILeyQ8Ks1seyyHyo0BH8jsM53N8NpZLf9L4nYSi5uFcvY11Zkc7mOrltE+ +b0r8NX1scHnxRUy7KUqrmhWN+XBYRD6p97CJ2j+idfJqcq5RUXa8g3CorMv9N+Rt +EKewpevMKc/O1SWdXH6h7LbJ7LlUerCoU4LFuiJx5RcSh7PhHbsnGc/3hT5JyKSr +PQIDAQABozkwNzARBglghkgBhvhCAQEEBAMCBBAwFQYDVR0lBA4wDAYKKwYBBAGC +NwoDATALBgNVHQ8EBAMCB4AwDQYJKoZIhvcNAQELBQADggEBAGsgHaFyCmfhQyGk ++bCfcmTx2JpPOKD49DBOHOPeZJ5pmym9ouCyY5q4v2fIcB0twFKAZZtD/LLmxsbD +xUZXIIWU06cn3+zURPeRSGQltJupnE6cm3IB+iFTEmZUBUHREEUlEwRE/n9le6GL +s0Z3P0bK4dD/mTy9mLKs1sFSplXvFSJd9gpM0tboMvCJa6G1cC/52MsA4SeKAIDY +/oFT+d/Lq36rBjtvCS1IGP2qq2W/Q2q7xDImnISXonlHWcHxaMgNK8j0QsZEsWvW +3mC4oonxYCH5pBTacuUpcLPtv5HYOdcbR3ENYZ0Ut41HSVhmzf+oJg+fz+HSlkvG +/GOXjcs= -----END CERTIFICATE----- diff --git a/debian/changelog b/debian/changelog index e6eba69af..12f8348d2 100644 --- a/debian/changelog +++ b/debian/changelog @@ -42,6 +42,7 @@ linux (4.19.132-1) UNRELEASED; urgency=medium (Closes: #964153, #964480) * efi: Restrict efivar_ssdt_load when the kernel is locked down (CVE-2019-20908) + * certs: Rotate to use the Debian Secure Boot Signer 2020 certificate -- Salvatore Bonaccorso Tue, 14 Jul 2020 21:48:28 +0200