Hi, On Fri, 2024-05-10 at 15:20 +0100, Luca Boccassi wrote: > On Thu, 04 Apr 2024 20:41:59 +0100 Luca Boccassi <bl...@debian.org> > > On IRC Steve mentioned that he's ok with proceeding with this. > > jcristau from DSA said that it's the FTP team that should confirm the > > request > > for the new intermediate signer cert for systemd-boot to DSA. > > > > FTP team, are you ok with proceeding with this? If so, would it be > > possible to have an ACK, please? Is there any more information required > > beforehand?
As long as the security boot people are fine with this, I think this should be fine. (And AFAIU this seems to be the case.) Maybe we should use a non-trusted cert for the initial setup and only switch to a proper cert once everything is confirmed to be working as expected? Ansgar