Bug#1071693: sbsign should check certificate's expiration

2024-05-30 Thread Steve McIntyre
On Thu, May 23, 2024 at 10:27:09PM +0200, Christoph Biedl wrote: >Package: sbsigntool >Version: 0.9.4-3.1+b1 >Severity: normal >X-Debbugs-Cc: debian.a...@manchmal.in-ulm.de > >Greetings, > >it was a bit surprising to learn sbsign will happily sign EFI images >even if the certificate, provided via t

Bug#1071693: sbsign should check certificate's expiration

2024-05-23 Thread Christoph Biedl
Package: sbsigntool Version: 0.9.4-3.1+b1 Severity: normal X-Debbugs-Cc: debian.a...@manchmal.in-ulm.de Greetings, it was a bit surprising to learn sbsign will happily sign EFI images even if the certificate, provided via the --cert parameter, has expired. While this possibly will not affect func