Implement kernel signing

This commit is contained in:
2025-09-09 21:05:02 -04:00
parent 851b1c048e
commit 756653ae99
16 changed files with 200 additions and 39 deletions

View File

@@ -46,3 +46,10 @@ toggle-nvk:
echo "Rebasing to ${NEW_IMAGE}"
rpm-ostree rebase ${CURRENT_URI}${NEW_IMAGE}
just _configure-nvidia ${CONFIG_ACTION}
generate-secureboot-key:
openssl req -config ./openssl.cnf \
-new -x509 -newkey rsa:2048 \
-nodes -days 36500 -outform DER \
-keyout ./.secure-files/MOK.priv \
-out ./files/base/etc/pki/akmods/certs/akmods-wunker-bunker.der