提交 22753674 编写于 作者: M Michal Marek 提交者: Rusty Russell

MODSIGN: Simplify Makefile with a Kconfig helper

Signed-off-by: NMichal Marek <mmarek@suse.cz>
Acked-by: NDavid Howells <dhowells@redhat.com>
Signed-off-by: NRusty Russell <rusty@rustcorp.com.au>
上级 a3535c7e
...@@ -1697,6 +1697,15 @@ config MODULE_SIG_SHA512 ...@@ -1697,6 +1697,15 @@ config MODULE_SIG_SHA512
endchoice endchoice
config MODULE_SIG_HASH
string
depends on MODULE_SIG
default "sha1" if MODULE_SIG_SHA1
default "sha224" if MODULE_SIG_SHA224
default "sha256" if MODULE_SIG_SHA256
default "sha384" if MODULE_SIG_SHA384
default "sha512" if MODULE_SIG_SHA512
endif # MODULES endif # MODULES
config INIT_ALL_POSSIBLE config INIT_ALL_POSSIBLE
......
...@@ -153,23 +153,7 @@ kernel/modsign_certificate.o: signing_key.x509 extra_certificates ...@@ -153,23 +153,7 @@ kernel/modsign_certificate.o: signing_key.x509 extra_certificates
# fail and that the kernel may be used afterwards. # fail and that the kernel may be used afterwards.
# #
############################################################################### ###############################################################################
sign_key_with_hash := ifndef CONFIG_MODULE_SIG_HASH
ifeq ($(CONFIG_MODULE_SIG_SHA1),y)
sign_key_with_hash := -sha1
endif
ifeq ($(CONFIG_MODULE_SIG_SHA224),y)
sign_key_with_hash := -sha224
endif
ifeq ($(CONFIG_MODULE_SIG_SHA256),y)
sign_key_with_hash := -sha256
endif
ifeq ($(CONFIG_MODULE_SIG_SHA384),y)
sign_key_with_hash := -sha384
endif
ifeq ($(CONFIG_MODULE_SIG_SHA512),y)
sign_key_with_hash := -sha512
endif
ifeq ($(sign_key_with_hash),)
$(error Could not determine digest type to use from kernel config) $(error Could not determine digest type to use from kernel config)
endif endif
...@@ -182,8 +166,8 @@ signing_key.priv signing_key.x509: x509.genkey ...@@ -182,8 +166,8 @@ signing_key.priv signing_key.x509: x509.genkey
@echo "### needs to be run as root, and uses a hardware random" @echo "### needs to be run as root, and uses a hardware random"
@echo "### number generator if one is available." @echo "### number generator if one is available."
@echo "###" @echo "###"
openssl req -new -nodes -utf8 $(sign_key_with_hash) -days 36500 -batch \ openssl req -new -nodes -utf8 -$(CONFIG_MODULE_SIG_HASH) -days 36500 \
-x509 -config x509.genkey \ -batch -x509 -config x509.genkey \
-outform DER -out signing_key.x509 \ -outform DER -out signing_key.x509 \
-keyout signing_key.priv -keyout signing_key.priv
@echo "###" @echo "###"
......
Markdown is supported
0% .
You are about to add 0 people to the discussion. Proceed with caution.
先完成此消息的编辑!
想要评论请 注册