#7598 Please add rhughes to the pesign ACL
Closed: Fixed 5 years ago Opened 5 years ago by puiterwijk.

Filed for @rhuges, original at https://pagure.io/fedora-infrastructure/issue/7063.

Describe what you need us to do:
Please can somebody add me (rhughes) to the pesign ACL and move fwupd to that group. Some background: fwupdate recently merged into fwupd, and so the fwup.efi binary that used to get built by fwupdate now gets built by the fwupd srpm instead. pjones used to be the person building the package, now it's me.

When do you need this? (YYYY/MM/DD)
Ideally before the end of July.

If we cannot complete your request, what is the impact?
We can't install firmware in Fedora 29 when secure boot is turned on.


Note that I asked him to file a ticket, sorry if I pointed him the wrong place.

Also note that in addition to the permissions, we need to add fwupd to the hub config (with an ansible patch/run against hub playbook).

I'll go ahead and do this unless someone else would like to do so before me. :smile:

Oh, looks like fwupd is in there already, sorry... just need the perms now.

And since thats just a short command line, done.

Let us know if you have any problems with it.

Metadata Update from @kevin:
- Issue close_status updated to: Fixed
- Issue status updated to: Closed (was: Open)

5 years ago

Thanks for the super-quick action! I assume I should be getting "Red Hat Test Certificate" when doing a scratch build?

Yeah, scratch builds work as they always have. Only official builds are sent to the builders with the signing software in place.

If you need to test something, @pjones has a pesign-test-app package that goes to the secure-boot channel, but isn't used for anything after that (ie, not shipped in media, etc).

Login to comment on this ticket.

Metadata