Skip to content

Update CentOS Stream kernel signing cert.#804

Merged
vathpela merged 1 commit into
rhboot:mainfrom
vathpela:update-centos-certs
Jun 24, 2026
Merged

Update CentOS Stream kernel signing cert.#804
vathpela merged 1 commit into
rhboot:mainfrom
vathpela:update-centos-certs

Conversation

@vathpela

Copy link
Copy Markdown
Member

CentOS recently rotated kernel and grub's signing certs and keys, so we need to reflect the new one now.

CentOS recently rotated kernel and grub's signing certs and keys, so we
need to reflect the new one now.

Signed-off-by: Peter Jones <pjones@redhat.com>
@vathpela

Copy link
Copy Markdown
Member Author

Right now this fails because 1) as currently implemented the mkosi code doesn't support VENDOR_DB_FILE= instead of VENDOR_CERT_FILE= so we can only have one cert, and 2) the CentOS Stream 10 kernel is incorrectly still being signed with the old certificate.

I'm gonna push this anyway and manually wave CI on things that need those two targets, while others work on fixing the kernel.

@vathpela vathpela merged commit db37959 into rhboot:main Jun 24, 2026
54 of 56 checks passed
@vathpela vathpela deleted the update-centos-certs branch June 24, 2026 14:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant