base-files: introduce sysupgrade signature chain verification
authorDaniel Golle <daniel@makrotopia.org>
Mon, 15 Jan 2018 02:37:17 +0000 (03:37 +0100)
committerDaniel Golle <daniel@makrotopia.org>
Wed, 8 Aug 2018 00:22:54 +0000 (02:22 +0200)
commit8174853c78f88b854ac66a3f0a5380d36ededa9a
tree90db16f8c8ced86a8329cb98b87b7e593a435acc
parentec78f03de589adc9bd47a02d723d7054510601dd
base-files: introduce sysupgrade signature chain verification

Verify ucert signature chains in sysupgrade images in case ucert is
installed and $CHECK_IMAGE_SIGNARURE = 1.
Also make sure ucert host binary is present and generate a self-signed
ucert in case $TOPDIR/key-build.ucert is missing.

Signed-off-by: Daniel Golle <daniel@makrotopia.org>
package/base-files/Makefile
package/base-files/files/lib/upgrade/fwtool.sh
package/base-files/files/sbin/sysupgrade