diff mbox series

[1/1] doc: provide links to Microsoft UEFI certificates

Message ID 20200714105539.68115-1-xypron.glpk@gmx.de
State Accepted
Commit 677da1c089ce5462aaf34a19b28ff16543446e71
Headers show
Series [1/1] doc: provide links to Microsoft UEFI certificates | expand

Commit Message

Heinrich Schuchardt July 14, 2020, 10:55 a.m. UTC
Some distributions provide UEFI binaries like Shim that have been signed
using a Microsoft certificate. Provide the download paths for the public
keys.

Signed-off-by: Heinrich Schuchardt <xypron.glpk at gmx.de>
---
 doc/uefi/uefi.rst | 9 +++++++++
 1 file changed, 9 insertions(+)

--
2.27.0
diff mbox series

Patch

diff --git a/doc/uefi/uefi.rst b/doc/uefi/uefi.rst
index 03d6fd0c6a..a72e729cc8 100644
--- a/doc/uefi/uefi.rst
+++ b/doc/uefi/uefi.rst
@@ -188,6 +188,15 @@  on the sandbox
     cd <U-Boot source directory>
     pytest.py test/py/tests/test_efi_secboot/test_signed.py --bd sandbox

+UEFI binaries may be signed by Microsoft using the following certificates:
+
+* KEK: Microsoft Corporation KEK CA 2011
+  http://go.microsoft.com/fwlink/?LinkId=321185.
+* db: Microsoft Windows Production PCA 2011
+  http://go.microsoft.com/fwlink/p/?linkid=321192.
+* db: Microsoft Corporation UEFI CA 2011
+  http://go.microsoft.com/fwlink/p/?linkid=321194.
+
 Using OP-TEE for EFI variables
 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~