I found the answer in the source code (it reuses secure boot key) and submitted a PR to clarify the manpage: https://github.com/systemd/mkosi/pull/2464
Thank you, Aaron VerDow From: VerDow, Aaron
Sent: Tuesday, March 5, 2024 10:58:15 AM To: systemd-devel@xxxxxxxxxxxxxxxxxxxxx Subject: mkosi: define key used by SignExpectedPcr I'm looking for a bit of clarification on how to define within mkosi the private key used by SignExpectedPcr. The mkosi manpage mentions a few keys but I'm not sure which one is used (or which other options are required) for the PCR signature specifically.
Thank you, Aaron VerDow |