sbsigntool (0.9.2-2ubuntu1~18.04.2) bionic; urgency=medium * Enable signing riscv64 EFI binaries (LP: #1964510) -- Heinrich Schuchardt Thu, 10 Mar 2022 20:41:04 +0100 sbsigntool (0.9.2-2ubuntu1~18.04.1) bionic; urgency=medium * No-change backport to bionic: - fix alignment of binaries and thus correct hash calculation LP: #1921387 -- Dimitri John Ledkov Thu, 25 Mar 2021 13:52:52 +0000 sbsigntool (0.9.2-2ubuntu1) eoan; urgency=low * Merge from Debian unstable. Remaining changes: - d/p/ubuntu-kernel-module-signing.patch and d/p/ubuntu-kernel-module-signing-fixes.patch: add the kernel module signing tool to the package. - d/p/ubuntu-clear-image-before-use.patch: avoid use of uninitialised data causing a startup crash. * Dropped changes, included upstream: - d/p/ubuntu-handle-odd-buffer-lengths-in-checksum.patch: correctly handle odd byte length buffers. * Dropped changes, obsoleted upstream: - d/p/ubuntu-tests-disable-pie.patch: disable PIE -- Steve Langasek Fri, 03 May 2019 16:12:28 -0700 sbsigntool (0.9.2-2) unstable; urgency=medium * Change Maintainer to be the EFI team, with Pierre and me as Uploaders * Remove the old alignment patch, looks to be un-needed now * Fix PE/COFF checksum calculation - only count the cert_table struct once when performing the calculation and counting buffer sizes. -- Steve McIntyre <93sam@debian.org> Fri, 19 Apr 2019 23:41:15 +0200 sbsigntool (0.9.2-1) unstable; urgency=medium * Add watch file * New upstream version 0.9.2 (Closes: #920013, #828696) * Remove test file after clean * Refreshed quilt patches, and removed all that were merged * Use priority optional -- Pierre Chifflier Mon, 21 Jan 2019 21:20:40 +0100 sbsigntool (0.6-3.2ubuntu2) bionic; urgency=high * No change rebuild against openssl1.1. -- Dimitri John Ledkov Mon, 05 Feb 2018 16:53:19 +0000 sbsigntool (0.6-3.2ubuntu1) artful; urgency=low * Merge with Debian unstable, remaining changes: - d/p/ubuntu-handle-odd-buffer-lengths-in-checksum.patch: correctly handle odd byte length buffers. - d/p/ubuntu-kernel-module-signing.patch and d/p/ubuntu-kernel-module-signing-fixes.patch: add the kernel module signing tool to the package. - d/p/ubuntu-tests-disable-pie.patch: disable PIE - d/p/ubuntu-clear-image-before-use.patch: avoid use of uninitialised data causing a startup crash. -- Andy Whitcroft Fri, 28 Apr 2017 08:40:27 +0100 sbsigntool (0.6-3.2) unstable; urgency=medium * Non-maintainer upload. * Fix linker flags for test cases (Closes: #842446) -- Ben Hutchings Sun, 29 Jan 2017 01:00:17 +0000 sbsigntool (0.6-3.1) unstable; urgency=medium * Non-maintainer upload with approval of maintainer * Limit build-dependency on gcc-multilib to the architectures where it is available, and disable tests where it is not * Enable building on arm64 and armhf (Closes: #821144) * Update OpenSSL API usage to support OpenSSL 1.1 (Closes: #828539) * Remove incorrect Vcs-Bzr field -- Ben Hutchings Sun, 26 Jun 2016 23:39:15 +0200 sbsigntool (0.6-3) unstable; urgency=medium * Add sbsign_check_write_return.patch: check return when writing output file (Closes: #819987) * Mark package as Multi-Arch: foreign (Closes: #820002) -- Pierre Chifflier Wed, 20 Apr 2016 09:34:26 +0200 sbsigntool (0.6-2) unstable; urgency=medium * Add missing build-dep on openssl (Closes: #816264) * debian/patches/sbverify_clear_out_cert_content.patch: clear out the contents part of the certificate we're building for signature verification from the EFI binary, in sbverify; OpenSSL 1.0.2e now enforces that there isn't data and content sections together. Bakport from ubuntu patch (LP: #1526959) * Bump Standards Version to 3.9.7 -- Pierre Chifflier Tue, 08 Mar 2016 08:11:10 +0100 sbsigntool (0.6-1) unstable; urgency=low * Initial release (Closes: #702254) -- Pierre Chifflier Wed, 23 Sep 2015 08:40:56 +0200 sbsigntool (0.6-0ubuntu12) yakkety; urgency=low * debian/patches/ubuntu-kernel-module-signing-fixes.patch: add help and update program name. This is used to generate the new manual page. -- Andy Whitcroft Tue, 17 May 2016 13:23:47 +0100 sbsigntool (0.6-0ubuntu11) yakkety; urgency=medium * debian/patches/ubuntu-kernel-module-signing.patch: add signing support programs for Ubuntu archive signing. (LP: #1579766) * tests: disable PIE mode when building examples for signing. * src/image.c: ensure we zero image objects on allocation. -- Andy Whitcroft Mon, 09 May 2016 14:25:49 +0100 sbsigntool (0.6-0ubuntu10) xenial; urgency=medium * debian/patches/sbverify_clear_out_cert_content.patch: clear out the contents part of the certificate we're building for signature verification from the EFI binary, in sbverify; OpenSSL 1.0.2e now enforces that there isn't data and content sections together. Thanks to Marc Deslauriers for help investigating this. (LP: #1526959) -- Mathieu Trudel-Lapierre Thu, 17 Dec 2015 14:55:09 -0500 sbsigntool (0.6-0ubuntu9) xenial; urgency=medium [ Linn Crosetto ] * debian/patches/0001-Handle-odd-buffer-lengths-in-checksum.patch: Fix checksum when handling buffers of odd length. LP: #1511108 -- Michael Terry Thu, 19 Nov 2015 16:32:19 -0500 sbsigntool (0.6-0ubuntu8) wily; urgency=medium * debian/patches/0001-Support-openssl-1.0.2b-and-above.patch: [PATCH] Support openssl 1.0.2b and above. Thanks to Marc Deslauriers . LP: #1474541. -- Steve Langasek Wed, 15 Jul 2015 08:57:46 -0700 sbsigntool (0.6-0ubuntu7) trusty; urgency=medium * debian/patches/del-duplicate-define.patch: Remove duplicate define. * debian/patches/zero-sized-sections.patch: Fix failure in sbsigntool when it encouters zero-sized PE/COFF image sections (LP: #1252288). * debian/patches/arm-arm64-support.patch: Support signing ARM images. -- Adam Conrad Tue, 15 Apr 2014 14:54:42 +0100 sbsigntool (0.6-0ubuntu6) trusty; urgency=low * debian/patches/add_corrected_efivars_magic.patch: Cherry-picked upstream fix to add corrected efivars magic (LP: #1257305) -- Jean-Baptiste Lallement Tue, 03 Dec 2013 15:50:45 +0100 sbsigntool (0.6-0ubuntu5) saucy; urgency=low * debian/patches/ignore-certificate-expiries.patch: ignore certificate expiries when verifying signatures. Closes LP: #1234649. -- Steve Langasek Fri, 04 Oct 2013 01:43:03 +0000 sbsigntool (0.6-0ubuntu4) saucy; urgency=low * debian/patches/efi_arch_ia32.patch: Use AC_CANONICAL_HOST, not uname -m, to determine target. Closes LP: #1066038. * debian/patches/Align-signature-data-to-8-bytes.patch: Align signature data to 8 bytes. This matches the Microsoft signing implementation, which enables us to use sbattach to verify the integrity of the binaries returned by the SysDev signing service. * debian/patches/update_checksums.patch: make sure we update the PE checksum field as well, also needed for matching the Microsoft signing implementation. * debian/patches/fix-signature-padding.patch: fix calculation of the size of our signature data, so that we don't write out extra zeroes when we detach a signature. -- Steve Langasek Fri, 23 Aug 2013 21:07:17 -0700 sbsigntool (0.6-0ubuntu3) saucy; urgency=low * Build-depend on gcc-multilib to support building the test suite. -- Colin Watson Mon, 17 Jun 2013 11:53:31 +0100 sbsigntool (0.6-0ubuntu2) raring; urgency=low * Mark sbsigntool Multi-Arch: foreign. -- Colin Watson Tue, 08 Jan 2013 12:20:42 +0000 sbsigntool (0.6-0ubuntu1) quantal; urgency=low * New upstream release. - Uses the new mount point for the efivars directory, for compatibility with the pending upstream kernel patches and compatibility with what mountall is doing. LP: #1063061. - Fixes sbverify verification of the pkcs7 bundles that Microsoft-signed binaries deliver to us, enabling us to do build-time verification of shim-signed. -- Steve Langasek Thu, 11 Oct 2012 17:24:56 -0700 sbsigntool (0.4-0ubuntu2) quantal; urgency=low * Fix FTBFS on i386 by defining EFI_ARCH to ia32 instead of uname. -- Adam Conrad Tue, 02 Oct 2012 07:44:59 -0600 sbsigntool (0.4-0ubuntu1) quantal; urgency=low * New upstream release. * Add new uuid-dev and gnu-efi build dependancies. -- Andy Whitcroft Tue, 02 Oct 2012 10:15:17 +0100 sbsigntool (0.3-0ubuntu2) quantal; urgency=low * Only build on amd64 and i386 (LP: #1020771). -- Colin Watson Mon, 01 Oct 2012 10:53:56 +0100 sbsigntool (0.3-0ubuntu1) quantal; urgency=low * New upstream release. -- Steve Langasek Sat, 30 Jun 2012 01:37:52 +0000 sbsigntool (0.2-0ubuntu1) quantal; urgency=low * Initial release. -- Steve Langasek Thu, 28 Jun 2012 01:47:06 +0000