Re: [PATCH v2 1/2] certs: Trigger creation of RSA module signing key if it's not an RSA key

From: Stefan Berger
Date: Thu Apr 08 2021 - 15:19:52 EST



On 4/8/21 1:15 PM, Mimi Zohar wrote:
On Thu, 2021-04-08 at 11:24 -0400, Stefan Berger wrote:
Address a kbuild issue where a developer created an ECDSA key for signing
kernel modules and then builds an older version of the kernel, when bi-
secting the kernel for example, that does not support ECDSA keys.

Trigger the creation of an RSA module signing key if it is not an RSA key.

Fixes: cfc411e7fff3 ("Move certificate handling to its own directory")
Signed-off-by: Stefan Berger <stefanb@xxxxxxxxxxxxx>
Thanks, Stefan.

Reviewed-by: Mimi Zohar <zohar@xxxxxxxxxxxxx>


Via which tree will this go upstream? keyrings?


   Stefan