summaryrefslogtreecommitdiffstats
path: root/NEWS
diff options
context:
space:
mode:
authorLuca Boccassi <luca.boccassi@gmail.com>2024-11-15 18:25:29 +0100
committerLuca Boccassi <luca.boccassi@gmail.com>2024-11-15 18:25:29 +0100
commit7751bfb1796b4a8d56ac1ad975c97da0071f0db5 (patch)
tree37649a0ad5f184b8ea96dd12afec19fcd51c2c82 /NEWS
parentUpdate hwdb (diff)
downloadsystemd-7751bfb1796b4a8d56ac1ad975c97da0071f0db5.tar.xz
systemd-7751bfb1796b4a8d56ac1ad975c97da0071f0db5.zip
NEWS: systemd-keyutil, --certificate-source, --certificate-provider
Diffstat (limited to 'NEWS')
-rw-r--r--NEWS12
1 files changed, 12 insertions, 0 deletions
diff --git a/NEWS b/NEWS
index 9e9f729895..cf609e6e00 100644
--- a/NEWS
+++ b/NEWS
@@ -399,6 +399,15 @@ CHANGES WITH 257 in spe:
be extended, and a --measure-base= switch to support measurement
of multi-profile UKIs.
+ * ukify gained a --certificate-provider switch to use an OpenSSL
+ provider to load the certificate used to sign artifacts, instead of
+ having to provide the path to a file on disk.
+
+ * bootctl, systemd-keyutil, systemd-measure, systemd-repart, and
+ systemd-sbsign gained a new --certificate-source switch that allows
+ loading the X.509 certificate from an OpenSSL provider instead of a
+ file system path.
+
* systemd-boot's menu will now react to volume up/down rocker presses
the same way as to arrow up/down presses: they move the menu item up
or down. This is useful on device form factors that have only a
@@ -437,6 +446,9 @@ CHANGES WITH 257 in spe:
and providers, with pin caching support for PKCS11. ukify supports it
as an alternative to sbsigntool and pesign.
+ * A new systemd-keyutil tool has been added, that can be used to perform
+ various operations on private keys and X.509 certificates.
+
The journal:
* journalctl can now list invocations of a unit with the