summaryrefslogtreecommitdiffstats
path: root/man
diff options
context:
space:
mode:
authorDaan De Meyer <daan.j.demeyer@gmail.com>2024-11-06 18:09:37 +0100
committerDaan De Meyer <daan.j.demeyer@gmail.com>2024-11-07 20:33:08 +0100
commit64cc7ba517c7d57a25ede9833e60aa8aa25fc6ed (patch)
treeb43d68cab67b8963d989e7cf939248c4055eb4a1 /man
parentmeasure: Add pcrpkey verb (diff)
downloadsystemd-64cc7ba517c7d57a25ede9833e60aa8aa25fc6ed.tar.xz
systemd-64cc7ba517c7d57a25ede9833e60aa8aa25fc6ed.zip
ukify: Introduce --certificate-provider= option
This translates to --certificate-source=provider:<provider> for signing tools invoked by ukify.
Diffstat (limited to 'man')
-rw-r--r--man/ukify.xml11
1 files changed, 11 insertions, 0 deletions
diff --git a/man/ukify.xml b/man/ukify.xml
index 6a697ee6e1..c42d6ae5c7 100644
--- a/man/ukify.xml
+++ b/man/ukify.xml
@@ -528,6 +528,17 @@
</varlistentry>
<varlistentry>
+ <term><varname>CertificateProvider=<replaceable>PROVIDER</replaceable></varname></term>
+ <term><option>--certificate-provider=<replaceable>PROVIDER</replaceable></option></term>
+
+ <listitem><para>An OpenSSL provider to be used for loading the certificate used to sign the
+ resulting binary and PCR measurements. This option can only be used when using
+ <command>systemd-sbsign</command> as the signing tool.</para>
+
+ <xi:include href="version-info.xml" xpointer="v257"/></listitem>
+ </varlistentry>
+
+ <varlistentry>
<term><varname>SignKernel=<replaceable>BOOL</replaceable></varname></term>
<term><option>--sign-kernel</option></term>
<term><option>--no-sign-kernel</option></term>