heads
heads copied to clipboard
[meta-issue] Push OEMs to maintain+ detach sign their ISOs and inlude their distro public key in tree
- [ ] https://github.com/Nitrokey/qubes-oem/issues/20
- [ ] https://github.com/Nitrokey/ubuntu-oem/issues/11
- [ ] ~@JonathonHall-Purism pureos key in tree but no detached signatures~ Removed in PR https://github.com/linuxboot/heads/pull/1746
- [ ] others?
Also think of a mechanism to check public keys against their expiration date, warning of expiration proactively in CI. Tails is becoming an issue as per last pr #1631
Track https://github.com/ben-grande/qusal/issues/46 since I have no clue how to efficiently do that