HomeFreeBSD

Update libsecureboot

Description

Update libsecureboot

Preparation for updating bearssl, pull in updates to libsecureboot.

o fix handling of some out-of-memory cases

o allow more control over reporting of Verified/Unverified files.

this helps boot time when console output is slow

o recheck verbose/debug level after reading any unverified file

o more debug support for vectx

o hash_string to support fake stat for tftp

o tests/tvo add -v to simply verify signatures

o vets.c allow for HAVE_BR_X509_TIME_CHECK which will greatly simplify

verification in loader

o report date when certificate fails validity period checks

Reviewed by: stevek
Sponsored by: Juniper Networks, Inc.

(cherry picked from commit 666554111a7e6b4c1a9a6ff2e73f12cd582573bb)

Details

Provenance
sjgAuthored on Apr 18 2022, 7:53 PM
gbeCommitted on Apr 14 2023, 5:19 AM
Parents
rG8dd1299ca599: Move ve_check_hash prototype to libsecureboot-priv.h
Branches
Unknown
Tags
Unknown