Change log for sbsigntool package in Ubuntu

147 of 47 results
Published in oracular-release
Published in noble-release
Deleted in noble-proposed (Reason: Moved to noble)
sbsigntool (0.9.4-3.1ubuntu7) noble; urgency=high

  * No change rebuild against libssl3t64.

 -- Julian Andres Klode <email address hidden>  Mon, 08 Apr 2024 16:49:32 +0200
Superseded in noble-release
Deleted in noble-proposed (Reason: Moved to noble)
sbsigntool (0.9.4-3.1ubuntu6) noble; urgency=medium

  * No-change rebuild for CVE-2024-3094

 -- Steve Langasek <email address hidden>  Sun, 31 Mar 2024 17:11:07 +0000
Superseded in noble-release
Deleted in noble-proposed (Reason: Moved to noble)
sbsigntool (0.9.4-3.1ubuntu5) noble; urgency=medium

  * No-change rebuild against libssl3t64

 -- Steve Langasek <email address hidden>  Mon, 04 Mar 2024 21:20:35 +0000
Deleted in noble-updates (Reason: superseded by release)
Superseded in noble-release
Deleted in noble-proposed (Reason: Moved to noble)
sbsigntool (0.9.4-3.1ubuntu4) noble; urgency=medium

  * d/p/zero-checksum-unsigned.patch: ensure sbsign/sbattach --remove are
    roundtrip safe and produce identical original binaries. LP: #2044606

 -- Dimitri John Ledkov <email address hidden>  Sat, 25 Nov 2023 15:37:27 +0000
Superseded in noble-release
Published in mantic-release
Deleted in mantic-proposed (Reason: Moved to mantic)
sbsigntool (0.9.4-3.1ubuntu3) mantic; urgency=medium

  * d/p/fix-gcc-13-lto.patch: add a patch to fix LTO errors on GCC 13

 -- Zixing Liu <email address hidden>  Mon, 25 Sep 2023 12:04:46 -0600
Superseded in mantic-release
Published in lunar-release
Deleted in lunar-proposed (Reason: Moved to lunar)
sbsigntool (0.9.4-3.1ubuntu2) lunar; urgency=medium

  * Add support for certificate bundles in sbverify. LP: #1997232

 -- Dimitri John Ledkov <email address hidden>  Mon, 21 Nov 2022 11:30:41 +0000
Superseded in lunar-release
Obsolete in kinetic-release
Deleted in kinetic-proposed (Reason: Moved to kinetic)
sbsigntool (0.9.4-3.1ubuntu1) kinetic; urgency=medium

  * Merge from Debian unstable to restore Ubuntu delta (LP: #1980057)
    Remaining changes:
    - d/p/ubuntu-kernel-module-signing.patch (rebased on 0.9.4) and
      d/p/ubuntu-kernel-module-signing-fixes.patch (rebased on 0.9.4):
      add the kernel module signing tool to the package.
    - d/p/ubuntu-clear-image-before-use.patch: avoid use of uninitialised
      data causing a startup crash.
    - dp/sbkeysync-Don-t-ignore-errors-from-insert_new_keys.patch: exit non-zero
      upon key insertion failure
    Dropped changes, applied in Debian:
    - Disable -Werror on deprecation warnings for the OpenSSL transition
    - Apply patch to fix the OpenSSL3 build

 -- Simon Chopin <email address hidden>  Tue, 28 Jun 2022 10:20:23 +0200
Superseded in kinetic-release
Deleted in kinetic-proposed (Reason: Moved to kinetic)
sbsigntool (0.9.4-3.1) unstable; urgency=medium

  * Non-maintainer upload

  [ Simon Chopin ]
  * Disable -Werror on deprecation warnings for the OpenSSL transition
    (Closes: #1006575)
  * Apply patch to fix the OpenSSL3 build (LP: #1946193)

 -- Bastian Germann <email address hidden>  Sat, 04 Jun 2022 11:37:27 +0000
Published in focal-updates
Deleted in focal-proposed (Reason: moved to -updates)
sbsigntool (0.9.2-2ubuntu1.1) focal; urgency=medium

  * Enable signing riscv64 EFI binaries (LP: #1964510)

 -- Heinrich Schuchardt <email address hidden>  Thu, 10 Mar 2022 20:41:04 +0100
Published in bionic-updates
Deleted in bionic-proposed (Reason: moved to -updates)
sbsigntool (0.9.2-2ubuntu1~18.04.2) bionic; urgency=medium

  * Enable signing riscv64 EFI binaries (LP: #1964510)

 -- Heinrich Schuchardt <email address hidden>  Thu, 10 Mar 2022 20:41:04 +0100
Superseded in kinetic-release
Published in jammy-release
Deleted in jammy-proposed (Reason: Moved to jammy)
sbsigntool (0.9.4-2ubuntu2) jammy; urgency=medium

  * Disable -Werror on deprecation warnings for the OpenSSL transition
  * Apply patch to fix the OpenSSL3 build (LP: #1946193)

 -- Simon Chopin <email address hidden>  Fri, 05 Nov 2021 18:32:24 +0100

Available diffs

Superseded in jammy-release
Obsolete in impish-release
Deleted in impish-proposed (Reason: Moved to impish)
sbsigntool (0.9.4-2ubuntu1) impish; urgency=medium

  * Merge from Debian unstable (LP: #1941888)
    Remaining changes:
    - d/p/ubuntu-kernel-module-signing.patch (rebased on 0.9.4) and
      d/p/ubuntu-kernel-module-signing-fixes.patch (rebased on 0.9.4):
      add the kernel module signing tool to the package.
    - d/p/ubuntu-clear-image-before-use.patch: avoid use of uninitialised
      data causing a startup crash.
    - dp/sbkeysync-Don-t-ignore-errors-from-insert_new_keys.patch: exit non-zero
      upon key insertion failure

Deleted in impish-proposed (Reason: Requested by the uploader, should have been uploaded to D...)
sbsigntool (0.9.4-1) experimental; urgency=medium

  * Team upload
  * debian/rules: Add reproducible get-orig-source target
  * New upstream version 0.9.4
  * Drop fix_checksum_calc.patch, applied upstream
  * Use debhelper-compat (= 13) instead of debian/compat 9
  * Remove explicit dh-autoreconf dependency
  * Bump Standards-Version to 4.5.1
  * Add any-riscv64 to Architecture

 -- Julian Andres Klode <email address hidden>  Mon, 02 Aug 2021 13:31:02 +0200

Available diffs

Published in xenial-updates
Published in xenial-security
sbsigntool (0.6-0ubuntu10.2) xenial-security; urgency=medium

  * No-change re-build upload for xenial-security, in support of landing
    shim 15.4 or newer in xenial-security (LP: #1921134)

 -- Steve Beattie <email address hidden>  Fri, 14 May 2021 09:52:37 -0700
Superseded in bionic-updates
Deleted in bionic-proposed (Reason: moved to -updates)
sbsigntool (0.9.2-2ubuntu1~18.04.1) bionic; urgency=medium

  * No-change backport to bionic:
    - fix alignment of binaries and thus correct hash calculation LP:
    #1921387

Superseded in impish-release
Obsolete in hirsute-release
Obsolete in groovy-release
Deleted in groovy-proposed (Reason: moved to Release)
sbsigntool (0.9.2-2ubuntu4) groovy; urgency=medium

  * Add a Breaks for secureboot-db versions that did not yet have a
    secureboot-db.service that permits a non-zero sbkeysync exitcode.

 -- dann frazier <email address hidden>  Wed, 26 Aug 2020 15:57:13 -0600

Available diffs

Superseded in groovy-release
Deleted in groovy-proposed (Reason: moved to Release)
sbsigntool (0.9.2-2ubuntu3) groovy; urgency=medium

  * sbkeysync: exit non-zero upon key insertion failure. (LP: #1892797)

 -- dann frazier <email address hidden>  Mon, 24 Aug 2020 18:35:41 -0600

Available diffs

Superseded in groovy-release
Deleted in groovy-proposed (Reason: moved to Release)
sbsigntool (0.9.2-2ubuntu2) groovy; urgency=medium

  * No change rebuild against new CET ABI.

 -- Dimitri John Ledkov <email address hidden>  Fri, 10 Jul 2020 18:29:28 +0100

Available diffs

Superseded in groovy-release
Published in focal-release
Obsolete in eoan-release
Deleted in eoan-proposed (Reason: moved to release)
sbsigntool (0.9.2-2ubuntu1) eoan; urgency=low

  * Merge from Debian unstable.  Remaining changes:
    - d/p/ubuntu-kernel-module-signing.patch and
      d/p/ubuntu-kernel-module-signing-fixes.patch: add the kernel module
      signing tool to the package.
    - d/p/ubuntu-clear-image-before-use.patch: avoid use of uninitialised
      data causing a startup crash.
  * Dropped changes, included upstream:
    - d/p/ubuntu-handle-odd-buffer-lengths-in-checksum.patch: correctly
      handle odd byte length buffers.
  * Dropped changes, obsoleted upstream:
    - d/p/ubuntu-tests-disable-pie.patch: disable PIE

Available diffs

Superseded in eoan-release
Obsolete in disco-release
Obsolete in cosmic-release
Published in bionic-release
Deleted in bionic-proposed (Reason: moved to release)
sbsigntool (0.6-3.2ubuntu2) bionic; urgency=high

  * No change rebuild against openssl1.1.

 -- Dimitri John Ledkov <email address hidden>  Mon, 05 Feb 2018 16:53:19 +0000

Available diffs

Superseded in bionic-release
Obsolete in artful-release
Deleted in artful-proposed (Reason: moved to release)
sbsigntool (0.6-3.2ubuntu1) artful; urgency=low

  * Merge with Debian unstable, remaining changes:
    - d/p/ubuntu-handle-odd-buffer-lengths-in-checksum.patch: correctly
      handle odd byte length buffers.
    - d/p/ubuntu-kernel-module-signing.patch and
      d/p/ubuntu-kernel-module-signing-fixes.patch: add the kernel module
      signing tool to the package.
    - d/p/ubuntu-tests-disable-pie.patch: disable PIE
    - d/p/ubuntu-clear-image-before-use.patch: avoid use of uninitialised
      data causing a startup crash.

Available diffs

Published in trusty-updates
Deleted in trusty-proposed (Reason: moved to -updates)
sbsigntool (0.6-0ubuntu7.2) trusty; urgency=medium

  * debian/patches/0001-Support-openssl-1.0.2b-and-above.patch: handle the
    case where we can't get the issuer certificate, which typically happens
    after 1.0.2b; but it appears that 1.0.1f includes that check too, which
    fails in sbsigntool. (LP: #1474541)

 -- Mathieu Trudel-Lapierre <email address hidden>  Tue, 24 May 2016 14:24:45 -0400

Available diffs

Published in precise-updates
Deleted in precise-proposed (Reason: moved to -updates)
sbsigntool (0.6-0ubuntu4~12.04.2) precise; urgency=medium

  * debian/patches/0001-Support-openssl-1.0.2b-and-above.patch: handle the
    case where we can't get the issuer certificate, which typically happens
    after 1.0.2b; but it appears that 1.0.1f includes that check too, which
    fails in sbsigntool. (LP: #1474541)
  * debian/patches/ignore-certificate-expiries.patch: ignore certificate
    expiries when verifying signatures. (LP: #1234649)

 -- Mathieu Trudel-Lapierre <email address hidden>  Tue, 24 May 2016 14:41:24 -0400
Superseded in trusty-updates
Deleted in trusty-proposed (Reason: moved to -updates)
sbsigntool (0.6-0ubuntu7.1) trusty; urgency=medium

  * debian/patches/ubuntu-kernel-module-signing.patch: add signing support
    programs for Ubuntu archive signing.  (LP: #1579766)
  * debian/patches/ubuntu-kernel-module-signing-fixes.patch: add help
    and update program name.  This is used to generate the new manual page.

 -- Andy Whitcroft <email address hidden>  Mon, 09 May 2016 18:03:53 +0100

Available diffs

Obsolete in wily-updates
Deleted in wily-proposed (Reason: moved to -updates)
sbsigntool (0.6-0ubuntu8.1) wily; urgency=medium

  * debian/patches/ubuntu-kernel-module-signing.patch: add signing support
    programs for Ubuntu archive signing.  (LP: #1579766)
  * debian/patches/ubuntu-kernel-module-signing-fixes.patch: add help
    and update program name.  This is used to generate the new manual page.

 -- Andy Whitcroft <email address hidden>  Tue, 17 May 2016 11:42:33 +0100

Available diffs

Superseded in xenial-updates
Deleted in xenial-proposed (Reason: moved to -updates)
sbsigntool (0.6-0ubuntu10.1) xenial; urgency=medium

  * debian/patches/ubuntu-kernel-module-signing.patch: add signing support
    programs for Ubuntu archive signing.  (LP: #1579766)
  * debian/patches/ubuntu-kernel-module-signing-fixes.patch: add help
    and update program name.  This is used to generate the new manual page.
  * src/image.c: ensure we zero image objects on allocation.

 -- Andy Whitcroft <email address hidden>  Tue, 17 May 2016 11:52:18 +0100

Available diffs

Superseded in artful-release
Obsolete in zesty-release
Obsolete in yakkety-release
Deleted in yakkety-proposed (Reason: moved to release)
sbsigntool (0.6-0ubuntu12) yakkety; urgency=low

  * debian/patches/ubuntu-kernel-module-signing-fixes.patch: add help
    and update program name.  This is used to generate the new manual page.

 -- Andy Whitcroft <email address hidden>  Tue, 17 May 2016 13:23:47 +0100

Available diffs

Superseded in yakkety-release
Deleted in yakkety-proposed (Reason: moved to release)
sbsigntool (0.6-0ubuntu11) yakkety; urgency=medium

  * debian/patches/ubuntu-kernel-module-signing.patch: add signing support
    programs for Ubuntu archive signing.  (LP: #1579766)
  * tests: disable PIE mode when building examples for signing.
  * src/image.c: ensure we zero image objects on allocation.

 -- Andy Whitcroft <email address hidden>  Mon, 09 May 2016 14:25:49 +0100

Available diffs

Superseded in yakkety-release
Published in xenial-release
Deleted in xenial-proposed (Reason: moved to release)
sbsigntool (0.6-0ubuntu10) xenial; urgency=medium

  * debian/patches/sbverify_clear_out_cert_content.patch: clear out the
    contents part of the certificate we're building for signature verification
    from the EFI binary, in sbverify; OpenSSL 1.0.2e now enforces that there
    isn't data and content sections together. Thanks to Marc Deslauriers for
    help investigating this. (LP: #1526959)

 -- Mathieu Trudel-Lapierre <email address hidden>  Thu, 17 Dec 2015 14:55:09 -0500

Available diffs

Superseded in xenial-release
Deleted in xenial-proposed (Reason: moved to release)
sbsigntool (0.6-0ubuntu9) xenial; urgency=medium

  [ Linn Crosetto ]
  * debian/patches/0001-Handle-odd-buffer-lengths-in-checksum.patch:
    Fix checksum when handling buffers of odd length.  LP: #1511108

 -- Michael Terry <email address hidden>  Thu, 19 Nov 2015 16:32:19 -0500

Available diffs

Superseded in xenial-release
Obsolete in wily-release
Deleted in wily-proposed (Reason: moved to release)
sbsigntool (0.6-0ubuntu8) wily; urgency=medium

  * debian/patches/0001-Support-openssl-1.0.2b-and-above.patch: [PATCH]
    Support openssl 1.0.2b and above.  Thanks to Marc Deslauriers
    <email address hidden>.  LP: #1474541.

 -- Steve Langasek <email address hidden>  Wed, 15 Jul 2015 08:57:46 -0700

Available diffs

Superseded in wily-release
Obsolete in vivid-release
Obsolete in utopic-release
Published in trusty-release
Deleted in trusty-proposed (Reason: moved to release)
sbsigntool (0.6-0ubuntu7) trusty; urgency=medium

  * debian/patches/del-duplicate-define.patch: Remove duplicate define.
  * debian/patches/zero-sized-sections.patch: Fix failure in sbsigntool
    when it encouters zero-sized PE/COFF image sections (LP: #1252288).
  * debian/patches/arm-arm64-support.patch: Support signing ARM images.
 -- Adam Conrad <email address hidden>   Tue, 15 Apr 2014 14:54:42 +0100

Available diffs

Superseded in trusty-release
Deleted in trusty-proposed (Reason: moved to release)
sbsigntool (0.6-0ubuntu6) trusty; urgency=low

  * debian/patches/add_corrected_efivars_magic.patch: Cherry-picked upstream
    fix to add corrected efivars magic (LP: #1257305)
 -- Jean-Baptiste Lallement <email address hidden>   Tue, 03 Dec 2013 15:50:45 +0100

Available diffs

Superseded in trusty-release
Obsolete in saucy-release
Deleted in saucy-proposed (Reason: moved to release)
sbsigntool (0.6-0ubuntu5) saucy; urgency=low

  * debian/patches/ignore-certificate-expiries.patch: ignore certificate
    expiries when verifying signatures.  Closes LP: #1234649.
 -- Steve Langasek <email address hidden>   Fri, 04 Oct 2013 01:43:03 +0000

Available diffs

Superseded in precise-updates
Deleted in precise-proposed (Reason: moved to -updates)
Superseded in precise-proposed
sbsigntool (0.6-0ubuntu4~12.04.1) precise; urgency=low

  * Backport to update SecureBoot support.  LP: #1229572.

Obsolete in raring-updates
Deleted in raring-proposed (Reason: moved to -updates)
sbsigntool (0.6-0ubuntu4~13.04.1) raring; urgency=low

  * Backport to update SecureBoot support.  LP: #1229572.

Obsolete in quantal-updates
Deleted in quantal-proposed (Reason: moved to -updates)
sbsigntool (0.6-0ubuntu4~12.10.1) quantal; urgency=low

  * Backport to update SecureBoot support.  LP: #1229572.

Superseded in saucy-release
Deleted in saucy-proposed (Reason: moved to release)
sbsigntool (0.6-0ubuntu4) saucy; urgency=low

  * debian/patches/efi_arch_ia32.patch: Use AC_CANONICAL_HOST, not uname -m,
    to determine target. Closes LP: #1066038.
  * debian/patches/Align-signature-data-to-8-bytes.patch: Align signature
    data to 8 bytes.  This matches the Microsoft signing implementation,
    which enables us to use sbattach to verify the integrity of the binaries
    returned by the SysDev signing service.
  * debian/patches/update_checksums.patch: make sure we update the PE checksum
    field as well, also needed for matching the Microsoft signing
    implementation.
  * debian/patches/fix-signature-padding.patch: fix calculation of the
    size of our signature data, so that we don't write out extra zeroes
    when we detach a signature.
 -- Steve Langasek <email address hidden>   Fri, 23 Aug 2013 21:07:17 -0700

Available diffs

Superseded in saucy-release
Deleted in saucy-proposed (Reason: moved to release)
sbsigntool (0.6-0ubuntu3) saucy; urgency=low

  * Build-depend on gcc-multilib to support building the test suite.
 -- Colin Watson <email address hidden>   Mon, 17 Jun 2013 11:53:31 +0100

Available diffs

Superseded in saucy-release
Obsolete in raring-release
Deleted in raring-proposed (Reason: moved to release)
sbsigntool (0.6-0ubuntu2) raring; urgency=low

  * Mark sbsigntool Multi-Arch: foreign.
 -- Colin Watson <email address hidden>   Tue, 08 Jan 2013 12:20:42 +0000

Available diffs

Published in precise-security
Superseded in precise-updates
Deleted in precise-proposed (Reason: moved to -updates)
Superseded in precise-proposed
sbsigntool (0.6-0ubuntu1~12.04.1) precise-proposed; urgency=low

  * Backport to precise to support secure boot for 12.04.02.  LP: #1075181.
 -- Andy Whitcroft <email address hidden>   Mon, 19 Nov 2012 11:15:38 +0000
Superseded in raring-release
Obsolete in quantal-release
Superseded in quantal-release
sbsigntool (0.6-0ubuntu1) quantal; urgency=low

  * New upstream release.
    - Uses the new mount point for the efivars directory, for compatibility
      with the pending upstream kernel patches and compatibility with what
      mountall is doing.  LP: #1063061.
    - Fixes sbverify verification of the pkcs7 bundles that Microsoft-signed
      binaries deliver to us, enabling us to do build-time verification of
      shim-signed.
 -- Steve Langasek <email address hidden>   Thu, 11 Oct 2012 17:24:56 -0700

Available diffs

Superseded in quantal-release
sbsigntool (0.4-0ubuntu2) quantal; urgency=low

  * Fix FTBFS on i386 by defining EFI_ARCH to ia32 instead of uname.
 -- Adam Conrad <email address hidden>   Tue, 02 Oct 2012 07:44:59 -0600

Available diffs

Superseded in quantal-release
sbsigntool (0.4-0ubuntu1) quantal; urgency=low

  * New upstream release (FFe approved by Adam Conrad)
  * Add new uuid-dev and gnu-efi build dependencies.
 -- Andy Whitcroft <email address hidden>   Tue, 02 Oct 2012 10:15:17 +0100

Available diffs

Superseded in quantal-release
sbsigntool (0.3-0ubuntu2) quantal; urgency=low

  * Only build on amd64 and i386 (LP: #1020771).
 -- Colin Watson <email address hidden>   Mon, 01 Oct 2012 10:53:56 +0100

Available diffs

Superseded in quantal-release
sbsigntool (0.3-0ubuntu1) quantal; urgency=low

  * New upstream release.
 -- Steve Langasek <email address hidden>   Sat, 30 Jun 2012 01:37:52 +0000

Available diffs

Superseded in quantal-release
sbsigntool (0.2-0ubuntu1) quantal; urgency=low

  * Initial release.
 -- Steve Langasek <email address hidden>   Thu, 28 Jun 2012 01:47:06 +0000
147 of 47 results