mirror of
https://github.com/openglow-org/forgefirm.git
synced 2026-09-27 16:51:12 -07:00
installer: production release-signing key
The embedded pubkey is the production key from the signing ceremony; release.sh's key-match gate now refuses any other signer. Verified: production-signed archives pass fwup 1.16 and the factory's 0.14.2; dev-signed archives are rejected.
This commit is contained in:
+6
-2
@@ -119,8 +119,12 @@ motion constants were extracted from the `_RESOURCES` pulse files
|
|||||||
what fwup 0.14.2 expects; 1.x reads both). Cross-version compat is
|
what fwup 0.14.2 expects; 1.x reads both). Cross-version compat is
|
||||||
proven both ways (modern-packed signed archives apply with 0.14.2;
|
proven both ways (modern-packed signed archives apply with 0.14.2;
|
||||||
modern fwup verifies+applies the factory .fw — signer key
|
modern fwup verifies+applies the factory .fw — signer key
|
||||||
2017-05-001.pub). The production release key does not exist yet —
|
2017-05-001.pub). The production signing-key ceremony
|
||||||
generation/custody is an operator ceremony (UPDATE-SYSTEM.md gate 8).
|
(UPDATE-SYSTEM.md gate 8) was executed 2026-08-08.
|
||||||
|
**The production release key lives at
|
||||||
|
`~/forgefirm-release-key/fwup-key.priv`** (0600; `fwup-key.pub` +
|
||||||
|
`fwup-key-raw.pub` beside it; offline backups held by the operator) —
|
||||||
|
the installer embeds its pubkey, so releases sign with THIS key only.
|
||||||
Pack releases with `scripts/mkfw.sh`; the full pipeline is
|
Pack releases with `scripts/mkfw.sh`; the full pipeline is
|
||||||
`scripts/release.sh`, invoked on this host as:
|
`scripts/release.sh`, invoked on this host as:
|
||||||
`FWUP=~/fwup-lab/bin/fwup-v1.16.0 FWUP_COMPAT=~/fwup-lab/bin/fwup-0.14.2
|
`FWUP=~/fwup-lab/bin/fwup-v1.16.0 FWUP_COMPAT=~/fwup-lab/bin/fwup-0.14.2
|
||||||
|
|||||||
+10
-11
@@ -234,17 +234,16 @@ selector, factory restore and return — without touching a shell.*
|
|||||||
≥ 195 MiB.
|
≥ 195 MiB.
|
||||||
4. **RESOLVED** (Phase 3): dev archives are always signed with the
|
4. **RESOLVED** (Phase 3): dev archives are always signed with the
|
||||||
dedicated dev key (`release.sh --dev`), never unsigned.
|
dedicated dev key (`release.sh --dev`), never unsigned.
|
||||||
8. Production signing-key ceremony — **procedure defined, execution
|
8. **RESOLVED** — production signing-key ceremony executed: key
|
||||||
pending**: generate with fwup on the build host (never in the
|
generated on the build host (never in the repo, CI, or
|
||||||
repo, CI, or cloud-synced plaintext; the build-host copy is the
|
cloud-synced plaintext; the build-host copy is the only online
|
||||||
only online copy), keep ≥ 2 verified offline backups (USB /
|
copy, offline backups held by the operator), public key embedded
|
||||||
paper — the private key is 128 hex chars — / passphrase-encrypted
|
in the installer, and the chain verified: production-signed
|
||||||
file), embed the public key in the installer (release.sh's
|
archives verify with fwup 1.16 and the factory's 0.14.2 (raw
|
||||||
key-match gate enforces the swap), and verify a signed test
|
pubkey form); dev-signed archives are rejected. Custody optimizes
|
||||||
archive with both fwup generations before first use. Custody
|
against compromise over loss: loss means users re-run a fresh
|
||||||
optimizes against compromise over loss: loss means users re-run a
|
installer; compromise means attacker-signed firmware on fielded
|
||||||
fresh installer; compromise means attacker-signed firmware on
|
machines.
|
||||||
fielded machines.
|
|
||||||
5. Periodic GUI update check default-on vs opt-in (it pings the GitHub
|
5. Periodic GUI update check default-on vs opt-in (it pings the GitHub
|
||||||
API; proposal: on by default, apply always manual, config switch to
|
API; proposal: on by default, apply always manual, config switch to
|
||||||
disable).
|
disable).
|
||||||
|
|||||||
@@ -24,8 +24,7 @@ MIN_DATA_FREE_KB=300000
|
|||||||
|
|
||||||
# ForgeFIRM release-signing public key (raw 32-byte Ed25519, the format the
|
# ForgeFIRM release-signing public key (raw 32-byte Ed25519, the format the
|
||||||
# factory's fwup 0.14.2 expects).
|
# factory's fwup 0.14.2 expects).
|
||||||
# !! DEV KEY - must be replaced at the production key ceremony !!
|
PUBKEY='\x7c\x7c\x3f\x37\x91\xff\xe6\xdb\x81\xc6\x34\x41\x4b\x6f\xab\xed\x14\x65\xfb\x29\x25\xb6\xb1\x63\xb2\x1d\x38\xcb\xfb\x85\x91\x75'
|
||||||
PUBKEY='\x79\xf5\xc2\x53\x45\x13\x49\x51\xd4\x63\x17\x9d\x60\xd7\x7a\x97\xa7\xd6\xd6\xf4\xd8\x9f\x9d\xbd\x8f\xcc\x28\xfc\xba\xa0\x5d\x11'
|
|
||||||
|
|
||||||
LIGHTRED="\033[1;31m"
|
LIGHTRED="\033[1;31m"
|
||||||
YELLOW="\033[1;33m"
|
YELLOW="\033[1;33m"
|
||||||
|
|||||||
Reference in New Issue
Block a user