New Signing Keys

Richard Hughes <[email protected]> Tue, 30 Sep 2025 16:25:23 +0000
Newsgroups dev.linux.lists.lvfs-announce
Message-ID <d0QYp0aLyL0XJp1N36zpzlKxtLWIZELlg2GnQ-Vz434W3kOPDm2FLeKbvR8AEc_5YUeGfyN4k8301qdaiWN7Cu77oxEeaitu1ZFOSZphWYs=@hughsie.com>
Hi all,

Just a quick PSA: The LVFS is now signing with the old GPG and *two* new PK=
CS#7 keys:

* A new fwupd.org MLDSA-87 PKCS#7 certificate which is signed by a new LVFS=
 2025 PQ (Post-Quantum) CA.

* A new fwupd.org RSA-2048 PKCS#7 certificate which is signed by the existi=
ng LVFS 2017 CA. This was going to expire anyway in 2028-01-16, but it seem=
ed a good idea to reissue it considering we needed to upload a new PQ cert =
anyway.

Although the new PQ key needs a new LVFS-CA-2025PQ.pem to be deployed onto =
the client (which will be included by default in the next fwupd release) th=
e old CA is still good until 2047-08-01.=20

Some customers have a requirement to *only* trust the PQ signatures and for=
 that use case fwupd now supports OnlyTrustPostQuantumSignatures=3Dtrue in =
fwupd.conf

From a vendors-uploading-firmware and users-downloading-firmware points of =
view, there are no additional actions required. The .jcat files embedded in=
 the .cab files have got slightly larger, as did the .jcat file for the met=
adata. If you need some help with testing the PQ support please let me know=
.

Richard