New Signing Keys
Richard Hughes <[email protected]> Tue, 30 Sep 2025 16:25:23 +0000
| Newsgroups | dev.linux.lists.lvfs-announce |
|---|---|
| Message-ID | <d0QYp0aLyL0XJp1N36zpzlKxtLWIZELlg2GnQ-Vz434W3kOPDm2FLeKbvR8AEc_5YUeGfyN4k8301qdaiWN7Cu77oxEeaitu1ZFOSZphWYs=@hughsie.com> |
Hi all, Just a quick PSA: The LVFS is now signing with the old GPG and *two* new PK= CS#7 keys: * A new fwupd.org MLDSA-87 PKCS#7 certificate which is signed by a new LVFS= 2025 PQ (Post-Quantum) CA. * A new fwupd.org RSA-2048 PKCS#7 certificate which is signed by the existi= ng LVFS 2017 CA. This was going to expire anyway in 2028-01-16, but it seem= ed a good idea to reissue it considering we needed to upload a new PQ cert = anyway. Although the new PQ key needs a new LVFS-CA-2025PQ.pem to be deployed onto = the client (which will be included by default in the next fwupd release) th= e old CA is still good until 2047-08-01.=20 Some customers have a requirement to *only* trust the PQ signatures and for= that use case fwupd now supports OnlyTrustPostQuantumSignatures=3Dtrue in = fwupd.conf From a vendors-uploading-firmware and users-downloading-firmware points of = view, there are no additional actions required. The .jcat files embedded in= the .cab files have got slightly larger, as did the .jcat file for the met= adata. If you need some help with testing the PQ support please let me know= . Richard