• Ard Biesheuvel's avatar
    efi: libstub: Remove zboot signing from build options · f57fb375
    Ard Biesheuvel authored
    The zboot decompressor series introduced a feature to sign the PE/COFF
    kernel image for secure boot as part of the kernel build. This was
    necessary because there are actually two images that need to be signed:
    the kernel with the EFI stub attached, and the decompressor application.
    
    This is a bit of a burden, because it means that the images must be
    signed on the the same system that performs the build, and this is not
    realistic for distros.
    
    During the next cycle, we will introduce changes to the zboot code so
    that the inner image no longer needs to be signed. This means that the
    outer PE/COFF image can be handled as usual, and be signed later in the
    release process.
    
    Let's remove the associated Kconfig options now so that they don't end
    up in a LTS release while already being deprecated.
    Signed-off-by: default avatarArd Biesheuvel <ardb@kernel.org>
    f57fb375
Kconfig 11.9 KB