mirror of
https://github.com/morgan9e/systemd
synced 2026-04-14 08:25:20 +09:00
In some examples we inserted "-initrd" after the "public-key" instead of before when naming PEM files. Let's fix that, and stick to common suffixes.
15 lines
539 B
Plaintext
15 lines
539 B
Plaintext
[UKI]
|
|
SecureBootPrivateKey=/etc/kernel/secureboot-private-key.pem
|
|
SecureBootCertificate=/etc/kernel/secureboot-certificate.pem
|
|
|
|
[PCRSignature:initrd]
|
|
Phases=enter-initrd
|
|
PCRPrivateKey=/etc/systemd/tpm2-pcr-initrd-private-key.pem
|
|
PCRPublicKey=/etc/systemd/tpm2-pcr-initrd-public-key.pem
|
|
|
|
[PCRSignature:system]
|
|
Phases=enter-initrd:leave-initrd enter-initrd:leave-initrd:sysinit
|
|
enter-initrd:leave-initrd:sysinit:ready
|
|
PCRPrivateKey=/etc/systemd/tpm2-pcr-private-key-system.pem
|
|
PCRPublicKey=/etc/systemd/tpm2-pcr-public-key-system.pem
|