[Bug 2003701] [NEW] PKCS7: Message signed outside of X.509 validity window

Dimitri John Ledkov 2003701 at bugs.launchpad.net
Mon Jan 23 11:19:56 UTC 2023


Public bug reported:

When signing UEFI applications, the signature includes signing
timestamp.

Kernels, upon kexec, check that message signature is within the validity
of the X.509 signing certificate.

When using original canonical kernel team test key, I no longer can
kexec kernels, as the test key has expired.

UEFI specifications in general ignore signing time.

IMHO we should remove / not include signing timestamp in the UEFI
signatures to avoid this.

** Affects: sbsigntool (Ubuntu)
     Importance: Undecided
         Status: New

-- 
You received this bug notification because you are a member of Ubuntu
Foundations Bugs, which is subscribed to sbsigntool in Ubuntu.
https://bugs.launchpad.net/bugs/2003701

Title:
  PKCS7: Message signed outside of X.509 validity window

Status in sbsigntool package in Ubuntu:
  New

Bug description:
  When signing UEFI applications, the signature includes signing
  timestamp.

  Kernels, upon kexec, check that message signature is within the
  validity of the X.509 signing certificate.

  When using original canonical kernel team test key, I no longer can
  kexec kernels, as the test key has expired.

  UEFI specifications in general ignore signing time.

  IMHO we should remove / not include signing timestamp in the UEFI
  signatures to avoid this.

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/sbsigntool/+bug/2003701/+subscriptions




More information about the foundations-bugs mailing list