attendedsyuspgrade-common: add key and set server 8356/head
authorPaul Spooren <mail@aparcar.org>
Wed, 6 Mar 2019 20:43:01 +0000 (21:43 +0100)
committerPaul Spooren <mail@aparcar.org>
Wed, 6 Mar 2019 22:24:08 +0000 (23:24 +0100)
commit54a2c8d087e65ce5389586b62b2ec41f00c0c8c0
tree032a110c9d2429339231de9455285876b2159247
parentaf68f431474a7cb6816e77a46aea2eb6ef35026e
attendedsyuspgrade-common: add key and set server

In collaboration with @dangowrt the server makes use of `ucert`.  Active
workers sign created firmware and clients check if the signature is
valid. Certs of *hacked* or inactive workers can be revoked.  Private CA
key is **not** stored on the upgrade server.

Only for devices already supporting ucert via firmware metadata.

Signed-off-by: Paul Spooren <mail@aparcar.org>
utils/attendedsysupgrade-common/Makefile
utils/attendedsysupgrade-common/files/attendedsysupgrade.defaults
utils/attendedsysupgrade-common/files/c06d891233ba699 [new file with mode: 0644]