mkimage: use environment variable MKIMAGE_SIGN_PIN to set pin for OpenSSL Engine
This patch adds the possibility to pass the PIN the OpenSSL Engine
used during signing via the environment variable MKIMAGE_SIGN_PIN.
This follows the approach used during kernel module
signing ("KBUILD_SIGN_PIN") or UBIFS image
signing ("MKIMAGE_SIGN_PIN").
Signed-off-by: Marc Kleine-Budde <mkl@pengutronix.de>
This commit is contained in:
committed by
Tom Rini
parent
89795ef3b6
commit
62b27a561c
@@ -533,8 +533,8 @@ Generic engine key ids:
|
||||
or
|
||||
"<key-name-hint>"
|
||||
|
||||
As mkimage does not at this time support prompting for passwords HSM may need
|
||||
key preloading wrapper to be used when invoking mkimage.
|
||||
In order to set the pin in the HSM, an environment variable "MKIMAGE_SIGN_PIN"
|
||||
can be specified.
|
||||
|
||||
The following examples use the Nitrokey Pro using pkcs11 engine. Instructions
|
||||
for other devices may vary.
|
||||
|
||||
Reference in New Issue
Block a user