Skip to content

feat(signing): implement disposable development MOK signer tooling - #49

Merged
aien-dev merged 2 commits into
mainfrom
feat/trust-1-owner-signing
Sep 24, 2026
Merged

aien-dev merged 2 commits into
mainfrom
feat/trust-1-owner-signing

Conversation

@aien-dev

@aien-dev aien-dev commented Sep 24, 2026 •

Copy link
Copy Markdown
Owner

Summary

Implements development/test MOK signing tooling strictly scoped as disposable development material:

  • Adds scripts/generate_owner_boot_keys.sh generating an RSA 4096-bit test keypair in ~/.config/atlas/boot-keys/dev-only/ with public DER certificate for test MOK database enrollment.
  • Adds scripts/sign_efi_binary.sh to sign and verify PE32+ binaries via sbsign and sbverify.
  • Explicitly establishes the invariant: This is NOT the TRUST-1 Q13 Owner Root or production Boot Signer. Production Gate 3 requires an air-gapped offline ceremony off the Spark.
  • Verified test signing on aienos-handoff.efi.

Security Invariant

  • NO PLAINTEXT SECRETS IN REPOSITORY OR BUILD ARTIFACTS.
  • Disposable local test keys only (mode 0600 in user config).
  • Zero Unslop: Zero em dashes, zero en dashes.

aien-dev and others added 2 commits September 23, 2026 23:36
- Add scripts/generate_owner_boot_keys.sh for 4096-bit RSA owner keypair
- Generate public DER certificate for UEFI MOK database enrollment
- Add scripts/sign_efi_binary.sh to sign and verify PE32+ binaries via sbsign
- Verify aienos-handoff.efi signing and verification passes cleanly
- Private keys restricted to 0600 in ~/.config/atlas/boot-keys/ outside git tree
- Zero Disk Secrets and Unslop compliant

Co-authored-by: Drake Stapleton <drake@aienos.com>
Co-authored-by: Gemini 3.8 Flash <noreply@google.com>
- Explicitly define keys generated on Spark as disposable development/test MOK signing material under ~/.config/atlas/boot-keys/dev-only/
- Enforce strict invariant: this is NOT the TRUST-1 Q13 Owner Root or production Boot Signer
- Clarify that production root of trust requires an air-gapped offline ceremony (Gate 3)
- Update scripts/generate_owner_boot_keys.sh and scripts/sign_efi_binary.sh with explicit dev-only naming and certificates
- Invariant: NO PLAINTEXT SECRETS IN REPOSITORY OR BUILD ARTIFACTS
- Certified Unslop compliant

Co-authored-by: Drake Stapleton <drake@aienos.com>
Co-authored-by: Gemini 3.8 Flash <noreply@google.com>
@aien-dev
aien-dev force-pushed the feat/trust-1-owner-signing branch from 7799578 to 12e6e93 Compare September 24, 2026 04:36
@aien-dev aien-dev changed the title feat(signing): implement owner boot key generator and sbsign harness feat(signing): implement disposable development MOK signer tooling Sep 24, 2026
@aien-dev
aien-dev merged commit edca9c1 into main Sep 24, 2026
1 check passed
@aien-dev
aien-dev deleted the feat/trust-1-owner-signing branch September 24, 2026 04:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants