)]}'
{"/COMMIT_MSG":[{"author":{"_account_id":33394,"name":"Mark Asselstine","email":"mark.asselstine@windriver.com","username":"markawr"},"change_message_id":"bc1eafaff3fdce793ebe690d28e99a08fb964f32","unresolved":true,"context_lines":[{"line_number":4,"context_line":"Commit:     Li Zhou \u003cli.zhou@windriver.com\u003e"},{"line_number":5,"context_line":"CommitDate: 2023-04-23 04:17:18 -0400"},{"line_number":6,"context_line":""},{"line_number":7,"context_line":"Update secure boot doc about StarlingX debian"},{"line_number":8,"context_line":""},{"line_number":9,"context_line":"Add \"Build considerations for signing packages for UEFI Secure Boot\""},{"line_number":10,"context_line":"for Debian build, which has been different with Centos build."}],"source_content_type":"text/x-gerrit-commit-message","patch_set":2,"id":"cd1a67da_306eda20","line":7,"updated":"2023-04-24 13:21:34.000000000","message":"s/debian/Debian/","commit_id":"d243d94e9473245d5db6e0e0659eebbae2b0b548"},{"author":{"_account_id":32832,"name":"Li Zhou","display_name":"Li Zhou","email":"li.zhou@windriver.com","username":"lzhou2"},"change_message_id":"aba4bd7764ce32a6c1c3767d0ddd5b706b82f9c2","unresolved":false,"context_lines":[{"line_number":4,"context_line":"Commit:     Li Zhou \u003cli.zhou@windriver.com\u003e"},{"line_number":5,"context_line":"CommitDate: 2023-04-23 04:17:18 -0400"},{"line_number":6,"context_line":""},{"line_number":7,"context_line":"Update secure boot doc about StarlingX debian"},{"line_number":8,"context_line":""},{"line_number":9,"context_line":"Add \"Build considerations for signing packages for UEFI Secure Boot\""},{"line_number":10,"context_line":"for Debian build, which has been different with Centos build."}],"source_content_type":"text/x-gerrit-commit-message","patch_set":2,"id":"839c80b5_85c0e7ef","line":7,"in_reply_to":"cd1a67da_306eda20","updated":"2023-04-25 02:29:17.000000000","message":"Done","commit_id":"d243d94e9473245d5db6e0e0659eebbae2b0b548"}],"/PATCHSET_LEVEL":[{"author":{"_account_id":33394,"name":"Mark Asselstine","email":"mark.asselstine@windriver.com","username":"markawr"},"change_message_id":"499e8ae51457998b801262acbdadcd014a8c122f","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":1,"id":"43fd09f5_3f7c1038","updated":"2023-04-20 18:37:20.000000000","message":"Just a few minor issues. Overall the text is well done.","commit_id":"498394aa520fdb1656a91216e98dcafcdb9e05f6"},{"author":{"_account_id":34021,"name":"Luis Sampaio","display_name":"Luis Sampaio","email":"luis.sampaio@windriver.com","username":"lsampaio"},"change_message_id":"c0fd747dc1330b476a6683a521565ccdc9ea98a3","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":3,"id":"ca77ecd7_a777a06c","updated":"2023-05-09 16:27:46.000000000","message":"@Juanita, do you know the process to add this update into the stx docs?","commit_id":"bcdff155149dc4dad08f7e19874573e1ed682042"},{"author":{"_account_id":32832,"name":"Li Zhou","display_name":"Li Zhou","email":"li.zhou@windriver.com","username":"lzhou2"},"change_message_id":"43c133355bc7b9eb3b6c5acbaa14bb1cf7b5b14b","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":3,"id":"a695f20c_378bb86d","updated":"2023-07-10 01:26:07.000000000","message":"Ping.","commit_id":"bcdff155149dc4dad08f7e19874573e1ed682042"},{"author":{"_account_id":32832,"name":"Li Zhou","display_name":"Li Zhou","email":"li.zhou@windriver.com","username":"lzhou2"},"change_message_id":"88d215f12fd6d162f2a20a7be413eb9193a4a724","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":3,"id":"088da1d8_360d970f","updated":"2023-05-04 01:30:35.000000000","message":"Ping. \nI\u0027m not sure about what the doc management process is. Will anyone give more review about this? Or will anyone help merge it? Thanks.","commit_id":"bcdff155149dc4dad08f7e19874573e1ed682042"},{"author":{"_account_id":32187,"name":"Juanita-Balaraj","email":"juanita.balaraj@windriver.com","username":"jbalaraj"},"change_message_id":"ad6e8807eab17246211346d9491a30d6ad451864","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":3,"id":"f89af44e_ebdf5476","in_reply_to":"ca77ecd7_a777a06c","updated":"2023-05-15 13:29:15.000000000","message":"@Luis Sampaio, this review will be integrated into Stx. master once the review merges; You can see the output here: https://docs.starlingx.io/security/kubernetes/use-uefi-secure-boot.html and it will be in the Stx 9.0 docs once the branch is cut from stx. master.","commit_id":"bcdff155149dc4dad08f7e19874573e1ed682042"}],"doc/source/security/kubernetes/use-uefi-secure-boot.rst":[{"author":{"_account_id":33394,"name":"Mark Asselstine","email":"mark.asselstine@windriver.com","username":"markawr"},"change_message_id":"499e8ae51457998b801262acbdadcd014a8c122f","unresolved":true,"context_lines":[{"line_number":158,"context_line":"    ``Debian`` build. You may find it helpful in implementing your own signing"},{"line_number":159,"context_line":"    server."},{"line_number":160,"context_line":""},{"line_number":161,"context_line":"    The secure boot verification sequence of StarlingX debian is:"},{"line_number":162,"context_line":"    UEFI firmware verify shim image;"},{"line_number":163,"context_line":"    shim verify grub image;"},{"line_number":164,"context_line":"    grub verify kernel image and initramfs image."}],"source_content_type":"text/x-rst","patch_set":1,"id":"cdedc4d2_84cca83e","line":161,"updated":"2023-04-20 18:37:20.000000000","message":"s/debian/Debian/","commit_id":"498394aa520fdb1656a91216e98dcafcdb9e05f6"},{"author":{"_account_id":32832,"name":"Li Zhou","display_name":"Li Zhou","email":"li.zhou@windriver.com","username":"lzhou2"},"change_message_id":"937197601fec776cf82780fb44aac63dae069350","unresolved":false,"context_lines":[{"line_number":158,"context_line":"    ``Debian`` build. You may find it helpful in implementing your own signing"},{"line_number":159,"context_line":"    server."},{"line_number":160,"context_line":""},{"line_number":161,"context_line":"    The secure boot verification sequence of StarlingX debian is:"},{"line_number":162,"context_line":"    UEFI firmware verify shim image;"},{"line_number":163,"context_line":"    shim verify grub image;"},{"line_number":164,"context_line":"    grub verify kernel image and initramfs image."}],"source_content_type":"text/x-rst","patch_set":1,"id":"c6e2597d_7bd34913","line":161,"in_reply_to":"cdedc4d2_84cca83e","updated":"2023-04-23 08:22:10.000000000","message":"Done","commit_id":"498394aa520fdb1656a91216e98dcafcdb9e05f6"},{"author":{"_account_id":33394,"name":"Mark Asselstine","email":"mark.asselstine@windriver.com","username":"markawr"},"change_message_id":"499e8ae51457998b801262acbdadcd014a8c122f","unresolved":true,"context_lines":[{"line_number":182,"context_line":"    The \"key file\" is the private key generated by \"ssh-keygen -t rsa\""},{"line_number":183,"context_line":"    and used to setup signing server access without password."},{"line_number":184,"context_line":""},{"line_number":185,"context_line":"    The signging script ``sign-secure-boot_debian`` does secure boot signing for"},{"line_number":186,"context_line":"    |prod| Debian in this way:"},{"line_number":187,"context_line":""},{"line_number":188,"context_line":"    .. code-block:: none"}],"source_content_type":"text/x-rst","patch_set":1,"id":"944a19c9_fc502068","line":185,"updated":"2023-04-20 18:37:20.000000000","message":"s/signging /signing/","commit_id":"498394aa520fdb1656a91216e98dcafcdb9e05f6"},{"author":{"_account_id":32832,"name":"Li Zhou","display_name":"Li Zhou","email":"li.zhou@windriver.com","username":"lzhou2"},"change_message_id":"937197601fec776cf82780fb44aac63dae069350","unresolved":false,"context_lines":[{"line_number":182,"context_line":"    The \"key file\" is the private key generated by \"ssh-keygen -t rsa\""},{"line_number":183,"context_line":"    and used to setup signing server access without password."},{"line_number":184,"context_line":""},{"line_number":185,"context_line":"    The signging script ``sign-secure-boot_debian`` does secure boot signing for"},{"line_number":186,"context_line":"    |prod| Debian in this way:"},{"line_number":187,"context_line":""},{"line_number":188,"context_line":"    .. code-block:: none"}],"source_content_type":"text/x-rst","patch_set":1,"id":"c94fa2f8_e49c0c4b","line":185,"in_reply_to":"944a19c9_fc502068","updated":"2023-04-23 08:22:10.000000000","message":"Done","commit_id":"498394aa520fdb1656a91216e98dcafcdb9e05f6"},{"author":{"_account_id":33394,"name":"Mark Asselstine","email":"mark.asselstine@windriver.com","username":"markawr"},"change_message_id":"499e8ae51457998b801262acbdadcd014a8c122f","unresolved":true,"context_lines":[{"line_number":195,"context_line":""},{"line_number":196,"context_line":"        (2) Sign kernel images and LockDown.efi"},{"line_number":197,"context_line":"        The file sign_rootfs-post-scripts is inserted to where the"},{"line_number":198,"context_line":"        hook script \"rootfs-post-scripts\" is defined in the lat config file"},{"line_number":199,"context_line":"        base-bullseye.yaml. This will sign kernel images and LockDown.efi"},{"line_number":200,"context_line":"        on signing server in the lat build process."},{"line_number":201,"context_line":"        The \"rootfs-post-scripts\" is the hook in lat tool running after rootfs"}],"source_content_type":"text/x-rst","patch_set":1,"id":"4ae18d35_b2c72367","line":198,"updated":"2023-04-20 18:37:20.000000000","message":"s/lat/LAT/g","commit_id":"498394aa520fdb1656a91216e98dcafcdb9e05f6"},{"author":{"_account_id":32832,"name":"Li Zhou","display_name":"Li Zhou","email":"li.zhou@windriver.com","username":"lzhou2"},"change_message_id":"937197601fec776cf82780fb44aac63dae069350","unresolved":false,"context_lines":[{"line_number":195,"context_line":""},{"line_number":196,"context_line":"        (2) Sign kernel images and LockDown.efi"},{"line_number":197,"context_line":"        The file sign_rootfs-post-scripts is inserted to where the"},{"line_number":198,"context_line":"        hook script \"rootfs-post-scripts\" is defined in the lat config file"},{"line_number":199,"context_line":"        base-bullseye.yaml. This will sign kernel images and LockDown.efi"},{"line_number":200,"context_line":"        on signing server in the lat build process."},{"line_number":201,"context_line":"        The \"rootfs-post-scripts\" is the hook in lat tool running after rootfs"}],"source_content_type":"text/x-rst","patch_set":1,"id":"76682cc6_06d785e3","line":198,"in_reply_to":"4ae18d35_b2c72367","updated":"2023-04-23 08:22:10.000000000","message":"Done","commit_id":"498394aa520fdb1656a91216e98dcafcdb9e05f6"},{"author":{"_account_id":33394,"name":"Mark Asselstine","email":"mark.asselstine@windriver.com","username":"markawr"},"change_message_id":"499e8ae51457998b801262acbdadcd014a8c122f","unresolved":true,"context_lines":[{"line_number":255,"context_line":""},{"line_number":256,"context_line":"        The keys under cgcs-root/public-keys are the public keys used in"},{"line_number":257,"context_line":"        the verification process of secure boot process for StarlingX"},{"line_number":258,"context_line":"        debian."},{"line_number":259,"context_line":""},{"line_number":260,"context_line":"        Keys Introduction:"},{"line_number":261,"context_line":"        tis-boot.crt: it is the public key flashed into UEFI to verify"}],"source_content_type":"text/x-rst","patch_set":1,"id":"d1644466_4919de4f","line":258,"updated":"2023-04-20 18:37:20.000000000","message":"s/debian/Debian/","commit_id":"498394aa520fdb1656a91216e98dcafcdb9e05f6"},{"author":{"_account_id":32832,"name":"Li Zhou","display_name":"Li Zhou","email":"li.zhou@windriver.com","username":"lzhou2"},"change_message_id":"937197601fec776cf82780fb44aac63dae069350","unresolved":false,"context_lines":[{"line_number":255,"context_line":""},{"line_number":256,"context_line":"        The keys under cgcs-root/public-keys are the public keys used in"},{"line_number":257,"context_line":"        the verification process of secure boot process for StarlingX"},{"line_number":258,"context_line":"        debian."},{"line_number":259,"context_line":""},{"line_number":260,"context_line":"        Keys Introduction:"},{"line_number":261,"context_line":"        tis-boot.crt: it is the public key flashed into UEFI to verify"}],"source_content_type":"text/x-rst","patch_set":1,"id":"b19d6ad0_51d36e81","line":258,"in_reply_to":"d1644466_4919de4f","updated":"2023-04-23 08:22:10.000000000","message":"Done","commit_id":"498394aa520fdb1656a91216e98dcafcdb9e05f6"},{"author":{"_account_id":30539,"name":"Ron Stone","email":"ronald.stone@windriver.com","username":"ronstone2000"},"change_message_id":"c786afaf8e593b29af9da5118855bd4621d76c31","unresolved":true,"context_lines":[{"line_number":151,"context_line":"    ------------------------------------------------------------------------------"},{"line_number":152,"context_line":"    Build considerations for signing packages for UEFI Secure Boot -- Debian build"},{"line_number":153,"context_line":"    ------------------------------------------------------------------------------"},{"line_number":154,"context_line":"    The |prod| build environment has provisions for calling out to a signing"},{"line_number":155,"context_line":"    server for purposes of creating a secure boot load.  At this time |prod|"},{"line_number":156,"context_line":"    does not include an implementation of the signing server.  The following"},{"line_number":157,"context_line":"    describes how the signing process is intended to work in the context of a"}],"source_content_type":"text/x-rst","patch_set":3,"id":"d5b09450_50a50df2","line":154,"updated":"2023-07-11 10:14:55.000000000","message":"Please add a blank line between 153 and 154","commit_id":"bcdff155149dc4dad08f7e19874573e1ed682042"},{"author":{"_account_id":32832,"name":"Li Zhou","display_name":"Li Zhou","email":"li.zhou@windriver.com","username":"lzhou2"},"change_message_id":"db239be580fa5746d6273621fe76ce89cdd75ec4","unresolved":false,"context_lines":[{"line_number":151,"context_line":"    ------------------------------------------------------------------------------"},{"line_number":152,"context_line":"    Build considerations for signing packages for UEFI Secure Boot -- Debian build"},{"line_number":153,"context_line":"    ------------------------------------------------------------------------------"},{"line_number":154,"context_line":"    The |prod| build environment has provisions for calling out to a signing"},{"line_number":155,"context_line":"    server for purposes of creating a secure boot load.  At this time |prod|"},{"line_number":156,"context_line":"    does not include an implementation of the signing server.  The following"},{"line_number":157,"context_line":"    describes how the signing process is intended to work in the context of a"}],"source_content_type":"text/x-rst","patch_set":3,"id":"d88c5230_f499a5f1","line":154,"in_reply_to":"d5b09450_50a50df2","updated":"2023-07-12 02:06:25.000000000","message":"Done","commit_id":"bcdff155149dc4dad08f7e19874573e1ed682042"}]}
