Where are Canonical's secure boot certificates?
Where can I find copies of the certificates used by Canonical's secure boot setup? I want to roll my own PK, KEK, and db lists and need the certificates in PEM or DER form.
There appeared to be links on this page (https:/
Specifically, I am looking for the two certificates in the following chain on the bootloader:
% sudo sbverify --list /boot/efi/
signature 1
image signature issuers:
- /C=GB/ST=Isle of Man/L=Douglas/
image signature certificates:
- subject: /C=GB/ST=Isle of Man/O=Canonical Ltd./OU=Secure Boot/CN=Canonical Ltd. Secure Boot Signing (2017)
issuer: /C=GB/ST=Isle of Man/L=Douglas/
Question information
- Language:
- English Edit question
- Status:
- Answered
- For:
- Ubuntu Edit question
- Assignee:
- No assignee Edit question
- Last query:
- Last reply:
Can you help with this problem?
Provide an answer of your own, or ask James Wilson for more information if necessary.