Skip to content

Commit

Permalink
security: transfer certificates from intiramfs to root in dracut
Browse files Browse the repository at this point in the history
Resolves: INSTALLER-4089
  • Loading branch information
rvykydal committed Jan 23, 2025
1 parent 6d62247 commit e8033e4
Show file tree
Hide file tree
Showing 3 changed files with 9 additions and 0 deletions.
1 change: 1 addition & 0 deletions dracut/Makefile.am
Original file line number Diff line number Diff line change
Expand Up @@ -37,6 +37,7 @@ dist_dracut_SCRIPTS = module-setup.sh \
anaconda-copy-cmdline.sh \
anaconda-copy-dhclient.sh \
anaconda-copy-prefixdevname.sh \
anaconda-copy-certs.sh
anaconda-ifcfg.sh \
anaconda-set-kernel-hung-timeout.sh \
anaconda-error-reporting.sh \
Expand Down
7 changes: 7 additions & 0 deletions dracut/anaconda-copy-certs.sh
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
#!/bin/sh
# Transfer CA certificates imported in initramfs via kickstart
# to anaconda environment

./lib/anaconda-lib.sh

[ -d /run/install/certificates/path ] && copytree /run/install/certificates/path /sysroot || true
1 change: 1 addition & 0 deletions dracut/module-setup.sh
Original file line number Diff line number Diff line change
Expand Up @@ -50,6 +50,7 @@ install() {
inst_hook pre-pivot 50 "$moddir/anaconda-copy-cmdline.sh"
inst_hook pre-pivot 90 "$moddir/anaconda-copy-dhclient.sh"
inst_hook pre-pivot 91 "$moddir/anaconda-copy-prefixdevname.sh"
inst_hook pre-pivot 92 "$moddir/anaconda-copy-certs.sh"
inst_hook pre-pivot 95 "$moddir/anaconda-set-kernel-hung-timeout.sh"
inst_hook pre-pivot 99 "$moddir/save-initramfs.sh"
inst_hook cleanup 98 "$moddir/anaconda-nfsrepo-cleanup.sh"
Expand Down

0 comments on commit e8033e4

Please sign in to comment.