lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Date:	Wed, 10 Jul 2013 19:22:23 -0500
From:	Sherry Hurwitz <sherry.hurwitz@....com>
To:	Ben Hutchings <ben@...adent.org.uk>
CC:	David Woodhouse <dwmw2@...radead.org>,
	<linux-kernel@...r.kernel.org>, <amd64-microcode@...64.org>,
	<suravee.suthikulpanit@....com>
Subject: Re: [PATCH 1/1] linux-firmware: Add AMD microcode patch firmware
 files

On 07/03/2013 09:56 PM, Ben Hutchings wrote:
> On Fri, 2013-06-28 at 14:27 -0500, Sherry Hurwitz wrote:
>> For AMD Families 10h ~ 14h Processors
>> file:   amd-ucode/microcode_amd.bin
>> md5sum: 55ae79b82cbfddcf7142058be3c9ec2d
>>
>> For AMD Family 15h Processors
>> file:   amd-ucode/microcode_amd_fam15h.bin
>> md5sum: 122ac7e56442c2b7c28eb26978b2d57c
>>
>> Signed-off-by: Sherry Hurwitz<sherry.hurwitz@....com>
>> ---
>>   LICENSE.amd-ucode                  |   64 ++++++++++++++++++++++++++++++++++++
>>   WHENCE                             |    9 +++++
>>   amd-ucode/microcode_amd.bin        |  Bin 0 -> 12684 bytes
>>   amd-ucode/microcode_amd_fam15h.bin |  Bin 0 -> 7876 bytes
>>   4 files changed, 73 insertions(+)
>>   create mode 100644 LICENSE.amd-ucode
>>   create mode 100644 amd-ucode/microcode_amd.bin
>>   create mode 100644 amd-ucode/microcode_amd_fam15h.bin
> [...]
>> --- a/WHENCE
>> +++ b/WHENCE
>> @@ -2169,3 +2169,12 @@ File: go7007/wis-startrek.fw
>>   Licence: Redistributable. See LICENCE.go7007_firmware for details
>>   
>>   --------------------------------------------------------------------------
>> +
>> +Driver: microcode_amd - AMD CPU Microcode Update Driver for Linux
>> +
>> +File: amd-ucode/microcode_amd.bin
>> +File: amd-ucode/microcode_amd_fam15h.bin
>> +
>> +License: Redistributable. See LICENSE.amd-ucode for details
> [...]
>
> Please include the version number.
>
> I notice that the download page on amd64.org also has GPG signatures.
> Perhaps those should be included too?
>
> (Actually, I would like to see verifiable signatures on all binary
> firmware, but I don't think that can be made a requirement any time
> soon.  Key 9F94BC90 isn't signed by another published key, so I still
> have no reason to trust its identity.)
>
> Ben.
>
The amd64.org site is down and will no longer be used for distributing 
AMD microcode patches.  Therefore, the Key ID 9F94BC90 will no longer be 
used to sign the future microcode container files.  A new key will be 
created and signed by me and another AMD co-worker.  We will resend the 
patch with  the Key ID 8C0108B4.  You can pull this key from the gnuPG 
key server to verify and see it is signed by two other keys, one 
belonging to me and the other by Suravee Suthikulpanit, with AMD email 
addresses.

Sherry


--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@...r.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ