Witherspoon: Enable PNOR signature verification
Enable signature verification in the openpower-software-manager code
for witherspoon. This causes an error to be logged if updating to
an unsigned image, or image signed with a different key than the one
on the system, and if field mode is set, it'll stop the activation
process.
Tested: PNOR signature verification is enforced on witherspoon,
verified error is logged with and without field mode enabled, and
activation is prevented with field mode enabled.
Change-Id: I6b8b74f146066da058e137779faf9af157f7131b
Signed-off-by: Adriana Kobylak <anoo@us.ibm.com>
diff --git a/meta-witherspoon/recipes-phosphor/flash/openpower-software-manager.bbappend b/meta-witherspoon/recipes-phosphor/flash/openpower-software-manager.bbappend
new file mode 100644
index 0000000..3dcc25d
--- /dev/null
+++ b/meta-witherspoon/recipes-phosphor/flash/openpower-software-manager.bbappend
@@ -0,0 +1 @@
+PACKAGECONFIG_append_df-openpower-ubi-fs = " verify_pnor_signature"