Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
[manuf] only verify X.509 DICE chain with openssl
DICE certs can be generated in X.509 or CWT format during perso. OpenSSL can only verify X.509 cert chains. This updates the perso flow to only check if the DICE cert chain verifies successfully if the certs are X.509 format until a new tool (`hwtrust`) can be used to validate the CWT chain. Signed-off-by: Tim Trippel <[email protected]>
- Loading branch information