Re: [systemd-devel] Sysext questions

2024-06-07 Thread Itxaka Serrano Garcia
On Thu, Jun 6, 2024 at 6:17 PM Lennart Poettering wrote: > On Mi, 05.06.24 18:28, Itxaka Serrano Garcia ( > [email protected]) wrote: > > > Hello again! > > > > A few sysext questions that have arisen from our testing > > > > - image policy is configurable but it's there a single co

Re: [systemd-devel] Sysext questions

2024-06-07 Thread Itxaka Serrano Garcia
done, thanks! On Thu, Jun 6, 2024 at 6:18 PM Lennart Poettering wrote: > On Do, 06.06.24 16:49, Itxaka Serrano Garcia ( > [email protected]) wrote: > > > Another extra question, trying a extension that is signed, if I dont > > provide the signature in the verity.d dir, the service h

Re: [systemd-devel] Sysext questions

2024-06-06 Thread Lennart Poettering
On Do, 06.06.24 16:49, Itxaka Serrano Garcia ([email protected]) wrote: > Another extra question, trying a extension that is signed, if I dont > provide the signature in the verity.d dir, the service hangs because its > asking for a password. Is it possible to skip that somehow? I do

Re: [systemd-devel] Sysext questions

2024-06-06 Thread Lennart Poettering
On Mi, 05.06.24 18:28, Itxaka Serrano Garcia ([email protected]) wrote: > Hello again! > > A few sysext questions that have arisen from our testing > > - image policy is configurable but it's there a single config file where > we can put that so it's used system wide? For example to

Re: [systemd-devel] Sysext questions

2024-06-06 Thread Itxaka Serrano Garcia
Another extra question, trying a extension that is signed, if I dont provide the signature in the verity.d dir, the service hangs because its asking for a password. Is it possible to skip that somehow? I dont want it to ask for a password, if there is not a key, just fial to load it. Thanks! On W

[systemd-devel] Sysext questions

2024-06-05 Thread Itxaka Serrano Garcia
Hello again! A few sysext questions that have arisen from our testing - image policy is configurable but it's there a single config file where we can put that so it's used system wide? For example to only allow verity+signed? Service override? - I can't see anything preventing a manual call to