Disabling fake signing of firmware images

Paul Spooren mail at aparcar.org
Tue Jul 21 02:07:42 PDT 2026


Hi again,

Well good news, I added this via a new config option[1] and as a result, the armsr/armv8 firmware images are now fully reproducible!

Best,
Paul

[1]: https://github.com/openwrt/openwrt/pull/24291

> On 18. Jul 2026, at 10:47, Paul Spooren <mail at aparcar.org> wrote:
> 
> Hi, I’m trying to make our firmware reproducible and found another issue, we sign our firmware with a fake key[1]
> 
> I’d like to disable this entirely. We never signed the firmware properly and adding this fake signature adds nothing, checking the git logs, this was due to an entanglement between signing packages and firmware.
> 
> Are there any strong opinions against this change or is anyone working on proper image signing? In that case, I’d have to modify the rebuild script to strip attached signatures.
> 
> Best,
> Paul
> 
> [1]: https://git.openwrt.org/buildbot/tree/phase1/master.cfg#n1063.





More information about the openwrt-devel mailing list