The trust chain

Secure Boot: the Platform Key owns the firmware and authorizes the KEK; the KEK authorizes the signature database (db). db holds cairn's UKI signing certificate alongside the Microsoft and Windows vendor CAs, kept so 2011-chained option ROMs still load. The cairn cert is the one that signs what actually runs: systemd-boot, every unified kernel image, and the ZFS/NVIDIA kernel modules baked into the images.

Measured boot: each UKI carries a TPM PCR11 policy signed by the PCR11 policy key, so TPM2 unsealing extends only to kernels the estate signed. Images: where a repo turns on signing (sign_on_promote), the promoted digest is signed by the cosign key. That is own-key signing with no transparency log, so these fingerprints are the only anchor there is.

The same anchors live in the public repo under keys/, and the machine-readable list is fingerprints.txt. Those are two independent out-of-band paths to the same values, and the table below is parsed from that same file at build time: the build fails if the published copies drift from the canonical anchors, or if the file and this page disagree on even one entry. No private half appears in this repo: PK and KEK stay in offline escrow, and the three signing keys exist only as masked, protected CI variables (the trust chain).

Fingerprints

PK · Platform Key

CN=cairn Platform Key, O=cairn.dunn.dev

sha-256 fingerprint

B2:23:AE:9A:5A:7F:C8:5A36:ED:17:85:9F:ED:BD:E82F:45:E5:9F:80:37:DB:C332:91:68:9B:82:4B:7D:87

Firmware ownership root. Enrolled as the UEFI Platform Key; the only key that authorizes changes to the KEK.

RSA-4096 · X.509 (PEM) · valid 2026-07-18 → 2076-07-17

download PK.crt

openssl x509 -in PK.crt -noout -subject -fingerprint -sha256

KEK · Key Exchange Key

CN=cairn Key Exchange Key, O=cairn.dunn.dev

sha-256 fingerprint

D4:E9:03:DA:CE:06:F3:D042:01:CA:B2:2C:74:18:FFC9:8A:56:EE:03:CC:A6:92F4:83:15:49:6C:94:20:9B

Authorizes updates to the Secure Boot signature databases (db/dbx). Signed into the hierarchy under the PK.

RSA-4096 · X.509 (PEM) · valid 2026-07-18 → 2076-07-17

download KEK.crt

openssl x509 -in KEK.crt -noout -subject -fingerprint -sha256

UKI · UKI signing certificate

CN=cairn UKI signing, O=cairn.dunn.dev

sha-256 fingerprint

A4:19:A8:25:C8:78:52:43C2:1F:23:74:C1:8B:49:8E4E:51:59:B4:83:2E:5B:ED3C:EF:46:88:A4:1E:F4:C6

db member. Signs systemd-boot, every unified kernel image (UKI) the estate promotes, and the out-of-tree ZFS/NVIDIA kernel modules baked into the images.

RSA-4096 · X.509 (PEM) · valid 2026-07-18 → 2076-07-17

download UKI.crt

openssl x509 -in UKI.crt -noout -subject -fingerprint -sha256

pcr11 · PCR11 policy public key

RSA public key (no certificate)

sha-256 fingerprint

0f0dbb4eecba169e5c036c4b45707a3371bece1f7f1795fdec6e9e1327aabe4f

Verifies the signed TPM PCR11 policy each UKI carries (systemd-measure); TPM2 unsealing trusts UKIs it vouches for.

RSA-3072 · SPKI (PEM) · fingerprint = SHA-256 of the DER-encoded key

download pcr11.pub.pem

openssl pkey -pubin -in pcr11.pub.pem -outform DER | sha256sum

cosign · Image signing public key

ECDSA public key (no certificate)

sha-256 fingerprint

03bd99155ffaa044a97f2c6b2cff56aae83195df65f83a58abab5eda404d7ef7

Verifies the cosign signature on estate-signed image digests (opt-in sign_on_promote at promotion).

ECDSA P-256 · PEM · fingerprint = SHA-256 of the key file itself

download cosign.pub

sha256sum cosign.pub

Verify a promoted image

To check the cosign signature on a signed digest, use the published key. The estate signs with its own key rather than a keyless transparency-log identity, so the tlog check is turned off. Trust comes from this fingerprint instead, fetched out-of-band:

cosign verify --key cosign.pub --insecure-ignore-tlog=true <image>@<digest>

On a running cairn host, confirm a kernel module was signed by the estate's UKI key:

modinfo -F signer zfs   # → cairn UKI signing

Everything at once

Every anchor is published verbatim at a stable URL under /keys/: PK.crt · KEK.crt · UKI.crt · pcr11.pub.pem · cosign.pub · fingerprints.txt · README.md