Garrett: Why UEFI secure boot is difficult for Linux
Posted Jan 19, 2012 3:06 UTC (Thu) by laptop006 (subscriber, #60779)
[Link]
What about mechanisms? Can a Windows update silently blacklist keys? (Or even add a new one?)
Garrett: Why UEFI secure boot is difficult for Linux
Posted Jan 19, 2012 3:12 UTC (Thu) by mjg59 (subscriber, #23239)
[Link]
Keys can be added to the whitelist or the blacklist by updating the DB or DBX variables. Doing that requires that the update be signed by a valid KEK. Windows 8 logo machines will have a Microsoft key in KEK, so Windows Update can certainly add keys to either.