LWN.net Logo

Custom key management

Custom key management

Posted Jun 6, 2012 6:12 UTC (Wed) by DavidS (subscriber, #84675)
In reply to: Fedora, secure boot, and an insecure future by ajb
Parent article: Fedora, secure boot, and an insecure future

Yes, it'd be great to have a firmware that would allow easy key mgmt, removing all existing keys and uploading a local key. Judging from the amount of customization one gets from the big-iron shops when purchasing enough, I presume it'll be possible to get a boat-load of PCs with pre-loaded keys.

Running an "independent" certification authority on the other side will make about 99$ difference to using the Microsoft key. Except for the additional cost this "Foundation" has to shoulder to keep their own key safe.

1 Windows updates on dual-boot machines would still *need* to black-list compromised linux certificates
2 Getting the key onto machines would still be a pain
3 The machines would still not allow to run arbitrary code under secure boot
4 The machines would still be vulnerable to 0-day windows exploits

But maybe cacert.org would be interested?


(Log in to post comments)

Custom key management

Posted Jun 11, 2012 12:14 UTC (Mon) by nix (subscriber, #2304) [Link]

removing all existing keys and uploading a local key
That sounds like you think that uploading a local key should require removal of the existing ones. Thanks, but no thanks: being able to boot from distro-provided rescue CDs is sometimes very useful!

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds