Posted Sep 13, 2012 21:00 UTC (Thu) by iabervon (subscriber, #722)
In reply to: LSS: Secure Boot by mjg59
Parent article: LSS: Secure Boot
You wouldn't accidentally enroll a key, but Microsoft might not like what you signed and were able to boot using a key you'd enrolled. The existence of a shim like this means that it will be possible to use Windows versions on Secure Boot hardware after Microsoft wants to EOL them. From the point of view of the CA evaluating the trustworthiness of the shim, there's not really any difference between a user signing a kexec-enabled kernel and using it to run Windows XP and a user signing Windows XP and booting it from the shim.