|
|
Subscribe / Log in / New account

The first "shim" UEFI secure bootloader released

The first "shim" UEFI secure bootloader released

[Development] Posted Dec 3, 2012 16:37 UTC (Mon) by corbet

Matthew Garrett has announced the availability of the first "usable" version of the "shim" UEFI secure bootloader. "If you want, you're then free to impose any level of additional signing restrictions - it's entirely possible to use this signing as the basis of a complete chain of trust, including kernel lockdowns and signed module loading. However, since the end-user has explicitly indicated that they trust your code, you're under no obligation to do so. You should make it clear to your users what level of trust they'll be able to place in their system after installing your key, if only to allow them to make an informed decision about whether they want to or not."

Comments (none posted)


Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds