Why?
Why?
Posted Jul 17, 2025 4:57 UTC (Thu) by kraxel (subscriber, #49444)In reply to: Why? by NYKevin
Parent article: Linux and Secure Boot certificate expiration
In firmware context the problem is that there is no time source available (other than the cmos real time clock which can be changed easily). So, yes, expiring certificates doesn't make much sense in this specific case. You can't create x509 certificates without expiry date though, so the firmware goes turn off time checks instead.
