|
|
Subscribe / Log in / New account

Why?

Why?

Posted Jul 17, 2025 4:57 UTC (Thu) by kraxel (subscriber, #49444)
In reply to: Why? by NYKevin
Parent article: Linux and Secure Boot certificate expiration

In firmware context the problem is that there is no time source available (other than the cmos real time clock which can be changed easily). So, yes, expiring certificates doesn't make much sense in this specific case. You can't create x509 certificates without expiry date though, so the firmware goes turn off time checks instead.


to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds