Vendor-specificity of KEK
Vendor-specificity of KEK
Posted Jul 19, 2025 20:12 UTC (Sat) by raven667 (subscriber, #5198)In reply to: Vendor-specificity of KEK by linuxtardis
Parent article: Linux and Secure Boot certificate expiration
And at the time they didn't have a use case for using SecureBoot for virtualization guests but now that is something which is used to help validate the kernel booted cleanly even for servers, it's not trying to protect against the hypervisor vendor which owns the underlying hardware anyway, but still trying to keep malware from modifying the server OS in ways that aren't detectable.
Posted Jul 19, 2025 20:31 UTC (Sat)
by linuxtardis (guest, #178362)
[Link]
Vendor-specificity of KEK