Poettering: Brave new trusted boot world
Poettering: Brave new trusted boot world
Posted Nov 2, 2022 17:33 UTC (Wed) by farnz (subscriber, #17727)In reply to: Poettering: Brave new trusted boot world by luto
Parent article: Poettering: Brave new trusted boot world
It doesn't require a custom Secure Boot setup, but it does require a firmware password (at least on my laptop) to stop you just turning Secure Boot off. On my setup, if there's a firmware password, then there are only two ways to boot something other than the default option:
- Enter the firmware password.
- Log into the running system as root (or equivalent unconstrained superuser), and change the BootNext UEFI variable.
Both of these need credentials - but if I have system owner credentials, it's game over already.
