Poettering: Brave new trusted boot world
Poettering: Brave new trusted boot world
Posted Oct 3, 2023 19:13 UTC (Tue) by kreijack (guest, #43513)In reply to: Poettering: Brave new trusted boot world by mjg59
Parent article: Poettering: Brave new trusted boot world
You should remove all the keys (even the Microsoft key ) from the uefi-bios except the one that allow your shim to work, otherwise anything that was signed with (e.g.) Microsoft key may break the protection...
From the points above it seems to me that the PCR11 signature of an UKI file, is secure only in a strongly constrained environment, i.e. where it is possible to be sure that all 'bootloader chain' is secure. This is not impossible, but it is less practical than seemed in the beginning.
