gdamjan / secure-boot

UEFI SecureBoot for ArchLinux
58 stars 3 forks source link

Protect signing keys #1

Open gdamjan opened 8 years ago

gdamjan commented 8 years ago

The keys in /etc/secure-boot/*.key should be protected, maybe moved on an automount usb or protected with a passphrase. For the second option that would interfere with automatically running the post-install hook in pacman.