Open hramrach opened 2 years ago
Why is this?
The key is enrolled with shim, not kernel.
The key built into kernel has nothing to do with keys recognized by shim.
Not enrolling the kernel key makes kernel unbootable for typical distribution kernels that are signed with a key that's also built into the kernel.
@joeyli
This is related to https://bugzilla.suse.com/show_bug.cgi?id=1173115
Why is this?
The key is enrolled with shim, not kernel.
The key built into kernel has nothing to do with keys recognized by shim.
Not enrolling the kernel key makes kernel unbootable for typical distribution kernels that are signed with a key that's also built into the kernel.