privacyguides / privacyguides.org

Protect your data against global mass surveillance programs.
https://www.privacyguides.org
Creative Commons Attribution Share Alike 4.0 International
2.69k stars 206 forks source link

Elaborate Secure boot article #1853

Open dngray opened 1 year ago

dngray commented 1 year ago

Description

URL of affected page: https://www.privacyguides.org/linux-desktop/hardening/#secure-boot

We should probably elaborate there a little on Dynamic Kernel Module Support (DKMS) and Akmods and how to sign them.

These come up when using virtualization software, NVIDIA drivers etc.

While it's not great to sign kernel modules blindly, it's better than disabling secure boot.

The alternative is to use the shim and Machine Owner Key (MOK).

dngray commented 1 year ago

Another thing that I wouldn't mind mentioning here is the use of sbctl. It makes managing secure boot with your own keys so much easier. Currently available on a variety of distributions.

I've been working on packaging this for Fedora. I have used it successfully on Archlinux that it works successfully.

dngray commented 1 month ago

These come up when using virtualization software, NVIDIA drivers etc.

https://www.phoronix.com/news/Fedora-NVIDIA-Secure-Boot