privacyguides / privacyguides.org

Protect your data against global mass surveillance programs.
https://www.privacyguides.org
Creative Commons Attribution Share Alike 4.0 International
2.82k stars 208 forks source link

Elaborate Secure boot article #1853

Open dngray opened 2 years ago

dngray commented 2 years ago

Description

URL of affected page: https://www.privacyguides.org/linux-desktop/hardening/#secure-boot

We should probably elaborate there a little on Dynamic Kernel Module Support (DKMS) and Akmods and how to sign them.

These come up when using virtualization software, NVIDIA drivers etc.

While it's not great to sign kernel modules blindly, it's better than disabling secure boot.

The alternative is to use the shim and Machine Owner Key (MOK).

dngray commented 2 years ago

Another thing that I wouldn't mind mentioning here is the use of sbctl. It makes managing secure boot with your own keys so much easier. Currently available on a variety of distributions.

I've been working on packaging this for Fedora. I have used it successfully on Archlinux that it works successfully.

dngray commented 3 months ago

These come up when using virtualization software, NVIDIA drivers etc.

https://www.phoronix.com/news/Fedora-NVIDIA-Secure-Boot