rhboot / shim

UEFI shim loader
Other
848 stars 290 forks source link

SBAT Policy latest should be a one-shot #481

Closed jsetje closed 2 years ago

jsetje commented 2 years ago

Since booting from removable media can be hard to detect, setting a persistent latest SBAT policy is risky in a typical client system. This changes latest to be a one-shot operation that could be set at the time of an OS update if desired.

vathpela commented 2 years ago

I've pushed the fix as https://github.com/rhboot/shim/commit/77144e5a404df89b45941bfc54fd2f59e0ee607b