tateru / tateru-pba

Pre-boot authentication image for TCG SSC OPAL 2.0 with TPM 2.0 and EFI support
4 stars 0 forks source link

Secure Boot #2

Open bluecmd opened 3 years ago

bluecmd commented 3 years ago

Figure out a story for Secure Boot

There is a branch for experiments using it right now.

bluecmd commented 3 years ago

Mokutil seems to be an answer to how people self-sign kernels, and it appears to store its state in EFI variables. That is good for us as we could offer a quite simple enrollment through an installer script.