3 ms·
> If you have a signed Grub EFI loader, remove the default secure boot keys and add in just the CA/certs for your system and password your BIOS/setup, you have
by Leace 7y ago
> If you have a signed Grub EFI loader, remove the default secure boot keys and add in just the CA/certs for your system and password your BIOS/setup, you have the potential for a very secure system (ignoring the Intel/AMD management systems that are difficult or impossible to disable).
Or just dump Grub altogether and boot kernel directly as an UEFI image. No need for middle-man!
(Instructions vary by distro but see this for example: https://wiki.gentoo.org/wiki/EFI_stub_kernel https://wiki.gentoo.org/wiki/EFI_stub_kernel)
- e12e 7y agoBut then you're loading the kernel from unencrypted fat32 partition?
- Leace 7y agoIf it's signed with Secure Boot keys it's no different for loading signed Grub image. Grub would also need to be unencrypted to work. As for signing kernel: https://github.com/andreyv/sbupdate https://github.com/andreyv/sbupdate