3 ms·
For the 99% use-case, secure boot being enabled and enforcing by default shouldn't really be an issue in the last few years. Almost all major Linux distributio
by g_p 4y ago
For the 99% use-case, secure boot being enabled and enforcing by default shouldn't really be an issue in the last few years.
Almost all major Linux distributions (i.e. the ones with an easy install disc image you write to a USB stick) use a signed bootloader, and shim or mok or another way to validate the boot chain - the installer will boot fine, and after install, the OS will boot fine, under secure boot.
Windows since 8.0 (?) has also shipped signed - installer and resulting install will both work.
Unless you're dealing with an edge case (i.e. you want to install a non-secure boot capable Linux OS, or BSD or something less common, which isn't using a signed loader), an end user should never really encounter secure boot issues in theory. That's not to say there shouldn't be an "off" switch; but that these days there are very few scenarios where an end user doing their own OS install will hit a secure boot failure.
- jabbany 4y agoHaving to handle 1 customer support ticket for every 100 board sales seems like an extremely serious problem well worth supporting! The failure rate of motherboards is only ~3%, imagine adding an extra 1% on top... (I know you're trying to make a point with the 1%, but _any_ reduction in support tickets by adjusting the secure boot default (which is essentially free) is going to be worth it to the manufacturer. )