4 ms·
No. But on essentially all existing UEFI systems you can trivially overwrite the "db" keystore in flash and install anything you please. Also most (all?) UEFI
by kukrimate 2y ago
No.
But on essentially all existing UEFI systems you can trivially overwrite the "db" keystore in flash and install anything you please.
Also most (all?) UEFI systems are not locked to Windows and allow customizing the keystore via the firmware console interface anyhow.
- Foxboron 2y ago> Also most (all?) UEFI systems are not locked to Windows and allow customizing the keystore via the firmware console interface anyhow. All of them. The Secured Core machines still allows you to reset Secure Boot into user mode as mandated by the spec.
- josephcsible 2y agoIsn't this only true of x86 ones, not ARM ones?
- Foxboron 2y agoIf ARM implements the UEFI specification then there are escape hatches to enroll your own PKI. I don't own ARM machines with UEFI so I have no clue.