7 ms·
>Thanks to updates to sbctl, you can create keys with `sbctl create-keys` rather than typing out complex openssl commands. sbctl's `enroll-keys` should also mak
by Foxboron 1y ago
>Thanks to updates to sbctl, you can create keys with `sbctl create-keys` rather than typing out complex openssl commands. sbctl's `enroll-keys` should also make the key enrollment procedure easier.
I mean, reading Rod Smiths post is what originally made me write secure boot tooling many years ago. I didn't understand why it had to be soooo complicated.
If you read the original `efi-roller` project I started out with you'll see it's largely just a wrapper around the stuff in Rod Smiths book, that was later refined by actually implementing a proper library in Go and tooling on top.
https://github.com/Foxboron/efi-roller https://github.com/Foxboron/efi-roller
- jeroenhd 1y agoIt was definitely the most comprehensive article on actually using secure boot at the time it was written, that's for sure. I just don't want people to think that now, a decade later, you still need to mess with shell scripts calling openssl commands to get secure boot to work.