Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Any signature on a UKI is only relevant if you have secure boot enabled, and if you have secure boot enabled using the generally trusted keys then you're already not able to boot unsigned kernels. If you want to run arbitrary kernels then either use keys under your control (which UKIs support) or turn off secure boot - UKIs change absolutely nothing here.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: