One interesting point in the discussion of UEFI secure boot: it appears there is no way to boot OSes other than Mac OS and Windows without disabling secure boot entirely.
Aren't there various linux bootloader shims signed by the MS key to workaround exactly this sort of regressive thinking ?
NOTE: There is currently no trust provided for the the Microsoft Corporation UEFI CA 2011, which would allow verification of code signed by Microsoft partners. This UEFI CA is commonly used to verify the authenticity of bootloaders for other operating systems such as Linux variants.
Thank god - you wouldn't want that enabled by default.
Some people might want secure boot with their own certs to work with Linux, but I don't see the gain in security if you are using a generic boot loader.
Comments
Aren't there various linux bootloader shims signed by the MS key to workaround exactly this sort of regressive thinking ?
Thank god - you wouldn't want that enabled by default.
Some people might want secure boot with their own certs to work with Linux, but I don't see the gain in security if you are using a generic boot loader.