Re: [RFC] Second attempt at kernel secure boot support

From: Alan Cox
Date: Tue Nov 06 2012 - 17:44:19 EST


On Tue, 06 Nov 2012 16:55:25 -0500
Matthew Garrett <mjg59@xxxxxxxxxxxxx> wrote:

> I'm not sure why you think that Fedora PXE installs will automatically wipe disks - they'll do whatever Kickstart tells them to do. The only thing relevant to secure boot here is that you need a signed bootloader, just like when you book off CD.

They'll do whatever the kickstart file says - which means for any
untrusted distribution path like PXE your kickstart file had better be
signed too
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/