Re: [GIT PULL] Load keys from signed PE binaries

From: Matthew Garrett
Date: Fri Mar 01 2013 - 13:22:07 EST


On Wed, Feb 27, 2013 at 08:35:45PM +0000, ownssh wrote:
> Matthew Garrett <mjg59 <at> srcf.ucam.org> writes:
>
> > There's no way to update the UEFI key database without the update being
> > signed by an already trusted key, so what you're proposing isn't
> > possible.
> >
>
> I confused.
> Isn't custom mode can add user's own key?

Yes, but that involves physically-present end-user interaction. A
bootloader can't do it even if it's signed by Microsoft.

--
Matthew Garrett | mjg59@xxxxxxxxxxxxx
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/