Hello #systemd bubble! Does anyone know why `ukify genkey` generates a signing key/cert pair (AFAICT that corresponds to the #EFI #SecureBoot DB Key/Cert), and even references sd-boot's ability to enroll them, but sd-boot requires .auth files for KEK, PK and DB (I mean, it can't just invent them :'-D)?
So, the only way to do that is to either manually generate KEK, PK and then sign them with the DB key and generate the .auth files, or to let a tool like #sbctl or whatever generate them and try to feed those into ukify (which internally uses #sbsigntool). But both seem to be a bit more of a hassle than needed?
#systemd #EFI #SecureBoot #sbctl #sbsigntool #uefi
Dual boot Ubuntu and Windows 11 on my organization managed school laptop #dualboot #secureboot
Can't enter BIOS on ACER laptop #boot #lubuntu #bios #secureboot
#boot #lubuntu #BIOS #SecureBoot
Error "shim_lock protocol not found" in GRUB while secure boot is enabled #dualboot #grub2 #uefi #secureboot #mint
#dualboot #grub2 #uefi #SecureBoot #mint
Ubuntu secure boot installation problems #boot #drivers #systeminstallation #uefi #secureboot
#boot #drivers #systeminstallation #uefi #SecureBoot
Your average Operating System gets a lot of quality engineering time (code review, testing etc).
You know what gets none of that? Firmware aka BIOS. Cheapest bidder wins garbage dumpster fire untested code.
All that fancy #SecureBoot and #TPM and stuff? All bullshit. Nobody reviewed that code, nor tested that it actually works.
How to setup secure boot on customized Ubuntu Server ISO? #server #2004 #automation #secureboot #preseed
#server #automation #SecureBoot #preseed
firmware question during install + no wifi #wireless #secureboot #firmware
#wireless #SecureBoot #firmware
PXE and UEFI SecureBoot #grub2 #uefi #secureboot #pxe #tftp
#grub2 #uefi #SecureBoot #pxe #tftp
Apparmor full system implementation help #1804 #security #secureboot #apparmor
#security #SecureBoot #apparmor
How to install Virtualbox with signed kernel modules #softwareinstallation #kernel #virtualbox #uefi #secureboot
#softwareinstallation #kernel #virtualbox #uefi #SecureBoot
Issue with secure boot and official kernel 5.15.0-56 #boot #kernel #secureboot
Ubuntu's dkms v3.0.6 breaks drivers with enabled SecureBoot #drivers #apt #2210 #secureboot #dkms
#drivers #apt #SecureBoot #dkms
Unable to Download Latest Version of DBX #updates #downloads #secureboot
#Updates #downloads #SecureBoot
It seems that #Windows #Update #KB5012170 updates the #SecureBoot DBX database to exclude some exploits. Unfortunately this may fail with 0x800f0992 on installation with incompatible firmwares. OVMF_CODE.secboot.fd for #QEMU/#KVM/#libvirt seems to be just that. Switch to the 4M-version of the firmware which has 4 Megabytes allocated instead of 2M to fix this.
#windows #update #kb5012170 #SecureBoot #qemu
Ars Technica: 300+ models of MSI motherboards have Secure Boot turned off. Is yours affected? https://arstechnica.com/?p=1911594 #Tech #arstechnica #IT #Technology #Motherboards #secureboot #Biz&IT #BIOS #uefi #msi
#Tech #arstechnica #it #technology #motherboards #SecureBoot #biz #bios #UEFI #msi
A flaw in some Acer laptops can be used to bypass security features https://securityaffairs.co/wordpress/139055/hacking/acer-flaw-uefi-secure-boot.html #informationsecuritynews #ITInformationSecurity #PierluigiPaganini #SecurityAffairs #BreakingNews #SecurityNews #hackingnews #SecureBoot #Security #Hacking #Acer #UEFI
#informationsecuritynews #ITInformationSecurity #PierluigiPaganini #SecurityAffairs #BreakingNews #SecurityNews #hackingnews #SecureBoot #Security #Hacking #Acer #UEFI