Leonard/Janis aka ljĀ·rk · @ljrk
620 followers · 20767 posts · Server todon.eu

Hello bubble! Does anyone know why `ukify genkey` generates a signing key/cert pair (AFAICT that corresponds to the DB Key/Cert), and even references sd-boot's ability to enroll them, but sd-boot requires .auth files for KEK, PK and DB (I mean, it can't just invent them :'-D)?

So, the only way to do that is to either manually generate KEK, PK and then sign them with the DB key and generate the .auth files, or to let a tool like or whatever generate them and try to feed those into ukify (which internally uses ). But both seem to be a bit more of a hassle than needed?

#systemd #EFI #SecureBoot #sbctl #sbsigntool #uefi

Last updated 2 years ago