-
Notifications
You must be signed in to change notification settings - Fork 59
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Regular updates for the UEFI revoked signatures database (dbx) #1478
Comments
Copying the comment from @bgilbert in #1452 (comment) here since I think it will be useful for this ticket: At present we're automatically updating neither shim/GRUB nor the dbx denylist. That has some consequences:
|
some passing discussion with @jmflinuxtx I had on this topic:
|
We discussed this in the community meeting today.
|
We discussed this in the community meeting today
|
Ticket to submit a Fedora Change in: #1512 |
In #1452 (comment) we determined that we'd like to explore regular updates to the UEFI revoked signatures database in order to keep our systems at least not booting known bad bootloaders/software.
There are several investigations that would need to take place first and we'd also need to implement #1468 because we can't really update the dbx without having a good policy on keeping the bootloader up to date.
The text was updated successfully, but these errors were encountered: