Profile
Matthew Garrett
About Matthew
Active Entries
- 1: Playing with Thunderbolt under Linux on Apple hardware
- 2: A short introduction to TPMs
- 3: More in the series of bizarre UEFI bugs
- 4: Samsung laptop bug is not Linux specific
- 5: Rebooting
- 6: Update on leaked UEFI signing keys - probably no significant risk
- 7: Leaked UEFI signing keys
- 8: Secure Boot and Restricted Boot.
- 9: The current state of UEFI and Linux
- 10: Using pstore to debug awkward kernel crashes
Expand Cut Tags
No cut tags
Re: Is there any way for the end-user to load their own keys?
Date: 2011-09-25 10:25 am (UTC)If you want the issuance of countersigned keys to be viable in practice, there needs to be provision in the spec for the signed key update request to be limited in scope - say to a particular motherboard serial number and/or date range.