Matthew, what does secure boot mean for source-based distributions like Gentoo? I understand that, if this scheme does not turn out to be gruesome, Red Hat, Canonical, etc. could get their keys to OEMs. What about the case where every user's kernel and bootloader is different? It seems the only option here is to allow users insert their own keys, which might be a real pain if one has to recompile these components very often.
Source based distro's?