ext_213628 ([identity profile] http://users.livejournal.com/deviant_/) wrote in [personal profile] mjg59 2011-10-19 06:50 pm (UTC)

That's not really necessary. In the vendor-signed case (i.e. installing Fedora), the install media would have this on it, and so the key would be enrolled before the install media is booted. When the installed system reboots, it's still using the same key, so no extra reboot is needed.

In the "I'm building my own software" case, you've already got a chicken-and-egg problem where either a) you've already installed this machine and you're just updating things, or b) you have another machine you're building on. In both cases you can simply sign your new software with your own key and put it on the boot media next to bootx64.efi , and enroll it during the reboot you're planning to do anyway.

Post a comment in response:

If you don't have an account you can create one now.
HTML doesn't work in the subject.
More info about formatting

If you are unable to use this captcha for any reason, please contact us by email at support@dreamwidth.org