Overview
Support for UEFI Secure Boot with signed bootloaders and kernels.
Requirements
- Signed shim bootloader
- Signed GRUB
- MOK (Machine Owner Key) management
- Certificate enrollment workflow
- Signed kernel images
Workflow
- Enroll PureBoot certificate in MOK
- Chain: shim → signed GRUB → signed kernel
- Verify signatures at each stage
Technical Details
- sbsign for signing binaries
- mokutil for key management
- Certificate generation and storage
- Key rotation procedures
Priority
LOW - Enterprise security feature
Related
Overview
Support for UEFI Secure Boot with signed bootloaders and kernels.
Requirements
Workflow
Technical Details
Priority
LOW - Enterprise security feature
Related