Re: Secure boot

Pau Garcia i Quiles <[email protected]>
Newsgroups gmane.comp.kde.events
Message-ID <CAKcBokt+8=OGZEsXeb5TTNsAEMnzeO3GEGAs1a5opQq105sQUQ@mail.gmail.com>
Hi,

IMHO this is not Microsoft's fault.

The UEFI secure boot standard should have defined an organization (a "Secure
Boot Certification Authority") that would issue and/or receive certificates
from organizations/companies (Red Hat, Oracle, Ubuntu, Microsoft, Apple,
etc) that want their binaries signed. This SBCA would also be in charge of
verifying the background of those organizations. There is actually no need
for a new organization: just use an existing one, such as Verisign, that
carries on with this task for Microsoft for kernel-level binaries
("AuthentiCode").

Given that there is no Secure Boot Certification Authority, Microsoft asked
BIOS (UEFI) developers and manufacturers to include their certificates,
which looks 100% logical to me. The fact that Linux distributions do not
have such power is unfortunate, but it is not Microsoft's fault.

Now: solutions? Given its strong ties with Intel, AMD and others, maybe The
Linux Foundation could start a task force and a "Temporary Secure Boot
Certification Authority", and act as a proxy for minorities such as Linux,
BSD, etc distributions. IMHO this is our best chance to get something done
in a reasonable amount of time. Complaining will not get us anything. We
need to propose solutions.



On Thu, Oct 20, 2011 at 3:09 PM, Agustin <[email protected]> wrote:

> Hi,
>
> I've received the last few days several mails related with Microsoft
> strategy to deliver secure boot implemented in a way that adds restrictions
> for installing free software based distros.
>
> Is this being discussed in Kde? Where?
>
>
-- 
Pau Garcia i Quiles
http://www.elpauer.org
(Due to my workload, I may need 10 days to answer)


_______________________________________________
This message is from the kde-promo mailing list.

Visit https://mail.kde.org/mailman/listinfo/kde-promo to unsubscribe, set digest on or temporarily stop your subscription.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.