Re: [EXTERNAL] Re: F45 Change Proposal: Grub EFI For Confidential Computing (self-contained)

Lennart Poettering <[email protected]>
Newsgroups gmane.linux.redhat.fedora.devel
Message-ID <akOrm_ks8wTdA7Sv@gardel-login>
On Di, 30.06.26 09:43, Zbigniew Jędrzejewski-Szmek ([email protected]) wrote:

> This approach has been discussed extensively in the past. The "no more
> boot loader" project of the grub team implements something like this.
>
> It is a flexible and powerful approach, but it does have certain downsides:

There are a bunch more issues:

- can't kexec windows, i.e. multi-boot stuff is borked with this

- no mechanism for passing over userspace tpm event log

- unclear regarding authenticating invoked kernels, i.e. one would
  expect that on kexec the kernel would authenticate the next kernel,
  and not userspace, but that's not where we are at.

Lennart

--
Lennart Poettering, Berlin
-- 
_______________________________________________
devel mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/[email protected]
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.