Re: [EXTERNAL] Re: F45 Change Proposal: Grub EFI For Confidential Computing (self-contained)
Lennart Poettering <[email protected]>
| Newsgroups | gmane.linux.redhat.fedora.devel |
|---|---|
| Message-ID | <akOrm_ks8wTdA7Sv@gardel-login> |
On Di, 30.06.26 09:43, Zbigniew Jędrzejewski-Szmek ([email protected]) wrote: > This approach has been discussed extensively in the past. The "no more > boot loader" project of the grub team implements something like this. > > It is a flexible and powerful approach, but it does have certain downsides: There are a bunch more issues: - can't kexec windows, i.e. multi-boot stuff is borked with this - no mechanism for passing over userspace tpm event log - unclear regarding authenticating invoked kernels, i.e. one would expect that on kexec the kernel would authenticate the next kernel, and not userspace, but that's not where we are at. Lennart -- Lennart Poettering, Berlin -- _______________________________________________ devel mailing list -- [email protected] To unsubscribe send an email to [email protected] Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/[email protected] Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new