Re: signing custom kernel for secure boot

Malte Gell <[email protected]> Fri, 31 Mar 2017 01:12:34 +0200
Newsgroups gmane.linux.suse.security
Message-ID <[email protected]>
Am 30.03.2017 um 15:48 schrieb [email protected]:
> On Wed, Mar 29, 2017 at 09:19:42PM +0200, Malte Gell wrote:
>> And, do I understand correctly, MokManager.efi is signed with the
>> Microsoft KEK and writes my user key into the UEFI db key store? Thus,
>> MokManager.efi is a way to get user keys into UEFI db?
> 
> yes, with MokManager you can enroll your own keys

Oh, is MokManager able to enroll new PK and KEK keys?
That would be awesome, some mainboards have no EFI GUI for doing that
and my Asrock only has a broken test PK..... :-(


thanks
Malte


-- 
To unsubscribe, e-mail: [email protected]
To contact the owner, e-mail: [email protected]