Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> Other operating system vendors are free to arrange with hardware manufacturers to include certificates for their operating systems. It's not an antitrust issue that other OS vendors were not able to get their act together in order to do so.

For a lot of users, merely having the option of signing their images simply won't be good enough. Unless the signing keys are available to everyone, you cannot boot a self-compiled kernel on a secure boot system.



If you want to compile your own kernels and boot them without disabling Secure Boot, make your own self-signed certificate, add that to the certificate list the firmware maintains, and self-sign your kernel with your certificate.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: