logoalt Hacker News

invokestaticyesterday at 6:26 PM1 replyview on HN

No, this is not true at all. Microsoft requires their system vendors (Dell, HP, etc) to allow users to enroll their own Secure Boot keys through their “Designed for Windows” certification.

Further, many distributions are already compatible with Secure Boot and work out of the box. Whether or not giving Microsoft the UEFI root of trust was a good idea is questionable, but what they DO have is a long, established history of supporting Linux secure boot. They sign a UEFI shim that allows distributions to sign their kernels with their own, distribution-controlled keys in a way that just works on 99% of PCs.


Replies

mhitzayesterday at 7:04 PM

Is it possible to un-enroll the Microsoft certificates, and just trust the efi shim?

show 2 replies