Enroll keys without clearing for Multi boot #460
Labels
No labels
bug
dependency
documentation
duplicate
enhancement
good first issue
help wanted
invalid
question
review-next
security
stub
tool
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference: raito/lanzaboote#460
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
I am currently using a Framework 16. I have multiple OS on different modules. They are all registered with Secure Boot.
I was going through the setup process for lanzaboote for Nix and sbctl says everything looks good.
The problem is that clearing all the existing ones is problematic. Is there any plan of allowing this to add to the existing keys (like mokutil or whatever)? Currently Nix is the only one not able to secure boot.
Would like Mokutil too. As soon as one of my other OSes re-updated the forbidden database, my Nix OS install started throwing a bad shim signature error and couldn't boot it again.
Also it seems to create several boot entries for me.
You can keep the keys for shim if you want to be able to boot with shim.
As long as you keep the lanzaboote keys, this will work too.