On Tue, Dec 20, 2022 at 04:31:20PM -0500, Simo Sorce wrote:
On Tue, 2022-12-20 at 20:42 +0100, Björn Persson wrote:
> I note that taking away the kernel command line is indeed a clearly
> stated goal, which will limit Fedora to simple, appliance-like uses.
And if you chose your HW carefully you may even be able to register
your own public keys, generate and sign your own built UKIs and re-
enable SecureBoot after that... your choice!
And when your hardware doesn't allow that you can still add your own
keys with mokutil so shim.efi will accept your self-signed UKIs.
take care,
Gerd