Matthew Garrett mjg59 at srcf.ucam.org
Mon Jun 18 14:10:58 UTC 2012

On Mon, Jun 18, 2012 at 10:04:38AM -0400, Seth Johnson wrote:
> On Mon, Jun 18, 2012 at 9:56 AM, Matthew Garrett <mjg59 at srcf.ucam.org> wrote:
> > Ok so what you mean is "I want a UEFI implementation that doesn't
> > require a Microsoft signature to boot"? The options there are currently
> > (1) have a Fedora specific key (which we're not doing because it would
> > fragment the community) and (2) ship systems without secure boot enabled
> > by default. System76 (and possibly others) will be supplying systems
> > that provide (2), so that choice is available to you.
> To me.  We all -- and this notably includes Red Hat -- need to work to
> make those other systems viable.  That goes beyond my own choices.

So you want Fedora to boot on all hardware sold? There are two options 
there - we can sign Fedora with the Microsoft key or we can force 
Microsoft to change the Windows 8 requirements to forbid secure boot. 
The second of these is impossible, which leaves signing with Microsoft.

Matthew Garrett | mjg59 at srcf.ucam.org

