Red Hat Will Pay Microsoft To Get Past UEFI Restrictions

Alan Cox alan at lxorguk.ukuu.org.uk
Tue Jun 5 10:17:12 UTC 2012


> It is logically impossible to have a so-called "secure-boot" for both a free  
> OS and a non-free OS on the same platform.

Actually it's perfectly possible with some careful planning.

If you are using TXT or similar services you measure the entire boot path
and that then defines your access to the TPM which is where you put your
disk decryption keys. Neither OS can then get at the decryption key for
the other.

You can do that today 8)

Alan


More information about the users mailing list