-
Notifications
You must be signed in to change notification settings - Fork 2
Open
Labels
SovereignBootIssues related to Sovereign Boot and Sovereign Boot Provisioning WizardIssues related to Sovereign Boot and Sovereign Boot Provisioning Wizard
Description
Managing UEFI Secure Boot variables using OS tools like efitools does not work as intended. According to Debian manpages it should be possible to remove PK if owning the private key enrolled currently as PK: https://manpages.debian.org/testing/efitools/efi-updatevar.1.en.html
However, for some reason it does not want to pass:

One may say that the protection works, but to the extent that nothing can be done once PK is enrolled.
It will have to be investigated and eventually fixed in the next phase of Sovereign Boot Provisioning Wizard project.
Metadata
Metadata
Assignees
Labels
SovereignBootIssues related to Sovereign Boot and Sovereign Boot Provisioning WizardIssues related to Sovereign Boot and Sovereign Boot Provisioning Wizard