Re: efibootmgr help

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Sat, Aug 29, 2015 at 5:20 AM, Paul Cartwright <pbcartwright@xxxxxxxxx> wrote:
> On 08/29/2015 01:25 AM, Chris Murphy wrote:
>>> > Then it is necessary to deactivate the Secureboot. This tool was
>>> > implemented in Windows 8 with the new UEFI Bios, as a safety mechanism
>>> > to prevent malicious software from booting in your PC, as well as “non
>>> > authorized” operating systems.
>>> >
>>> > Therefore, this tool will block any operating system from starting,
>>> > besides Windows 8. So it must be deactivated.
>>> >
>>> > In order to do that, it’s necessary to access your computer Bios, search
>>> > for the option “Secureboot” and change it to “Disabled”.
>> The only correct part is "prevent malicious software from booting"
>> otherwise everything else is somewhere between misleading and junk.
>> Fedora has supported Secure Boot for almost three years.
>>
> that may be true, but however I got my fedora installed on this UEFI box
> is the way I am leaving it.. I am pretty sure I have secure boot turned
> off. it works, and I go with the KISS method, it works, I'm leaving it
> alone:)

UEFI Secure Boot implementation in Windows, Fedora, and openSUSE (and
presumably Ubuntu, I don't recall testing it) is as simple as it gets.
It's not so easy to understand but it's also not really necessary to
understand it unless you're rolling your own kernels, and then you
have to learn how to sign or hash your kernels and get shim to accept
your cert or hashes.

The one consequence of enabling Secure Boot is the GRUB menu entry for
Windows will not work. And although I haven't tried this, I actually
suspect that the os-prober menu entries for other OS's won't work
either because, e.g. the Fedora GRUB contains the key to verify Fedora
kernels, but not Ubuntu. And vice versa.


-- 
Chris Murphy
-- 
users mailing list
users@xxxxxxxxxxxxxxxxxxxxxxx
To unsubscribe or change subscription options:
https://admin.fedoraproject.org/mailman/listinfo/users
Fedora Code of Conduct: http://fedoraproject.org/code-of-conduct
Guidelines: http://fedoraproject.org/wiki/Mailing_list_guidelines
Have a question? Ask away: http://ask.fedoraproject.org



[Index of Archives]     [Older Fedora Users]     [Fedora Announce]     [Fedora Package Announce]     [EPEL Announce]     [EPEL Devel]     [Fedora Magazine]     [Fedora Summer Coding]     [Fedora Laptop]     [Fedora Cloud]     [Fedora Advisory Board]     [Fedora Education]     [Fedora Security]     [Fedora Scitech]     [Fedora Robotics]     [Fedora Infrastructure]     [Fedora Websites]     [Anaconda Devel]     [Fedora Devel Java]     [Fedora Desktop]     [Fedora Fonts]     [Fedora Marketing]     [Fedora Management Tools]     [Fedora Mentors]     [Fedora Package Review]     [Fedora R Devel]     [Fedora PHP Devel]     [Kickstart]     [Fedora Music]     [Fedora Packaging]     [Fedora SELinux]     [Fedora Legal]     [Fedora Kernel]     [Fedora OCaml]     [Coolkey]     [Virtualization Tools]     [ET Management Tools]     [Yum Users]     [Yosemite News]     [Gnome Users]     [KDE Users]     [Fedora Art]     [Fedora Docs]     [Fedora Sparc]     [Libvirt Users]     [Fedora ARM]

  Powered by Linux