> > And there is nothing fancy to be done for EFI and SecureBoot? Or is > that something that the kernel has to handle on its own (so somehow > passing some certificates to somewhere). > For EFI, no... other than passing the EFI parameters, which apparently is *not* currently done (David Woodhouse is working on it.) Secure boot is still a work in progress. -- H. Peter Anvin, Intel Open Source Technology Center I work for Intel. I don't speak on their behalf.