On Mon, Nov 2, 2020 at 12:24 PM Ard Biesheuvel <ardb@xxxxxxxxxx> wrote: > Does Shim use PCR 7 for the MOK key database? Are there any specific > requirements from MS on which PCRs Shim must touch? Yes, shim extends PCR 7 in the same way the firmware does. There's no requirement from MS on this, it just seemed like the right solution.