Hi Mimi, I need to add a statement about the IMA secure_boot rules to the kernel_lockdown manual page. Is this enough: IMA requires the addition of the "secure_boot" rules to the policy, whether or not they are specified on the command line, for both the builtin and custom policies in secure boot lockdown mode. I don't know what this actually does/achieves. David