On Tue, Nov 21, 2017 at 04:27:45PM -0800, Jethro Beekman wrote: > See http://www.spinics.net/lists/platform-driver-x86/msg13829.html under > "Launch control". Essentially, firmware can make it so that user has no > control over IA32_SGXLEPUBKEYHASHn value. ... and we're back full circle to my initial objection: firmware should not be doing anything here. The user should. The mail you're quoting is the same subthread we are at. -- Regards/Gruss, Boris. Good mailing practices for 400: avoid top-posting and trim the reply.