> Is the checksum the only protection against people loading arbitrary IFS > images or are those things signed or encrypted, just like the microcode? > > I'd hope they pass the same checks as microcode, when they get loaded, > considering the similarity of how they're handled... The checksum is just a "did this file get corrupted check". The file contains SHA256 checksums for each of the chunks. These checksums are digitally signed. Checking of these is done by microcode when the file is loaded into BIOS reserved memory (where it is inaccessible to OS and I/O). -Tony