On Mon, May 09, 2022 at 04:51:56PM +0000, Luck, Tony wrote: > The checksum is just a "did this file get corrupted check". The file contains > SHA256 checksums for each of the chunks. These checksums are digitally > signed. Checking of these is done by microcode when the file is loaded into > BIOS reserved memory (where it is inaccessible to OS and I/O). That sounds like something I was hoping to hear, good. :-) Thx. -- Regards/Gruss, Boris. https://people.kernel.org/tglx/notes-about-netiquette