Hi On Thu, Mar 12, 2015 at 2:41 PM, Andrei Borzenkov <[email protected]> wrote: > initrd and cmdline are volatile and generated on end-user system. So > your container must be signed on end user system. End user obviously > does not have Microsoft or vendor private keys to sign your container, > so end user must manage own keys. Apparently, it is not quite as > simple, otherwise we would not need to invent shim in the first place.
The signed EFI binary is distributed by your distribution/vendor/key-owner. The machine-owner is responsible of putting the key of your vendor into the firmware. Thanks David _______________________________________________ systemd-devel mailing list [email protected] http://lists.freedesktop.org/mailman/listinfo/systemd-devel
