Linked by Thom Holwerda on Fri 22nd Jun 2012 23:17 UTC
Thread beginning with comment 523428
To view parent comment, click here.
To read all comments associated with this story, please click here.
To view parent comment, click here.
To read all comments associated with this story, please click here.
RE[6]: Comment by Lazarus
by mjg59 on Sat 23rd Jun 2012 04:20
in reply to "RE[5]: Comment by Lazarus"
RE[7]: Comment by Lazarus
by Alfman on Sat 23rd Jun 2012 05:38
in reply to "RE[6]: Comment by Lazarus"
mjg59,
"Microsoft require that all x86 systems permit the user to modify the keys. They forbid that on ARM, so we won't be supporting secure boot on ARM."
Well that's great to hear that the keys can be overridden and not just disabled! Your earlier statement makes more sense to me now.




Member since:
2011-01-28
mjg59,
"We'll be providing tools for users to install their own keys if they want to build their own kernels or use third party modules - it's vitally important to us that users be in control of their system, and we won't support any scenario where they're not."
Correct me if I'm wrong, but your stock kernel, which is to be validated under microsoft's chainloader, will reject 3rd party/end-user modules signed with user keys not approved by microsoft, right?
The only way for users to load/run their own modules would be for them to get their own keys approved by microsoft. If this user distributes code as "open source" to another user, they then face the same problem all over again. Each user who obtains the source code will loose the ability to compile & run it without permission from microsoft.
Your claiming that it's vitally important for users to be in control of their system, yet in my opinion this scenario doesn't permit that. It gives microsoft control. Can you help me understand your point of view better?
Edit:
I'm aware that you mention disabling secure boot or changing the keys in this link.
http://mjg59.dreamwidth.org/12368.html
But I'm talking about being able to use Fedora with secure boot enabled on a typical consumer system where the keys cannot be changed.
Edited 2012-06-23 04:05 UTC