On Thu, Sep 10, 2020 at 05:23:14PM -0000, Lee Trager wrote:
> Secure boot must work for every operating system MAAS supports, not just
> Ubuntu.
Chainloading to shim instead of directly to grub is mandatory /even/ for
Ubuntu because it is not guaranteed over time that the shim in the MAAS
stream and the shim on disk from different versions of Ubuntu have the same
security policies.
On Thu, Sep 10, 2020 at 05:23:14PM -0000, Lee Trager wrote:
> Secure boot must work for every operating system MAAS supports, not just
> Ubuntu.
Chainloading to shim instead of directly to grub is mandatory /even/ for
Ubuntu because it is not guaranteed over time that the shim in the MAAS
stream and the shim on disk from different versions of Ubuntu have the same
security policies.