Comment 34 for bug 1865515

Revision history for this message
Steve Langasek (vorlon) wrote : Re: [Bug 1865515] Re: Chainbooting from grub over the network to local shim breaks chain of trust

On Thu, Sep 10, 2020 at 05:23:14PM -0000, Lee Trager wrote:
> Secure boot must work for every operating system MAAS supports, not just
> Ubuntu.

Chainloading to shim instead of directly to grub is mandatory /even/ for
Ubuntu because it is not guaranteed over time that the shim in the MAAS
stream and the shim on disk from different versions of Ubuntu have the same
security policies.