A Secure Boot system that has Canonical's key in the db can boot can boot our signed GRUB directly (i.e., w/o chaining through shim). In this configuration, GRUB will permit booting unsigned kernels. Reported by Ard Biesheuvel of Linaro.
A Secure Boot system that has Canonical's key in the db can boot can boot our signed GRUB directly (i.e., w/o chaining through shim). In this configuration, GRUB will permit booting unsigned kernels. Reported by Ard Biesheuvel of Linaro.