Comment 0 for bug 1810842

Revision history for this message
dann frazier (dannf) wrote :

A Secure Boot system that has Canonical's key in the db can boot can boot our signed GRUB directly (i.e., w/o chaining through shim). In this configuration, GRUB will permit booting unsigned kernels. Reported by Ard Biesheuvel of Linaro.