Skip to content

Support transitioning to Deployed Mode #429

@quite

Description

@quite

I think it would be nice if sbctl would try to transition Secure Boot to "Deployed Mode". If that is doable.
Then there cannot be any mistaken transition (carried out by anyone) to "Audit Mode" (support for which would be nice, but that's something else)

Figure 32.4 here is a nice ref: https://uefi.org/specs/UEFI/2.11/32_Secure_Boot_and_Driver_Signing.html#firmware-os-key-exchange-creating-trust-relationships

Metadata

Metadata

Assignees

No one assigned

    Labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions