On 7/3/26 1:00 PM, Zhuoying Cai wrote: > When secure boot is enabled (-secure-boot on) and certificate(s) are > provided, the boot operates in True Secure IPL mode. > > Any verification error during True Secure IPL mode will cause the > entire boot process to terminate. > > Secure IPL in audit mode requires at least one certificate provided in > the key store along with necessary facilities. If secure boot is enabled > but no certificate is provided, the boot process will also terminate, as > this is not a valid secure boot configuration. > > Note: True Secure IPL mode is implemented for the SCSI scheme of > virtio-blk/virtio-scsi devices. > > Signed-off-by: Zhuoying Cai <[email protected]> > Reviewed-by: Collin Walling <[email protected]>
Reviewed-by: Matthew Rosato <[email protected]>
