Re: [GIT PULL] Load keys from signed PE binaries

2013-02-27 Thread ownssh
Matthew Garrett srcf.ucam.org> writes: > There's no way to update the UEFI key database without the update being > signed by an already trusted key, so what you're proposing isn't > possible. > I confused. Isn't custom mode can add user's own key? > http://mjg59.dreamwidth.org/12368.html > Bu

Re: [GIT PULL] Load keys from signed PE binaries

2013-02-27 Thread ownssh
David Howells redhat.com> writes: > > > Florian Weimer deneb.enyo.de> wrote: > > > Seriously, folks, can we go back one step and discuss what problem you > > are trying to solve? Is it about allowing third-party kernel modules > > in an environment which does not allow unsigned ring 0 code e