> It is logically impossible to have a so-called "secure-boot" for both a free  
> OS and a non-free OS on the same platform.

Actually it's perfectly possible with some careful planning.

If you are using TXT or similar services you measure the entire boot path
and that then defines your access to the TPM which is where you put your
disk decryption keys. Neither OS can then get at the decryption key for
the other.

You can do that today 8)

Alan
-- 
users mailing list
users@lists.fedoraproject.org
To unsubscribe or change subscription options:
https://admin.fedoraproject.org/mailman/listinfo/users
Guidelines: http://fedoraproject.org/wiki/Mailing_list_guidelines
Have a question? Ask away: http://ask.fedoraproject.org

Reply via email to