Deploying Encrypted Images for Confidential Computing
blog.hansenpartnership.com
blog.hansenpartnership.com
Why is that? We have used the EFI stub, which is part of the Linux kernel for quite a while. There is no need for a separate boot loader. Admittedly our systems are closer to embedded Linux than to big servers. What are the cases where you absolutely need grub (or another loader) today?
Signing, as I said in the article, is a possible solution but it's more complex to implement than simply putting everything into the encrypted image to assure being both confidential and tamper proof.