UEFI is turning into a huge mess. I'd look to the Coreboot stuff being pushed/supported by AMD as a much better path to the future, and try to think of ways to club Intel's NIH-adled brain into getting on board.
UEFI is turning into a huge mess. I'd look to the Coreboot stuff being pushed/supported by AMD as a much better path to the future, and try to think of ways to club Intel's NIH-adled brain into getting on board.
The other problem is, in the original article that was published on this topic, that apparently the Linux/grub boot process will be changing so that the "kernel is part of the bootloader", so I think that adds to the complexity of the idea of signing either the bootloader or "the whole OS" (whatever that means anyway.
Regarding the "kernel is part of the bootloader" idea, I think that was just an idea :) That's not happening anytime soon, although you can give Linux as a stage 2 payload directly to coreboot currently.