From: Alan Cox <hidden> Date: 2012-09-18 18:46:53
Also in:lkml
On Tue, 18 Sep 2012 18:34:12 +0100
David Howells [off-list ref] wrote:
Alan Cox [off-list ref] wrote:
quoted
Why do this in the kernel.That appears to be completely insane.
A number of reasons:
(1) The UEFI signature/key database may contain ASN.1 X.509 certificates and
we may need to use those very early in the boot process, during initrd.
Ok that makes some sense. Presumably they've also got to fall within what
you trust and sign ?
Alan