Skip to content

Conversation

@zeetim
Copy link

@zeetim zeetim commented Mar 7, 2025

Microsoft asks us to submit a version of shim without fallback and mok addons to improve the security of our product.

zeetim added 2 commits March 7, 2025 17:06
It allows to use shim without fallback mechanism.
BOOT.CSV can cause security issues because user can manipulate its content.
So get rid of fallback image is one solution.

Signed-off-by: zeetim <support@zeetim.com>
This option allows to not build the mokmanager and fully remove mok variables support from shim.
This option is useful if you only want to trust vendort certificate or db certificate but not mok certificates.

Signed-off-by: zeetim <support@zeetim.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant