Feature request: secure boot compatibility

Some firmware allow installing or replacing certificates and keys other than the microsoft ones, therefore it is possible to enable secure boot for clear linux on these devices (like mine).

Although this procedure require certain operations under firmware, it can be largely simplified if the installer can automatize certain parts.

This will largely improve security for desktop clear linux.

Yes, we do have support for secure boot on our ‘todo’ list. It’s being tracked in https://github.com/clearlinux/distribution/issues/234


1 Like

This is possible with every UEFI firmware. By specification, you can remove the Microsoft keys and add your own keys.