|
|
|
|
|
by thudson
2092 days ago
|
|
This NSA report is a wonderfully thorough guide to configuring UEFI Secure Boot, although it is another example of how unusable security tools can be. This conplexity was my motivation for writing the safeboot[1] scripts, which wrap all of the signing key management, TPM key sealing, and attestation into a hopefully easier to use package. 1: https://safeboot.dev/ |
|
[0] https://github.com/google/go-tpm-tools.