Hacker News new | ask | show | jobs
by winstonwinston 2 hours ago
> Apparently RHEL will even refuse to install a 2023 signed shim if the firmware lacks the certificate for it.

Why is that? RHEL own blog post described that RHEL is distributing dual signed shim by both 2011 and 2023 certificates, so that it works either way, only 2011 present or only 2023.