Hacker News new | ask | show | jobs
by queeerkopf 4148 days ago
Gummiboot recently added support to create a single EFI executable that contains the /etc/os-release file, kernel parameters, bzImage and initrd [1] You should then be able to sign this file and configure UEFI Secure Boot so that only files signed by you can be booted. I guess that's the reasoning behind it.

[1] https://plus.google.com/+KaySievers/posts/GisPmPBsqfK