Comment by craftkiller
15 days ago
> signed shim
How would they sign such a shim without my keys? I don't leave Microsoft keys enrolled on my laptop.
15 days ago
> signed shim
How would they sign such a shim without my keys? I don't leave Microsoft keys enrolled on my laptop.
You don't but 99.99% of people do :) Especially because most Linux distros use a key signed by Microsoft by default.
The “people” don’t really matter.
Anyone who needs a secure boot environment is having their own MOK and probably a private CA.