dotfiles/etc/dracut-sbctl.conf

6 lines
300 B
Text
Raw Normal View History

2022-09-25 18:01:11 +00:00
# Sign unified images with sbctl keys to support secure boot
uefi_secureboot_cert="/usr/share/secureboot/keys/db/db.pem"
uefi_secureboot_key="/usr/share/secureboot/keys/db/db.key"
# Enable lockdown if secure boot's on to prevent loading unsigned kernel modules
kernel_cmdline+=" lockdown=integrity "