Skip to content

Modify Secure Boot key enrollment command#529

Open
eljojo wants to merge 1 commit intonix-community:masterfrom
eljojo:patch-1
Open

Modify Secure Boot key enrollment command#529
eljojo wants to merge 1 commit intonix-community:masterfrom
eljojo:patch-1

Conversation

@eljojo
Copy link

@eljojo eljojo commented Dec 22, 2025

Hello, I follow this guide at home and fount out that a command from the wiki was missing.

Updated command to include --firmware-builtin option for enrolling Microsoft keys.

This is based on https://wiki.nixos.org/wiki/Limine

Updated command to include --firmware-builtin option for enrolling Microsoft keys.

This is based on https://wiki.nixos.org/wiki/Limine
@nikstur
Copy link
Member

nikstur commented Dec 24, 2025

What's the reason to use this? Do you think this should be the general case? Should everone use --firmware-builtin?

@eljojo
Copy link
Author

eljojo commented Dec 27, 2025

@nikstur it seemed like a good idea to me to include the OEM's builtin certificates, they could come with revocation lists that come in handy? that being said, this is a bit of a cargo-culting kind of situation. I'm mostly saw it on that wiki and ran it myself, so I thought it'd be good to add it to this wiki.

it's a bit of a philosophical question whether people should trust their OEM's certificates or not, I think it's a sane default to have, and whoever has opinions about it can remove the command.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants