Originally posted by sithlord48
View Post

secondly there is nothing wrong with UEFI itself.
Matthew Garrett is the one at Red Hat that's been working quite extensively on UEFI support under Linux, since this BIOS successor is beginning to be found in all new hardware. He's the one that's been shouting how UEFI Secure Boot will cause big problems for Linux. He's also worked on matters like better reboot support and finally fixing the ASPM Linux kernel power regression.
While Secure Boot is what's usually brought up when mentioning Linux and UEFI in the same sentence, there's much more to this new architecture than just a locked-down boot process in an attempt for greater security. UEFI does provide some good like better variable storage, no longer needing to pound out Assembly, greater device capabilities and more. But besides Secure Boot being a major pain for Linux and other non-Windows operating systems, another big problem with UEFI has been all of the bugs uncovered in different hardware devices.
While Secure Boot is what's usually brought up when mentioning Linux and UEFI in the same sentence, there's much more to this new architecture than just a locked-down boot process in an attempt for greater security. UEFI does provide some good like better variable storage, no longer needing to pound out Assembly, greater device capabilities and more. But besides Secure Boot being a major pain for Linux and other non-Windows operating systems, another big problem with UEFI has been all of the bugs uncovered in different hardware devices.
on top of that we really do need a replacement for BIOS. personally i am in favor of coreboot. oh btw openbios iirc turned into coreboot or they merged. i have one of these as the main board in my server. the UEFI has given me no problems installing a linux distro on it. the problem is that M$ thinks they can dictate to hardware manufactures how to make their boards. If M$ dictates they force key signing and don't let users put their own keys have it enabled by the default (etc..) this is indeed very bad.
The use of these keys is not in themselves bad, as long as its user modifable.Prehaps all machines with UEFI (including those that come prebuilt) should come with a disk(or better yet built in utility) you can to run to install your os's keys from a list. if your keys are not on a list provide a user with a manual where they can provide their own key via a usb stick or net address (after all its UEFI so all the hw will be working). i realise that this is might not be the most realistic case but i think it would be a case that would at least make everyone happy. unless intel jumps on the support coreboot bandwagon then we might get that.
The use of these keys is not in themselves bad, as long as its user modifable.Prehaps all machines with UEFI (including those that come prebuilt) should come with a disk(or better yet built in utility) you can to run to install your os's keys from a list. if your keys are not on a list provide a user with a manual where they can provide their own key via a usb stick or net address (after all its UEFI so all the hw will be working). i realise that this is might not be the most realistic case but i think it would be a case that would at least make everyone happy. unless intel jumps on the support coreboot bandwagon then we might get that.
In addition, as I pointed out previously, EVERY Kernel module would have to have a PK certificate from the peripheral device that module drives, and for the PC on which that device is installed. The UEFI whitelist would get gigantic. And, the UEFI code is so buggy and untested that there is no guarantee that the UEFI would be stable under those circumstances.
It is a very informative talk by one of the FEW, if not the only, Linux guys to ACTUALLY work with the EUFI code. What anyone else says is just second hand knowledge, wild speculation, or blatent spinning.

Leave a comment: