docs/doc/source/planning/kubernetes/uefi-secure-boot.rst
Ron Stone f125a8b892 Remove spurious escapes (r8,dsR8)
This change addresses a long-standing issue in rST documentation imported from XML.
That import process added backslash escapes in front of various characters. The three
most common being '(', ')', and '_'.
These instances are removed.

Signed-off-by: Ron Stone <ronald.stone@windriver.com>
Change-Id: Id43a9337ffcd505ccbdf072d7b29afdb5d2c997e
2023-03-01 11:19:04 +00:00

1.0 KiB

UEFI Secure Boot

Secure Boot is a technology where the system firmware checks that the system boot loader is signed with a cryptographic key authorized by a configured database of certificate(s) contained in the firmware or a security device. It is used to secure various boot stages.

's implementation of Secure Boot also validates the signature of the second-stage boot loader, the kernel, and kernel modules.

Operational complexity:

  • For each node that is going to use secure boot, you must populate the public certificate (with public key) in the Secure Boot authorized database in accordance with the board manufacturer's process.
  • You may need to work with your hardware vendor to have the certificate installed.
  • This must be done for each node before starting the installation.

For more information, see the section UEFI Secure Boot <overview-of-uefi-secure-boot>.