-
Bug
-
Resolution: Unresolved
-
Critical
-
rhel-10.2
-
None
-
None
-
Critical
-
rhel-bootloader
-
1
-
29
-
30
-
0
-
False
-
False
-
-
Yes
-
secure boot
-
Approved Exception
-
None
-
None
-
Enhancement
-
-
Proposed
-
Unspecified
-
Unspecified
-
Unspecified
-
None
To deal with multiple certificates optionally enrolled on a system, including the Microsoft UEFI 2011 and Microsoft UEFI 2023 certs as well as future PQC roots of trust, we need to be able to select which shim to install during installation and upgrades.
To do that, we need a tool that can evaluate the enrolled roots of trust and select bootloaders based on their signatures.