Comment by trelane
Comment by trelane 5 days ago
Not all. The ones that ship Linux preinstalled and with support don't.
Comment by trelane 5 days ago
Not all. The ones that ship Linux preinstalled and with support don't.
AFAIU (I haven't looked much into it) shim basically exists so that MS signs the shim once (or only a few times when updated), which has the distro public key embedded, which does further verification of the chain (bootloader/kernel) which gets updated more frequently.
I hope you are mistaken. It's embarrassing how far behind in security the desktop Linux ecosystem is.