On Mon, May 24, 2021 at 11:30:09PM -0000, VINAY RAJESH wrote: > What about the scenario where the signers are different for kernel and > grub? For example, if the kernel is signed using a self signed cert and > loaded using MOK.
> I am trying to do that right now but the kernel fails to load when > signed with a MOK key. In that case, yes, the key in mok used for signing the kernel is supposed to be measured in addition to the key used for signing grub. But it sounds like you're not getting to that point yet, if your kernel fails to load. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1929454 Title: Bios measurements do not contain measurements for the kernel binary and kernel signer cert. To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/shim-signed/+bug/1929454/+subscriptions -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs