Kernel module signature verification can be enabled using the module.sig_enforce=1 kernel parameter on non-EFI systems.
On non-EFI systems, mokutil won't work. But then how could one enroll the key without needing to recompile grub or the kernel?
Can /var/lib/dkms/mok.pub be enrolled using keyctl?
Is this something that DKMS could automate?
Kernel module signature verification can be enabled using the
module.sig_enforce=1kernel parameter on non-EFI systems.On non-EFI systems,
mokutilwon't work. But then how could one enroll the key without needing to recompile grub or the kernel?Can
/var/lib/dkms/mok.pubbe enrolled usingkeyctl?Is this something that DKMS could automate?