Mandatory. Enable/Disable Secure Boot. On non-ARM systems, it is required to implement the ability to disable Secure Boot via firmware setup. A physically present user must be allowed to disable Secure Boot via firmware setup without possession of PKpriv. A Windows Server may also disable Secure Boot remotely using a strongly authenticated (preferably public-key based) out-of-band management connection, such as to a baseboard management controller or service processor. Programmatic disabling of Secure Boot either during Boot Services or after exiting EFI Boot Services MUST NOT be possible. Disabling Secure Boot must not be possible on ARM systems.
Donc Microsoft exige que le secure boot ne puisse être désactivé sur ARM.
[^] # Re: Irrémédiable
Posté par Shuba . En réponse au journal Gnome3 et systemd, c'est la fin des haricots!. Évalué à 10.
D'après http://msdn.microsoft.com/en-US/library/windows/hardware/jj128256 :
Donc Microsoft exige que le secure boot ne puisse être désactivé sur ARM.