Windows Hardware Certification Requirements - Client and Server Systems
Mandatory. On non-ARM systems, the platform MUST implement the ability for a physically present user to select between two Secure Boot modes in firmware setup: "Custom" and "Standard". Custom Mode allows for more flexibility as specified in the following:
It shall be possible for a physically present user to use the Custom Mode firmware setup option to modify the contents of the Secure Boot signature databases and the PK. This may be implemented by simply providing the option to clear all Secure Boot databases (PK, KEK, db, dbx) which will put the system into setup mode.
If the user ends up deleting the PK then, upon exiting the Custom Mode firmware setup, the system will be operating in Setup Mode with SecureBoot turned off.
The firmware setup shall indicate if Secure Boot is turned on, and if it is operated in Standard or Custom Mode. The firmware setup must provide an option to return from Custom to Standard Mode which restores the factory defaults.On an ARM system, it is forbidden to enable Custom Mode. Only Standard Mode may be enabled.
Enfin bon, de toutes manières, tu ne réponds même pas au problème principal, comme tous les supporters de cette techno : tu veux juste à tout prix montrer qu'on « peut » la désactiver, sans même parler de la nocivité de la techno en elle-même. C'est toujours les même méthodes, déplacer le débat. Alors que tu sais très bien la différence que ça fait que ça soit activé par défaut : le « par défaut », MS connaît bien.
Nocive ? Tu m'expliques comment ? L'utilisateur peut le stopper, peut ajouter les clefs qu'il veut.
Quand a "active par defaut", vu l'accord avec Fedora je ne vois pas le probleme, les distribs Linux pourront s'installer de maniere totalement transparente, et les rares gens qui veulent jouer avec le kernel, ils seront largement assez competent pour stopper Secure Boot ou ajouter leur propre cle.
[^] # Re: RH ne supporte pas Secure Boot
Posté par pasBill pasGates . En réponse au journal Canonical embrasse la technologie Microsoft (bootloader). Évalué à 0.
http://msdn.microsoft.com/en-US/library/windows/hardware/jj128256
Windows Hardware Certification Requirements - Client and Server Systems
It shall be possible for a physically present user to use the Custom Mode firmware setup option to modify the contents of the Secure Boot signature databases and the PK. This may be implemented by simply providing the option to clear all Secure Boot databases (PK, KEK, db, dbx) which will put the system into setup mode.
If the user ends up deleting the PK then, upon exiting the Custom Mode firmware setup, the system will be operating in Setup Mode with SecureBoot turned off.
The firmware setup shall indicate if Secure Boot is turned on, and if it is operated in Standard or Custom Mode. The firmware setup must provide an option to return from Custom to Standard Mode which restores the factory defaults.On an ARM system, it is forbidden to enable Custom Mode. Only Standard Mode may be enabled.
Enfin bon, de toutes manières, tu ne réponds même pas au problème principal, comme tous les supporters de cette techno : tu veux juste à tout prix montrer qu'on « peut » la désactiver, sans même parler de la nocivité de la techno en elle-même. C'est toujours les même méthodes, déplacer le débat. Alors que tu sais très bien la différence que ça fait que ça soit activé par défaut : le « par défaut », MS connaît bien.
Nocive ? Tu m'expliques comment ? L'utilisateur peut le stopper, peut ajouter les clefs qu'il veut.
Quand a "active par defaut", vu l'accord avec Fedora je ne vois pas le probleme, les distribs Linux pourront s'installer de maniere totalement transparente, et les rares gens qui veulent jouer avec le kernel, ils seront largement assez competent pour stopper Secure Boot ou ajouter leur propre cle.