Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Your option E is perfectly reasonable if you don't care about secure boot. And most people don't. After all, computers have worked without secure boot since they were invented.

If you, as a vendor, want to support secure boot (as a new, optional, extra feature), I think option B (be the CA) is the only right way to do it. If vendors don't like having to do duplicate work then they can cooperate and form a shared organization to be the central Linux CA. Relying on Microsoft to do the signing is not a good idea long term.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: