You are not logged in.
Hi !
kernel_lockdown.7 states :
On an EFI-enabled x86 or arm64 machine, lockdown will be automatically enabled if the system boots in EFI Secure Boot mode.
However on my system with Secure Boot enabled, lockdown is only enabled with the appropriate lockdown= kernel parameters.
(See https://wiki.archlinux.org/title/Securi … kdown_mode)
Is the manpage misleading or am I missing something ?
Thanks !
Last edited by Cvlc (2023-03-08 21:30:46)
Offline
It says x86, not x86_64. They should make that clearer. I have secure boot enabled on my x86_64 machine and I can confirm, lockdown isn’t enabled by default on it.
Offline
Good catch ! Although other sources and articles don't mention this detail at all.
Offline
The man page for lockdown was initially sourced from Fedora https://git.kernel.org/pub/scm/docs/man … d670d3608d
There have been later commits adjusting it to match what was accepted into the upstream kernel. This could be another overlooked difference as earlier iterations of the lockdown patch series did enable lockdown when secureboot was enabled https://git.kernel.org/pub/scm/linux/ke … 22b9b90203 that feature was rejected by Linus and so dropped.
Offline
Thanks ! I was just reading about this right now.
Offline