openSUSE's next version of sdbootutil will drop pcr-oracle in favor of systemd-pcrlock for user space Full Disk Encryption. The signed policy approach used by pcr-oracle is vulnerable to rollback attacks and requires ongoing maintenance for multiple bootloaders (GRUB2 and systemd-boot). The NVIndex policy via systemd-pcrlock

3m read timeFrom news.opensuse.org
Post cover image
Table of contents
IntroductionMotivationMigrationFurther Documentation

Sort: