Hacker News new | past | comments | ask | show | jobs | submit login

--permissive-security is the setting that you want. You are then able to enroll hashes of unsigned kernels with kmutil.



Kmutil is only there to load kernel extensions? Or did that change with Big Sur?


It changed. You use kmutil create to create the artifacts and add the hash to the Secure Boot policy. (--help at https://pastebin.ubuntu.com/p/mN3Z2kfJWy/, no manpage)




Consider applying for YC's Fall 2025 batch! Applications are open till Aug 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: