Comment 7 for bug 1811496

Revision history for this message
Steve Langasek (vorlon) wrote :

As discussed on IRC, we are not going to sign multiple bootloader implementations with the key because this would increase the attack surface of UEFI Secure Boot (which is already quite large, but signing multiple competing bootloader implementations would be an unforced error).

If there are features missing from grub, that should be addressed as a bug in grub.

We do publish a signed grub image suitable for netbooting use.
http://archive.ubuntu.com/ubuntu/dists/disco/main/uefi/grub2-amd64/current/grubnetx64.efi.signed