docs: Update note about Secure Boot support

Secure Boot support is enabled. Make it clear in the doc that it was
enabled so Windows could be installed, and not as a means for securing
the system.

Signed-off-by: Tim Crawford <tcrawford@system76.com>
This commit is contained in:
Tim Crawford 2023-12-12 09:46:39 -07:00 committed by Jeremy Soller
parent 2e4e34bf83
commit 6f1e65308e

View File

@ -14,12 +14,15 @@ Network functionality is disabled. Native PXE booting is not supported.
### Secure Boot
Secure Boot support is currently disabled.
Secure Boot support is enabled since system76/firmware-open@105e74b14613
(2023-04-03).
The implementation from 9elements is in development. If building a custom
image, the edk2 config `SECURE_BOOT_ENABLE` can be set to enable support.
A minimal firmware UI is available to delete all keys and enroll the default
keys. It is intended that most management is done from the OS.
There is currently no firmware UI to view or configure Secure Boot.
Note that the Secure Boot support present is only intended for allowing
Microsoft Windows installation checks to pass. It should not be relied on for
system security due to limitations of the implementation.
## Shell