Red Hat engineers are proposing a minimal 'GRUB light' package for Fedora 45, designed specifically for confidential computing VMs. This stripped-down GRUB variant would support only UEFI boot, UEFI Secure Boot, and the bare minimum modules, while handling Unified Kernel Images (UKIs) and Bootloader Specification (BLS) files. The goal is to maintain stable TPM PCR values for measured boot and remote attestation in confidential VMs. The standard GRUB remains the default. systemd-boot was considered but rejected due to feature limitations, testing concerns, and the desire to avoid maintaining multiple bootloaders.

2m read timeFrom phoronix.com
Post cover image
26 Impressions