Next: , Up: Special environment variables   [Contents][Index]


15.1.1 appendedsig_key_mgmt

This variable controls whether GRUB enforces appended signature validation using either static or dynamic key management. It is automatically set by GRUB to either static or dynamic based on the ’ibm,secure-boot’ device tree property and Platform KeyStore (PKS). Also, it can be explicitly set to either static or dynamic by setting the appendedsig_key_mgmt variable from the GRUB console when the GRUB is not locked down.

See Using appended signatures in GRUB for more information.