Next: check_signatures, Previous: blsuki_save_default, Up: Special environment variables [Contents][Index]
This variable controls whether GRUB enforces appended signature validation on
loaded kernel and GRUB module files. It is automatically set by GRUB
to either no or yes based on the ’ibm,secure-boot’ device
tree property. Also, it can be explicitly set to either no or yes by
setting the check_appended_signatures variable from the GRUB console
when the GRUB is not locked down.
See Using appended signatures in GRUB for more information.