-
-
Notifications
You must be signed in to change notification settings - Fork 49
Description
From linuxboot/heads#1282:
It's not obvious how to store your private keys on a YubiKey.
OEM Factory Reset / Re-Ownership -->is NOT your friend. Instead, you want to go underGPG Options -->→Add GPG key to running BIOS and reflash, which will prompt you to insert a USB drive containing your GPG public key. Then, the next time you selectUpdate checksums and sign all files in /boot, Heads will prompt you to insert your GPG smartcard.
OEM Factory Reset / Re-Ownership --> will generate keys on the device, OR, will prompt you to generate keys on a hardware token which led me to accidentally wipe my YubiKey.
I'm imagining some sort of guided menu that asks "Would you like to use an existing GPG key pair?" And then walks the user through flashing their public key to the BIOS, etc.