mirror of
https://github.com/NixOS/nixpkgs.git
synced 2026-10-02 21:10:08 +00:00
This signs the shim with the same vendor certificate that gets embedded in the shim, which is not what you want for supporting Microsoft Secure Boot keys. The Microsoft signature will require different handling in future work, and is blocked on compliance anyway, but this is still useful for having a uniform bootloader chain and MOK handling.