feat: check tpm unlocking signatures are valid on upgrade #2598
Labels
enhancement
New feature or request
triage
Add this label to issues that should be triaged and prioretized in the next planning call
Part 2 of #2200
While we now should be checking the EFI signature to confirm it can boot, we are not checking if the measurements of the EFI file are able to unlock the encrypted parts.
we should try to add this as it could lead to confusing errors in which you upgrade and boot, but then you cant unlock the partitions so you cannot log in (and apparently the system booted just fine)
The idea would be:
problems:
The text was updated successfully, but these errors were encountered: