This commit is contained in:
mjallen18
2026-01-27 13:01:36 -06:00
parent defbd725dd
commit 01ae622391
4 changed files with 207 additions and 14 deletions

View File

@@ -76,32 +76,32 @@ in
# Secureboot keys
# ------------------------------
"secureboot/GUID" = lib.mkIf isx86 {
path = "/etc/secureboot/GUID";
mode = "0640";
# path = "/etc/secureboot/GUID";
mode = "0600";
};
"secureboot/keys/db-key" = lib.mkIf isx86 {
path = "/etc/secureboot/keys/db/db.key";
mode = "0640";
# path = "/etc/secureboot/keys/db/db.key";
mode = "0600";
};
"secureboot/keys/db-pem" = lib.mkIf isx86 {
path = "/etc/secureboot/keys/db/db.pem";
mode = "0640";
# path = "/etc/secureboot/keys/db/db.pem";
mode = "0600";
};
"secureboot/keys/KEK-key" = lib.mkIf isx86 {
path = "/etc/secureboot/keys/KEK/KEK.key";
mode = "0640";
# path = "/etc/secureboot/keys/KEK/KEK.key";
mode = "0600";
};
"secureboot/keys/KEK-pem" = lib.mkIf isx86 {
path = "/etc/secureboot/keys/KEK/KEK.pem";
mode = "0640";
# path = "/etc/secureboot/keys/KEK/KEK.pem";
mode = "0600";
};
"secureboot/keys/PK-key" = lib.mkIf isx86 {
path = "/etc/secureboot/keys/PK/PK.key";
mode = "0640";
# path = "/etc/secureboot/keys/PK/PK.key";
mode = "0600";
};
"secureboot/keys/PK-pem" = lib.mkIf isx86 {
path = "/etc/secureboot/keys/PK/PK.pem";
mode = "0640";
# path = "/etc/secureboot/keys/PK/PK.pem";
mode = "0600";
};
};