Conversation

Jarkko Sakkinen

IMHO, a rational choice. Distributors know how to enable this for workstation/server, and for devices that are not fast enough have always e.g. fTPM in TrustZone option.

https://lore.kernel.org/linux-integrity/20240518113424.13486-1-jarkko@kernel.org/T/#u
1
0
0
... pushed already to master/next w/o review comments, it is just making upcoming feature opt-in. Turning default later off is much more tedious than turning it on so it is the right thing to do.

So soon available in linux-next...
1
0
0

Jarkko Sakkinen

Edited 6 months ago
rc1 will have this slowdown issue because the patch will go to my rc2 PR. for most part on desktop you still want this so not a big deal.
1
0
0
Highly recommended, actually almost mandatory, for anyone using TPM2 encrypted boot but in that case this problem does not exist in the first place.
0
0
0