Conversation
@archlinux I suppose the secure signing enclave will be used to make the Steam Deck able to run fully certified kernels that may pass kernel-level anti-cheat attestation, right? Great to know!
1
0
0

@csolisr @archlinux

What you are proposing doesn't exist.

The signing enclaves would move the package signing from the developer keys to a central signing key. It would avoid the current problem where users have issues with our developer keys because of outdated systems.

We could also support Secure Boot with a signed shim, but this is further down the pipeline.

1
0
0

@Foxboron @csolisr @archlinux

Basically what Morten wrote above.

Whether and to what extend Valve uses what we do is out of our hands. Generally speaking, we do hope to create broadly reusable code (as always) though.

More details about the (work on the) signing service can be gotten via the following link:
https://chaos.social/@dvzrv/113204676874021796

0
0
0
@archlinux any plans of merging alarm now that there are actual laptops that can run it properly?

RE: https://fosstodon.org/@archlinux/113212031636265114
0
0
0