On 07/08/2017 12:16 PM, Max wrote:
> Hello,
> How to check if BIOS require digital signatures on BIOS firmware updates?
>
IIRC, a firmware setup menu that has an 'anti-rollback' protection
setting (to prevent earlier firmware versions from being accepted)
should have signature verification.
As of 2012 the UEFI spec did not require this feature. I believe this
has changed since then -- you can look for such a requirement at
http://www.uefi.org/specifications .
You will probably get a more definitive answer for this type of question
if you ask the Coreboot and Libreboot communities, as they regularly
deal with such protection measures.
--
Chris Laprise,
tas...@openmailbox.org
https://twitter.com/ttaskett
PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886