Secure boot instructions for Ghaf 26.02.1 ->

Ghaf provides images with a signed UEFI, which means they can be booted with secure boot turned on. The key material for enrollment can be found in ghaf-infra-pki repo.

Required steps vary between UEFI implementations, but generally you should turn on secure boot, and get it into setup mode.

To enroll the keys into your machine, run the enrollment script:

nix run github:tiiuae/ghaf-infra-pki/213842#enroll-secureboot-keys