Secure Boot
If you have the option to enable and enroll custom keys, it is highly recommended that you do so in order to protect your encrypted data from boot-chain attacks.
Check Hardware for OpROM signatures
Section titled “Check Hardware for OpROM signatures”Detailed Guide: Arch Wiki
Enter the following command to check for devices with OpROM: If so, look at the Detailed Guide in the Arch Wiki to determine if any Microsoft keys are used.
find /sys/devices/ -name romSetup Mode
Section titled “Setup Mode”In order for the option to enroll AstrOS’s own keys to appear, the system’s Secure Boot needs to be in Setup Mode.
To put firmware in Setup Mode, enter firmware setup utility and find an option to delete or clear certificates.
Enroll
Section titled “Enroll”To enroll the keys, navigate to the Enroll Secure Boot Keys option in Systemd-Boot.
You will receive a warning that this could soft-break your machine.
This is the previously mentioned problem of some ROMs being signed with
Microsoft’s keys.