docs: add distribution specific chain of trust warning around grub

Change-Id: Ibf30ae4f47d13785dfb03e7d7074ac4e1078938a
This commit is contained in:
Julia Kreger 2024-01-03 15:23:42 -08:00
parent 76f68582d6
commit a40e3fd5ae
1 changed files with 8 additions and 0 deletions

View File

@ -302,6 +302,14 @@ Then the following script can be used to build an ESP image:
If you use an architecture other than x86-64, you'll need to adjust the
destination paths.
.. warning::
If you are using secure boot, you *must* utilize the same SHIM and GRUB
binaries matching your distribution's kernel and ramdisk, otherwise the
Secure Boot "chain of trust" will be broken.
Additionally, if you encounter odd issues UEFI booting with virtual media
which point to the bootloader, verify the appropriate distribution matching
binaries are in use.
The resulting image should be provided via the ``driver_info/bootloader``
ironic node property in form of an image UUID or a URL: