Iustin Pop, 2012-01-09 19:57+0100:
> Hmm, I might misunderstand this, but wouldn't just the grub binary need
> to be signed? And this binary then would parse the grub.cfg file and
> allow various kernels to boot.

Negative. Or rather, at least not the way GRUB currently works, since it
embeds in its core image just the modules required to access the file
system where it will find its configuration and all its other modules.

