Although your stack probably does a better job on all the pieces you can control than UEFI + secure boot, the root of trust doesn't come back to hardware and that's what BootGuard is about.
I don't feel there is any work in Ubuntu for this at this time, but it's worth iterating on the conversation in the upstream tickets if you disagree. ** Changed in: fwupd (Ubuntu) Importance: Low => Wishlist ** Changed in: fwupd (Ubuntu) Status: Triaged => Opinion -- You received this bug notification because you are a member of Desktop Packages, which is subscribed to gnome-control-center in Ubuntu. https://bugs.launchpad.net/bugs/2093192 Title: I am using seccure Dasharo BIOS, but Ubuntu settings is warning me about insecurity Status in gnome-control-center: Fix Released Status in fwupd package in Ubuntu: Opinion Status in gnome-control-center package in Ubuntu: Invalid Bug description: I am using a laptop with Dasharo (coreboot+Heads), that has measured boot (it actually verifies BIOS and /boot partition integrity), but not secure boot. Secure boot is not used, because I am using measured boot. Unfortunately Ubuntu settings is warning me that Intel BootGuard is not enabled. Tha is correct, but app should check if there is another, even more secure option enabled, and should not write that hardware does not pass checks. ProblemType: Bug DistroRelease: Ubuntu 24.04 Package: gnome-control-center 1:46.4-0ubuntu0.24.04.1 ProcVersionSignature: Ubuntu 6.8.0-51.52-generic 6.8.12 Uname: Linux 6.8.0-51-generic x86_64 ApportVersion: 2.28.1-0ubuntu3.3 Architecture: amd64 CasperMD5CheckResult: pass CurrentDesktop: ubuntu:GNOME Date: Tue Jan 7 15:18:28 2025 InstallationDate: Installed on 2024-12-10 (28 days ago) InstallationMedia: Ubuntu 24.04.1 LTS "Noble Numbat" - Release amd64 (20240827.1) SourcePackage: gnome-control-center UpgradeStatus: No upgrade log present (probably fresh install) To manage notifications about this bug go to: https://bugs.launchpad.net/gnome-control-center/+bug/2093192/+subscriptions -- Mailing list: https://launchpad.net/~desktop-packages Post to : desktop-packages@lists.launchpad.net Unsubscribe : https://launchpad.net/~desktop-packages More help : https://help.launchpad.net/ListHelp