Just noticed that today’s update brought in a new shim.efi and a few new related packages: may we now enable secure-boot even with Nvidia, VBox and the like without going out of our way to sign kernel modules? Or is a special procedure still required?
The new packages I noticed include:
pesign
pesign-obs-integration
kernel-pv-devel
kernel-syms
an update to mozilla-nss-tools
and an update to dkms from X11:Bumblebee