We should now use the "new" uki key from the BLS spec in Type 1 configs when referencing a UKI. See: https://uapi-group.org/specifications/specs/boot_loader_specification/#type-1-boot-loader-entry-keys
To not break updates, we should still accept configs using the efi key but newly generated configs should use the uki key only.
Both systemd-boot and the grub-cc build should support that now.
From https://discussion.fedoraproject.org/t/f45-change-proposal-grub-efi-for-confidential-computing-self-contained/193574/7
We should now use the "new"
ukikey from the BLS spec in Type 1 configs when referencing a UKI. See: https://uapi-group.org/specifications/specs/boot_loader_specification/#type-1-boot-loader-entry-keysTo not break updates, we should still accept configs using the
efikey but newly generated configs should use theukikey only.Both systemd-boot and the grub-cc build should support that now.
From https://discussion.fedoraproject.org/t/f45-change-proposal-grub-efi-for-confidential-computing-self-contained/193574/7