Vortrag: Secure Boot vs the Debian linux package

Debian is working toward support for UEFI Secure Boot, which requires us to generate and validate signatures on trusted components such as the boot loader and kernel. At the same time, we're working to make all our source packages build reproducible binaries. I will describe the approach I've taken to meet both requirements for the Linux kernel, and other changes in progress to improve the integrity of the running kernel.