Update variables #
This guide shows how to update Secure Boot variables ( PK, KEK, db, and dbx) after provisioning. You can either replace a variable completely or append a new value. Note that appending does not work for PK.
You can update a Secure Boot variable from your own OS package. For example,
one deployment option would be to periodically download .auth
files and apply
them as shown here.