doc: uefi: enhance anti-rollback documentation
authorMasahisa Kojima <masahisa.kojima@linaro.org>
Thu, 22 Jun 2023 08:06:29 +0000 (17:06 +0900)
committerHeinrich Schuchardt <heinrich.schuchardt@canonical.com>
Sat, 15 Jul 2023 09:20:41 +0000 (11:20 +0200)
commit345a8b15acf228c4a429f6569c34cbc0232e76eb
tree385c25c3bd11311d53cc32f218a59e0303bed8c4
parenta12b36434d822ef1c4f6631314a8ea229e68c520
doc: uefi: enhance anti-rollback documentation

To enforce anti-rollback to any older version, dtb must be
always update manually. This should be described in the
documentation.

This commit also adds the recommendation that secure system should not
enable the fdt command because lowest-supported-version
property in device tree can be changed by fdt command.

Reviewed-by: Ilias Apalodimas <ilias.apalodimas@linaro.org>
Signed-off-by: Masahisa Kojima <masahisa.kojima@linaro.org>
doc/develop/uefi/uefi.rst