On Mon, 2017-10-23 at 17:06 +0200, Didier Kryn wrote:
> I've read previously on this list that secureboot doesn't prevent
> booting from a usb key... Or did I misunderstood?
Correct, so long as the boot loader on the USB key is signed by a key
the system trusts. And you didn't disable booting from USB in the BIOS
and slap a password on it to stop people from messing with it. All the
basics of locking down a machine for an environment where people might
mess with it.