I now have an idea how to write the host firewall… Looking at network interfaces before/after installation of KVM and then white listing the new device.
Could you please make SecureBoot work as well? @onion_knight I.e. “just” as good as Debian has it.
Purpose: Usability. Boot compatibility. Let users where SecureBoot is enabled by default boot while SecureBoot stays enabled. Not require them to disable SecureBoot in the BIOS.
Non-purpose: Security.
Related: