Kernel with IMA and "better" secure boot / MOK support