Verifies signed boot components. Unsigned out-of-tree kernel modules (commonly GPU drivers) fail to load.

See the Shielded VM documentation.