It is really frustrating that they do not ship checksums for immutable sections of the UEFI image, as this would require almost no effort on their part [1]. Of course enterprise out of the extreme HAP universe doesn't care because it won't invest the effort to image their chips.<p>[1] <a href="https://github.com/LongSoft/UEFITool" rel="nofollow">https://github.com/LongSoft/UEFITool</a>