Foxboron / sbctl

:computer: :lock: :key: Secure Boot key manager
MIT License
1.35k stars 71 forks source link

sbctl won't work on Fujtsu Lifebook A574/M, BIOS would just reset ANY USER intervention of the secure boot changes #307

Open SUFandom opened 1 month ago

SUFandom commented 1 month ago

Pointers:

SUFandom commented 1 month ago

Also forgot:

IPlayZed commented 2 weeks ago

Could you provide screenshots of your UEFI setting step-by-step when doing your setup?

SUFandom commented 1 week ago

its been a while so ill recreate this again

Screenshot_20240618_233200 Screenshot_20240618_233248

i realized i disabled secure boot so went to enable it and enable setup mode/custom mode

Screenshot_20240618_233752

Screenshot_20240618_233745

after everything is done

Fujitsu BIOS says:

2024-06-18-23-38-31-327

SUFandom commented 1 week ago

basically did the instruction on the readme but only took the --microsoft flag

SUFandom commented 1 week ago

disabling the secure boot temporarily to check the chattr-ed files to see them having issues again

 [navia@fujitsu-a574m ~]$ sudo sbctl enroll-keys
[sudo] password for navia: 
‼ File is immutable: /sys/firmware/efi/efivars/KEK-8be4df61-93ca-11d2-aa0d-00e098032b8c
‼ File is immutable: /sys/firmware/efi/efivars/db-d719b2cb-3d3a-4596-a3bc-dad00e67656f
You need to chattr -i files in efivarfs
Foxboron commented 1 week ago

Which files did you sign before rebooting?