Open wesinator opened 7 years ago
I'll take that into consideration. Thanks. Meanwhile, you can check /sys/firmware/efi/efivars/MokSBStateRT-* for the validation state.
There is no MokSBState file (Ubuntu 16.04)
MokSBStateRT only exists if MoKSBState is set.
Add a
--validation-state | -v
command line option to show the current shim validation process state (enabled or disabled).If I understand correctly, the validation state is different than the sb-state; sb-state can be
SecureBoot enabled
even if the shim validation is disabled (https://askubuntu.com/questions/831574/re-enable-secure-boot-mok-secure-boot).