ublue-os / hwe

Fedora variants with support for ASUS devices, Nvidia devices, and Surface laptops
https://universal-blue.org/images/hwe
Apache License 2.0
176 stars 39 forks source link

[Secure Boot] Asus Image not able to boot when secure boot enabled #221

Open Tompott opened 8 months ago

Tompott commented 8 months ago

Hi ublue team!

I am using silverblue-asus-nvidia

The asus variant image will not boot with secure boot enabled and resulting errors:

error: ../../grub-core/kern/efi/sb.c:182: bad shim signature. error: ../../grub-core/loader/i386/efi/linux.c:258: you need to load the kernel first.

I tried to disable the secure boot, reset the MOK list and re-enroll the key by:

sudo mokutil --reset
ujust enroll-secure-boot-key

and enable the secure boot but nothing has changed, the errors still exist.

m2Giles commented 5 months ago

We will now start signing all of kernels with our MOK signing key