mokutil --sb-state reports SecureBoot enabled when it isn't

Bug #1817950 reported by mx80
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
mokutil (Ubuntu)
Fix Released
Undecided
Unassigned

Bug Description

mokutil --sb-state

says

SecureBoot enabled

But I've followed the instructions at https://wiki.ubuntu.com/UEFI/SecureBoot/DKMS to disable SecureBoot and I get the message that I'm booting in insecure made at startup. In fact, running unsigned mainline kernel.
---
ProblemType: Bug
ApportVersion: 2.20.10-0ubuntu13.2
Architecture: amd64
CurrentDesktop: ubuntu:GNOME
DistroRelease: Ubuntu 18.10
InstallationDate: Installed on 2018-12-09 (79 days ago)
InstallationMedia: Ubuntu 18.10 "Cosmic Cuttlefish" - Release amd64 (20181017.3)
Package: grub2 (not installed)
Tags: cosmic
Uname: Linux 4.20.13-042013-generic x86_64
UpgradeStatus: No upgrade log present (probably fresh install)
UserGroups: adm cdrom dip lpadmin plugdev sambashare sudo
_MarkForUpload: True

Revision history for this message
mx80 (rzach) wrote : ProcCpuinfoMinimal.txt

apport information

tags: added: apport-collected cosmic
description: updated
Revision history for this message
mx80 (rzach) wrote : ProcEnviron.txt

apport information

Revision history for this message
Mathieu Trudel-Lapierre (cyphermox) wrote :

Reassigning to mokutil and marking Fix Released:

I fixed that a few weeks ago. Mokutil reports the state it knows how to, and that was previously only checking the state of the SecureBoot-* variable, which is separate from the state that can be toggled in shim.

Now, mokutil looks at SecureBoot, SetupMode, and the MokSBStateRT variable (the one set by shim), and should display an appropriate message depending on the exact state of the system.

affects: grub2 (Ubuntu) → mokutil (Ubuntu)
Changed in mokutil (Ubuntu):
status: New → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.