I recompiled a new kernel and i cannot boot the new kernel when my secure boot is enable but the old kernel can.

Bug #2012183 reported by Abner Lu
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
shim (Ubuntu)
Expired
Undecided
Unassigned

Bug Description

  When I boot my new kernel with secure boot enable the following error showed :
error: bad shim signature
error: you need to load the kernel first.
Moreover, when my secure boot disable and I change to a open source Nvidia graphics card driver the boot stuck at the message :/dev/nvme1n1p2: clean, 457371/30498816 files, 16785240/121965056 blocks.

ProblemType: Bug
DistroRelease: Ubuntu 20.04
Package: shim (not installed)
Uname: Linux 6.2.7 x86_64
.proc.sys.kernel.moksbstate_disabled: Error: [Errno 2] 沒有此一檔案或目錄: '/proc/sys/kernel/moksbstate_disabled'
ApportVersion: 2.20.11-0ubuntu27.25
Architecture: amd64
BootEFIContents:
 BOOTX64.CSV
 grub.cfg
 grubx64.efi
 mmx64.efi
 shimx64.efi
CasperMD5CheckResult: skip
CurrentDesktop: ubuntu:GNOME
Date: Sun Mar 19 19:28:56 2023
InstallationDate: Installed on 2021-06-05 (652 days ago)
InstallationMedia: Ubuntu 20.04.2.0 LTS "Focal Fossa" - Release amd64 (20210209.1)
MokSBStateRT: 6 0 0 0 1
SecureBoot: 6 0 0 0 1
SourcePackage: shim
UpgradeStatus: No upgrade log present (probably fresh install)

Revision history for this message
Abner Lu (abner7124) wrote :
Revision history for this message
Heinrich Schuchardt (xypron) wrote :

Hello Abner,

for using secure boot shim must know the certificate that you used to sign the kernel. Did you enroll it?

Cf. https://wiki.ubuntu.com/UEFI/SecureBoot

Best regards

Heinrich

Changed in shim (Ubuntu):
status: New → Incomplete
Revision history for this message
Launchpad Janitor (janitor) wrote :

[Expired for shim (Ubuntu) because there has been no activity for 60 days.]

Changed in shim (Ubuntu):
status: Incomplete → Expired
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.