Comment 5 for bug 1789918

Revision history for this message
Adam Conrad (adconrad) wrote : Re: /boot/vmlinux-4.17 has invalid signature

My guess is that Brad's been getting all his kernels from the ckt PPA, which means they'd all have snakeoil sigs on them instead of the archive sig. In this case, "linux-image-4.17.0-6-generic" and "linux-image-4.17.0-6-generic" aren't the same thing, cause linux-signed binaries are rebuilt when we copy to the archive.

Disabling the ckt PPA and doing an "apt-get --reinstall install <list of packages above>" will probably fix it.

In future, I imagine kernel team folks might want to add their PPA's EFI signing key to MOK on systems where they're likely to run PPA kernels.