[Bug 1849863] Re: shim-signed does not boot on Lenovo Yoga C630 WOS with enabled Secure Boot

RussianNeuroMancer 1849863 at bugs.launchpad.net
Fri Oct 25 17:22:11 UTC 2019


> What if you set SHIM_VERBOSE in firmware, using 'sudo mokutil --set-
verbosity true' after booting with just grub?

This command fail with "This system doesn't support Secure Boot". On a
side note I found that attempt to boot with installed shim-signed fail
with both of Secure Boot enabled and disabled.

Also I guess I need to mention that Snapdragon-based laptops currently
boot only with "efi=novamap": Bug 1814982

Does it make sense to patch mokutil.c to ignore Secure Boot state (line
2413) or it expected to fail somewhere else due to issue described in
Bug 1814982?

** Changed in: shim (Ubuntu)
       Status: Incomplete => New

-- 
You received this bug notification because you are a member of Ubuntu
Foundations Bugs, which is subscribed to shim in Ubuntu.
https://bugs.launchpad.net/bugs/1849863

Title:
  shim-signed does not boot on Lenovo Yoga C630 WOS with enabled Secure
  Boot

Status in shim package in Ubuntu:
  New

Bug description:
  Hello!

  In my attempt to workaround Bug 1839317 I tried to install shim-signed
  and enable Secure Boot. Unfortunately, shim-signed binary does not
  boot for some reason (screen stay black). I want to notice that if I
  try to boot just with grub-efi-arm64-signed without shim binaries on
  esp (partition was cleaned up, then grub reinstalled) I getting
  firmware errors regarding invalid signature. So I guess when firmware
  validate shim-signed signature it is valid, but then when firmware
  trying to start shim-signed it get started but for some reason
  silently fail.

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/shim/+bug/1849863/+subscriptions



More information about the foundations-bugs mailing list