[Bug 1892754] Re: Unable to boot in UEFI+secure boot mode

Chris Guiver 1892754 at bugs.launchpad.net
Tue Sep 1 03:39:32 UTC 2020


The Ubuntu daily image I used in testing
(http://cdimage.ubuntu.com/ubuntu/daily-live/20200826/groovy-desktop-
arm64.iso.zsync) and matches comment #13 still fails to boot with secure
boot enabled

sony vaio svp112a1cw (i5-9400u, 4gb, intel haswell-ULT)

-  mokutil --db
https://paste.ubuntu.com/p/gdsMxpwztZ/

- mokutil --dbx
https://paste.ubuntu.com/p/3PtC2zzKfP/  (dbx)

(created on same sony device booting the ISO with secure boot disabled)

The subsequent screens I see on hitting OK are

- continue boot, enroll key from disk, enroll hash from disk
https://photos.app.goo.gl/Ve4PMQexDSfGcdWy5

- select key  (ESP or PciRoot(0)/Pci...)
https://photos.app.goo.gl/sKbVRTvbKQqCcbpz8

I have done nothing at this prompt; I just exited.

I don't own a box new enough to have secure boot so I've never learnt it
(this sony isn't mine but can use it for testing for now, but have
before now always had secure boot disabled).

Maybe for older folks like me we need a wiki walk-through page for this?

-- 
You received this bug notification because you are a member of Ubuntu
Foundations Bugs, which is subscribed to grub2 in Ubuntu.
https://bugs.launchpad.net/bugs/1892754

Title:
  Unable to boot in UEFI+secure boot mode

Status in grub2 package in Ubuntu:
  Incomplete

Bug description:
  The problem:

  Trying to install the QA daily build for Kubuntu Groovy 20200824 -
  when booting from the USB boot media I receive the following error:

  Error

  Verification failed: 
  (0x1A) security violation 

  Followed by an OK box - which when selected offers to import the SHIM
  key

  This error occurred on 2 machines running in UEFI+secure boot mode:

  1: Dell [Inspiron] 3521, (i3-3217U, 4GB, Intel HD Graphics 4000, Intel
  HM76 chipset 10/100 Mbps ethernet controller integrated on system
  board, WiFi 802.11 b/g/N, Bluetooth 4.0, 500 GB hd)

  2: Acer [Aspire] E3-111-P60S (Pent.N3530, 4GB, Intel HD Graphics,
  Realtek  RTL8111/81681/8411 GB Ethernet, Qualcomm Atheros AR9462
  Wireless, Bluetooth Atheros A315-53, 500 GB hd)

  Disabling secure boot the machines then boot normally in UEFI mode

  Will test further some of the other flavors..

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/grub2/+bug/1892754/+subscriptions



More information about the foundations-bugs mailing list