Latest kernel updates forced MOK key enrollment due to nvidia?

Jeffrey Walton noloader at gmail.com
Fri May 2 13:37:15 UTC 2025


Hi Everyone,

I'm running Ubuntu 24.04, x86_64, fully patched. I have the regular
and HWE kernels installed (two packages, so I can fallback if needed).

An `apt full-upgrade` brought in new kernels, and also brought in
nvidia packages. The nvidia packages was unusual. It was the first
time it happened. Now I am being prompted to enroll a MOK key because
Secure Boot is enabled.

I don't want nvidia components tainting my kernel. And I don't want to
dick around with MOK keys.

My question is, how do I back out of this transaction?

Jeff

-----

$ sudo lspci
00:00.0 Host bridge: Intel Corporation 8th Gen Core Processor Host
Bridge/DRAM Registers (rev 07)
00:01.0 PCI bridge: Intel Corporation 6th-10th Gen Core Processor PCIe
Controller (x16) (rev 07)
00:02.0 VGA compatible controller: Intel Corporation CoffeeLake-S GT2
[UHD Graphics 630]
00:08.0 System peripheral: Intel Corporation Xeon E3-1200 v5/v6 /
E3-1500 v5 / 6th/7th/8th Gen Core Processor Gaussian Mixture Model
00:14.0 USB controller: Intel Corporation 200 Series/Z370 Chipset
Family USB 3.0 xHCI Controller
00:16.0 Communication controller: Intel Corporation 200 Series PCH CSME HECI #1
00:17.0 SATA controller: Intel Corporation 200 Series PCH SATA
controller [AHCI mode]
00:1c.0 PCI bridge: Intel Corporation 200 Series PCH PCI Express Root
Port #2 (rev f0)
00:1c.2 PCI bridge: Intel Corporation 200 Series PCH PCI Express Root
Port #3 (rev f0)
00:1c.3 PCI bridge: Intel Corporation 200 Series PCH PCI Express Root
Port #4 (rev f0)
00:1c.4 PCI bridge: Intel Corporation 200 Series PCH PCI Express Root
Port #5 (rev f0)
00:1d.0 PCI bridge: Intel Corporation 200 Series PCH PCI Express Root
Port #9 (rev f0)
00:1e.0 Signal processing controller: Intel Corporation 200
Series/Z370 Chipset Family Serial IO UART Controller #0
00:1f.0 ISA bridge: Intel Corporation Z370 Chipset LPC/eSPI Controller
00:1f.2 Memory controller: Intel Corporation 200 Series/Z370 Chipset
Family Power Management Controller
00:1f.3 Audio device: Intel Corporation 200 Series PCH HD Audio
00:1f.4 SMBus: Intel Corporation 200 Series/Z370 Chipset Family SMBus Controller
02:00.0 USB controller: ASMedia Technology Inc. ASM1142 USB 3.1 Host Controller
03:00.0 Network controller: Qualcomm Atheros QCA9377 802.11ac Wireless
Network Adapter (rev 31)
04:00.0 Ethernet controller: Qualcomm Atheros Killer E2400 Gigabit
Ethernet Controller (rev 10)
70:00.0 Non-Volatile memory controller: Toshiba Corporation XG5 NVMe
SSD Controller

-----

$ cat /var/log/apt/history.log

Start-Date: 2025-05-02  09:11:39
Requested-By: jwalton (1000)

Install: linux-modules-extra-5.15.0-139-generic:amd64 (5.15.0-139.149,
automatic), linux-headers-5.15.0-139-generic:amd64 (5.15.0-139.149,
automatic), linux-modules-6.8.0-59-generic:amd64 (6.8.0-59.61~22.04.1,
automatic), linux-headers-5.15.0-139:amd64 (5.15.0-139.149,
automatic), linux-image-6.8.0-59-generic:amd64 (6.8.0-59.61~22.04.1,
automatic), nvidia-firmware-535-535.230.02:amd64
(535.230.02-0ubuntu0.22.04.1, automatic), libnvidia-egl-wayland1:amd64
(1:1.1.9-1.1ubuntu0.1, automatic),
linux-image-5.15.0-139-generic:amd64 (5.15.0-139.149, automatic),
linux-modules-extra-6.8.0-59-generic:amd64 (6.8.0-59.61~22.04.1,
automatic), linux-modules-5.15.0-139-generic:amd64 (5.15.0-139.149,
automatic)

Upgrade: libnvidia-common-535:amd64 (535.183.01-0ubuntu0.22.04.1,
535.230.02-0ubuntu0.22.04.1), libnvidia-fbc1-535:amd64
(535.183.01-0ubuntu0.22.04.1, 535.230.02-0ubuntu0.22.04.1),
libnvidia-gl-535:amd64 (535.183.01-0ubuntu0.22.04.1,
535.230.02-0ubuntu0.22.04.1), linux-headers-generic:amd64
(5.15.0.138.134, 5.15.0.139.135), libnvidia-extra-535:amd64
(535.183.01-0ubuntu0.22.04.1, 535.230.02-0ubuntu0.22.04.1),
nvidia-compute-utils-535:amd64 (535.183.01-0ubuntu0.22.04.1,
535.230.02-0ubuntu0.22.04.1), nvidia-dkms-535:amd64
(535.183.01-0ubuntu0.22.04.1, 535.230.02-0ubuntu0.22.04.1),
nvidia-driver-535:amd64 (535.183.01-0ubuntu0.22.04.1,
535.230.02-0ubuntu0.22.04.1), libnvidia-encode-535:amd64
(535.183.01-0ubuntu0.22.04.1, 535.230.02-0ubuntu0.22.04.1),
nvidia-utils-535:amd64 (535.183.01-0ubuntu0.22.04.1,
535.230.02-0ubuntu0.22.04.1), xserver-xorg-video-nvidia-535:amd64
(535.183.01-0ubuntu0.22.04.1, 535.230.02-0ubuntu0.22.04.1),
linux-image-generic-hwe-22.04:amd64 (6.8.0-58.60~22.04.1,
6.8.0-59.61~22.04.1), libnvidia-decode-535:amd64
(535.183.01-0ubuntu0.22.04.1, 535.230.02-0ubuntu0.22.04.1),
nvidia-kernel-common-535:amd64 (535.183.01-0ubuntu0.22.04.1,
535.230.02-0ubuntu0.22.04.1), linux-image-generic:amd64
(5.15.0.138.134, 5.15.0.139.135), libnvidia-cfg1-535:amd64
(535.183.01-0ubuntu0.22.04.1, 535.230.02-0ubuntu0.22.04.1),
nvidia-kernel-source-535:amd64 (535.183.01-0ubuntu0.22.04.1,
535.230.02-0ubuntu0.22.04.1), libnvidia-compute-535:amd64
(535.183.01-0ubuntu0.22.04.1, 535.230.02-0ubuntu0.22.04.1),
linux-libc-dev:amd64 (5.15.0-138.148, 5.15.0-139.149)

Remove: nvidia-firmware-535-535.183.01:amd64 (535.183.01-0ubuntu0.22.04.1)



More information about the ubuntu-users mailing list