<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<atom:link href="https://dev1galaxy.org/extern.php?action=feed&amp;tid=5116&amp;type=rss" rel="self" type="application/rss+xml" />
		<title><![CDATA[Dev1 Galaxy Forum / New ThinkPads will not boot Linux by default]]></title>
		<link>https://dev1galaxy.org/viewtopic.php?id=5116</link>
		<description><![CDATA[The most recent posts in New ThinkPads will not boot Linux by default.]]></description>
		<lastBuildDate>Sat, 09 Jul 2022 09:50:23 +0000</lastBuildDate>
		<generator>FluxBB</generator>
		<item>
			<title><![CDATA[Re: New ThinkPads will not boot Linux by default]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=36588#p36588</link>
			<description><![CDATA[<p><a href="https://www.rodsbooks.com/efi-bootloaders/controlling-sb.html" rel="nofollow">https://www.rodsbooks.com/efi-bootloade … ng-sb.html</a></p>]]></description>
			<author><![CDATA[dummy@example.com (Head_on_a_Stick)]]></author>
			<pubDate>Sat, 09 Jul 2022 09:50:23 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=36588#p36588</guid>
		</item>
		<item>
			<title><![CDATA[Re: New ThinkPads will not boot Linux by default]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=36587#p36587</link>
			<description><![CDATA[<div class="quotebox"><cite>Head_on_a_Stick wrote:</cite><blockquote><div><div class="quotebox"><cite>kyuss wrote:</cite><blockquote><div><p>But this can be disabled?</p></div></blockquote></div><p>The user can disable 3rd party certificates, yes. I&#039;ve removed all manufacturer-supplied certificates from my machine and just use a single certificate I created.</p><p>Some devices (usually discrete GPUs) can require the official Microsoft certificate to be allowed for their pre-installed firmware but the hash can be read from the TPM chip and enrolled into the SecureBoot database. Or so I have read :-)</p><div class="quotebox"><cite>kyuss wrote:</cite><blockquote><div><p>is the option in the bios to disable secure boot no longer available?</p></div></blockquote></div><p>The seems to be present in the PDF to which I linked in the OP. So far.</p></div></blockquote></div><p>Where can i read/learn about user created certificates, what would be the best source in your opinion?</p>]]></description>
			<author><![CDATA[dummy@example.com (kyuss)]]></author>
			<pubDate>Sat, 09 Jul 2022 09:48:44 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=36587#p36587</guid>
		</item>
		<item>
			<title><![CDATA[Re: New ThinkPads will not boot Linux by default]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=36586#p36586</link>
			<description><![CDATA[<div class="quotebox"><cite>kyuss wrote:</cite><blockquote><div><p>But this can be disabled?</p></div></blockquote></div><p>The user can disable 3rd party certificates, yes. I&#039;ve removed all manufacturer-supplied certificates from my machine and just use a single certificate I created.</p><p>Some devices (usually discrete GPUs) can require the official Microsoft certificate to be allowed for their pre-installed firmware but the hash can be read from the TPM chip and enrolled into the SecureBoot database. Or so I have read :-)</p><div class="quotebox"><cite>kyuss wrote:</cite><blockquote><div><p>is the option in the bios to disable secure boot no longer available?</p></div></blockquote></div><p>The seems to be present in the PDF to which I linked in the OP. So far.</p>]]></description>
			<author><![CDATA[dummy@example.com (Head_on_a_Stick)]]></author>
			<pubDate>Sat, 09 Jul 2022 09:45:29 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=36586#p36586</guid>
		</item>
		<item>
			<title><![CDATA[Re: New ThinkPads will not boot Linux by default]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=36585#p36585</link>
			<description><![CDATA[<p>But this can be disabled? So i have read. Is it a case of a certain threat model in regards to not having secure boot enabled? And is the option in the bios to disable secure boot no longer available?</p>]]></description>
			<author><![CDATA[dummy@example.com (kyuss)]]></author>
			<pubDate>Sat, 09 Jul 2022 09:36:10 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=36585#p36585</guid>
		</item>
		<item>
			<title><![CDATA[Re: New ThinkPads will not boot Linux by default]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=36584#p36584</link>
			<description><![CDATA[<p>ThinkPads preinstalled with Linux (or supplied without an operating system, as mine was) will already have 3rd party certificates enabled so I presume that would also be true for other Linux laptop vendors. Thankfully.</p>]]></description>
			<author><![CDATA[dummy@example.com (Head_on_a_Stick)]]></author>
			<pubDate>Sat, 09 Jul 2022 09:11:45 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=36584#p36584</guid>
		</item>
		<item>
			<title><![CDATA[Re: New ThinkPads will not boot Linux by default]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=36583#p36583</link>
			<description><![CDATA[<p>As an option what about the system76 machines that come preloaded with pop os? I know they are systemd but that can be fixed once the machine is in hand surely?</p>]]></description>
			<author><![CDATA[dummy@example.com (kyuss)]]></author>
			<pubDate>Sat, 09 Jul 2022 08:56:18 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=36583#p36583</guid>
		</item>
		<item>
			<title><![CDATA[Re: New ThinkPads will not boot Linux by default]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=36582#p36582</link>
			<description><![CDATA[<p>That&#039;ll most likely turn more people over to other platforms, like Chromebooks, Apple Arm, &amp; other ARM based like Raspberry Pi, or even to the new RISC machines that seem to be slowly appearing - typical MS tactics to try to keep people locked in!!!</p><p><strong>WAKE UP MANUFACTURERS</strong>, there are other Operating Systems, better than &#039;Windows&#039;, to put on your equipment.</p>]]></description>
			<author><![CDATA[dummy@example.com (Camtaf)]]></author>
			<pubDate>Sat, 09 Jul 2022 08:50:35 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=36582#p36582</guid>
		</item>
		<item>
			<title><![CDATA[Re: New ThinkPads will not boot Linux by default]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=36580#p36580</link>
			<description><![CDATA[<p>The only surprise is that this did not happen much earlier!</p>]]></description>
			<author><![CDATA[dummy@example.com (yeti)]]></author>
			<pubDate>Sat, 09 Jul 2022 06:29:12 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=36580#p36580</guid>
		</item>
		<item>
			<title><![CDATA[Re: New ThinkPads will not boot Linux by default]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=36576#p36576</link>
			<description><![CDATA[<p>What else would you expect but the tightening of the noose?</p>]]></description>
			<author><![CDATA[dummy@example.com (golinux)]]></author>
			<pubDate>Fri, 08 Jul 2022 18:43:05 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=36576#p36576</guid>
		</item>
		<item>
			<title><![CDATA[New ThinkPads will not boot Linux by default]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=36575#p36575</link>
			<description><![CDATA[<p>As of 2022 all new Lenovo machines require that the 3rd party UEFI SecureBoot certificate used by Linux distributions (including De{bi,vu}an) be authorised from the firmware (&quot;BIOS&quot;) options. No Linux installer will boot on the machines until this is done.</p><p>Reference: <a href="https://download.lenovo.com/pccbbs/mobiles_pdf/Enable_Secure_Boot_for_Linux_Secured-core_PCs.pdf" rel="nofollow">https://download.lenovo.com/pccbbs/mobi … re_PCs.pdf</a></p><p>Looks like this is a requirement enforced by Microsoft and so might apply to all manufacturers. Nice.</p>]]></description>
			<author><![CDATA[dummy@example.com (Head_on_a_Stick)]]></author>
			<pubDate>Fri, 08 Jul 2022 17:56:19 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=36575#p36575</guid>
		</item>
	</channel>
</rss>
