<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<atom:link href="https://dev1galaxy.org/extern.php?action=feed&amp;tid=6209&amp;type=rss" rel="self" type="application/rss+xml" />
		<title><![CDATA[Dev1 Galaxy Forum / Live cd unable to boot with secure boot enabled]]></title>
		<link>https://dev1galaxy.org/viewtopic.php?id=6209</link>
		<description><![CDATA[The most recent posts in Live cd unable to boot with secure boot enabled.]]></description>
		<lastBuildDate>Wed, 15 Jan 2025 18:52:26 +0000</lastBuildDate>
		<generator>FluxBB</generator>
		<item>
			<title><![CDATA[Re: Live cd unable to boot with secure boot enabled]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=54094#p54094</link>
			<description><![CDATA[<p>Hi fsmithred,<br />I got around to some testing at last - sorry for the delay.<br />Unfortunataly it doesn&#039;t seem the image works:<br />While booting from a USB stick (created with dd) the computer will complain it didn&#039;t find a valid signature and not boot at all. When using a Ventoy medium, we get as far as the grub menu, whereafter - no matter which entry has been selected - the following message is displayed:</p><div class="codebox"><pre><code>error: shim_lock protocol not found.
error: you need do load the kernel first.</code></pre></div><p>Tested on two different machines with the same results. Debian boots without trouble on both of them.<br />Please let me know if there is anything else I can do!</p>]]></description>
			<author><![CDATA[dummy@example.com (Torclyn)]]></author>
			<pubDate>Wed, 15 Jan 2025 18:52:26 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=54094#p54094</guid>
		</item>
		<item>
			<title><![CDATA[Re: Live cd unable to boot with secure boot enabled]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=54009#p54009</link>
			<description><![CDATA[<p>Thanks for the quick reply!</p><p>I&#039;m downloading right now and will hopefully get to test it over the weekend.</p>]]></description>
			<author><![CDATA[dummy@example.com (Torclyn)]]></author>
			<pubDate>Fri, 10 Jan 2025 20:47:20 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=54009#p54009</guid>
		</item>
		<item>
			<title><![CDATA[Re: Live cd unable to boot with secure boot enabled]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=54008#p54008</link>
			<description><![CDATA[<p>Thanks for testing. Here&#039;s a new live iso. This one has bootx64.efi and shimx64.efi.signed in efi/boot. I made this one using refractasnapshot and had to copy the shim into the iso build tree manually. If it works, I&#039;ll work it into live-sdk so it gets into the official isos.</p><p>devuan_5_signed-test_amd64-20250110_1825.iso<br /><a href="https://distro.ibiblio.org/refracta/files/experimental/" rel="nofollow">https://distro.ibiblio.org/refracta/files/experimental/</a></p><p>sha256sum:</p><div class="codebox"><pre><code>ec458d2e023b7d6abc982c8c0f690250c562133a5b0491ced3226602d662903d  devuan_5_signed-test_amd64-20250110_1825.iso</code></pre></div>]]></description>
			<author><![CDATA[dummy@example.com (fsmithred)]]></author>
			<pubDate>Fri, 10 Jan 2025 19:04:00 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=54008#p54008</guid>
		</item>
		<item>
			<title><![CDATA[Re: Live cd unable to boot with secure boot enabled]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=54006#p54006</link>
			<description><![CDATA[<p>I can confirm that neither the Daedalus live ISO nor the netinstall seems to work on a machine with secureboot enabled. If that&#039;s of any help, I&#039;ll volunteer to test any new images - fsmithreds link above gives me a 404.</p>]]></description>
			<author><![CDATA[dummy@example.com (Torclyn)]]></author>
			<pubDate>Fri, 10 Jan 2025 17:30:05 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=54006#p54006</guid>
		</item>
		<item>
			<title><![CDATA[Re: Live cd unable to boot with secure boot enabled]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=49052#p49052</link>
			<description><![CDATA[<p>Hi, I noticed on my bios settings when secureboot is switched on another menu becomes available </p><p>where I can select forbidden devices like cdrom, usb, wake on lan (or something like that) </p><p>maybe you have that setting as well. </p><p>Generally I haven&#039;t used secureboot since I found a way to turn it off, so I&#039;m no expert.</p>]]></description>
			<author><![CDATA[dummy@example.com (GlennW)]]></author>
			<pubDate>Tue, 19 Mar 2024 22:19:42 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=49052#p49052</guid>
		</item>
		<item>
			<title><![CDATA[Re: Live cd unable to boot with secure boot enabled]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=49048#p49048</link>
			<description><![CDATA[<p>After some experiments it became clear to me that when secureboot is on, it verifies the signatures on removable media too. For some reason i thought that when SB is on it just refuses to boot from that kind of media.</p>]]></description>
			<author><![CDATA[dummy@example.com (nahkhiirmees)]]></author>
			<pubDate>Tue, 19 Mar 2024 19:41:29 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=49048#p49048</guid>
		</item>
		<item>
			<title><![CDATA[Re: Live cd unable to boot with secure boot enabled]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=46392#p46392</link>
			<description><![CDATA[<p>It seems that your iso image doesn&#039;t contain the right efi application : for secure boot with Microsoft signature, i need the efi application from /usr/lib/shim/shimx64.efi.signed (package shim-signed) and a grub efi application signed with the debian signature (package grub-efi-amd64-signed), both in the ESP partition inside the /EFI/boot/ directory</p>]]></description>
			<author><![CDATA[dummy@example.com (GuillaumeWA)]]></author>
			<pubDate>Wed, 20 Dec 2023 18:52:00 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=46392#p46392</guid>
		</item>
		<item>
			<title><![CDATA[Re: Live cd unable to boot with secure boot enabled]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=46108#p46108</link>
			<description><![CDATA[<div class="quotebox"><cite>fsmithred wrote:</cite><blockquote><div><p>Yes, it&#039;s isohybrid. I installed grub-efi-amd64-signed and shim-signed, which pulled in a couple other things. I assume the kernel is signed because there is no kernel package linux-image-*-signed, but there is an -unsigned kernel package. I did not install the -unsigned.</p><p>Edit:<br />When I get to fast internet, I&#039;ll download debian-live to compare.</p></div></blockquote></div><p>Ok, i&#039;ll look at it too</p>]]></description>
			<author><![CDATA[dummy@example.com (GuillaumeWA)]]></author>
			<pubDate>Sun, 10 Dec 2023 13:26:22 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=46108#p46108</guid>
		</item>
		<item>
			<title><![CDATA[Re: Live cd unable to boot with secure boot enabled]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=46086#p46086</link>
			<description><![CDATA[<p>Yes, it&#039;s isohybrid. I installed grub-efi-amd64-signed and shim-signed, which pulled in a couple other things. I assume the kernel is signed because there is no kernel package linux-image-*-signed, but there is an -unsigned kernel package. I did not install the -unsigned.</p><p>Edit:<br />When I get to fast internet, I&#039;ll download debian-live to compare.</p>]]></description>
			<author><![CDATA[dummy@example.com (fsmithred)]]></author>
			<pubDate>Sat, 09 Dec 2023 20:42:05 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=46086#p46086</guid>
		</item>
		<item>
			<title><![CDATA[Re: Live cd unable to boot with secure boot enabled]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=46082#p46082</link>
			<description><![CDATA[<div class="quotebox"><cite>fsmithred wrote:</cite><blockquote><div><p>I put the iso on my old website because it was easier to get there from the build host.,<br /><a href="http://distro.ibiblio.org/refracta/files/experimental/devuan_daedalus_5.0-signed-test_amd64_desktop-live.iso" rel="nofollow">http://distro.ibiblio.org/refracta/file … p-live.iso</a></p><p>sha256sum</p><div class="codebox"><pre><code>4fb0a40a6f58e358e00e940e3ac6c1112ef450dffdcb509bd0df6949041b477c  devuan_daedalus_5.0-signed-test_amd64_desktop-live.iso</code></pre></div></div></blockquote></div><p>Hello,</p><p>I tested it and it doesn&#039;t boot, i don&#039;t know your recipe, is it an hybrid iso? because my understanding is that my computer must boot in uefi with a signed efi application (with the third party market key from microsoft)</p>]]></description>
			<author><![CDATA[dummy@example.com (GuillaumeWA)]]></author>
			<pubDate>Sat, 09 Dec 2023 18:23:37 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=46082#p46082</guid>
		</item>
		<item>
			<title><![CDATA[Re: Live cd unable to boot with secure boot enabled]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=46041#p46041</link>
			<description><![CDATA[<p>I put the iso on my old website because it was easier to get there from the build host.,<br /><a href="http://distro.ibiblio.org/refracta/files/experimental/devuan_daedalus_5.0-signed-test_amd64_desktop-live.iso" rel="nofollow">http://distro.ibiblio.org/refracta/file … p-live.iso</a></p><p>sha256sum</p><div class="codebox"><pre><code>4fb0a40a6f58e358e00e940e3ac6c1112ef450dffdcb509bd0df6949041b477c  devuan_daedalus_5.0-signed-test_amd64_desktop-live.iso</code></pre></div>]]></description>
			<author><![CDATA[dummy@example.com (fsmithred)]]></author>
			<pubDate>Fri, 08 Dec 2023 16:35:48 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=46041#p46041</guid>
		</item>
		<item>
			<title><![CDATA[Re: Live cd unable to boot with secure boot enabled]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=46030#p46030</link>
			<description><![CDATA[<div class="quotebox"><cite>fsmithred wrote:</cite><blockquote><div><p>If I make a desktop-live iso with signed grub and kernel, will you test it for me? I am unable to test secure boot.<br />I could have it ready in a day or two and post a link here.</p><p>Thanks.</p></div></blockquote></div><p>Ok, I will test it, my guess is that you will need the shim package from debian (signed with a Microsoft&#039;s key?). I read that Ubuntu manages to boot with only the efi application signed while Fedora uses a chain of trust with everything signed from efi to loaded modules (you can see the status of secure boot on freebsd with thoose details <a href="https://wiki.freebsd.org/SecureBoot" rel="nofollow">https://wiki.freebsd.org/SecureBoot</a>)</p>]]></description>
			<author><![CDATA[dummy@example.com (GuillaumeWA)]]></author>
			<pubDate>Fri, 08 Dec 2023 08:00:36 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=46030#p46030</guid>
		</item>
		<item>
			<title><![CDATA[Re: Live cd unable to boot with secure boot enabled]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=46014#p46014</link>
			<description><![CDATA[<p>If I make a desktop-live iso with signed grub and kernel, will you test it for me? I am unable to test secure boot.<br />I could have it ready in a day or two and post a link here.</p><p>Thanks.</p>]]></description>
			<author><![CDATA[dummy@example.com (fsmithred)]]></author>
			<pubDate>Thu, 07 Dec 2023 21:55:43 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=46014#p46014</guid>
		</item>
		<item>
			<title><![CDATA[Re: Live cd unable to boot with secure boot enabled]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=46011#p46011</link>
			<description><![CDATA[<p>Too bad, I thought it might work. I do disable Secure Boot on every computer I take my hands on.</p>]]></description>
			<author><![CDATA[dummy@example.com (rolfie)]]></author>
			<pubDate>Thu, 07 Dec 2023 18:50:37 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=46011#p46011</guid>
		</item>
		<item>
			<title><![CDATA[Re: Live cd unable to boot with secure boot enabled]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=46004#p46004</link>
			<description><![CDATA[<div class="quotebox"><cite>GuillaumeWA wrote:</cite><blockquote><div><div class="quotebox"><cite>rolfie wrote:</cite><blockquote><div><p>Try the netinstall ...</p></div></blockquote></div><p>Thank you, I will try to boot the netinstall</p></div></blockquote></div><p>=&gt; It doesn&#039;t boot</p>]]></description>
			<author><![CDATA[dummy@example.com (GuillaumeWA)]]></author>
			<pubDate>Thu, 07 Dec 2023 14:37:16 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=46004#p46004</guid>
		</item>
	</channel>
</rss>
