If i installed Kubuntu with secure boot disabled, will switching it on work as intended?
Announcement
Collapse
No announcement yet.
secure boot
Collapse
X
-
Tags: None
- Top
- Bottom
-
You still there? No one chimed in yet.
I've never tried it. I can at least give you something to think about.
It should work OK. the Kubuntu installer should automatically install the Microsoft-signed Shim shimx64.efi and signed kernels during setup, even if secure boot is off at the time.
When you boot Kubuntu with Secure Boot ON, your firmware loads/accesses the Shim,
which then checks the signature of your Linux bootloader grubx64.efi and verifies it
with a secondary key provided by your Kubuntu/Ubuntu distribution, and boots Kubuntu.
At first, I was thinking that after turning secure boot on, you might have to re-install GRUB (sudo grub-install) so it catches the secure boot's Shim,
but that should NOT be necessary in many cases. (There is the issue of being booted into Kubuntu so you could even issue that command ... or chrooting ...)
I did some quick searching and found some stuff that could mess things up.
If you use open-source drivers, graphic drivers, etc., there should be no problem.
If, however, you use 3rd-party proprietary drivers (graphics, WiFi, etc.), you could have a problem (that code would be unsigned).
The fix would involve looking into MOK, Machine Owner Keys, and it seems fixable.
(I did ask AI about MOK, and its response was clear (if it is correct!).)Last edited by Qqmike; Jun 29, 2026, 11:06 AM.An intellectual says a simple thing in a hard way. An artist says a hard thing in a simple way. Charles Bukowski
- Top
- Bottom
-
In most cases, yes. Kubuntu supports Secure Boot, so installing it with Secure Boot disabled doesn't usually prevent it from working later if you enable it in your firmware.
Whether it boots successfully depends on what has been installed since then:
A standard Kubuntu installation using the default signed bootloader and Ubuntu-supplied kernel should normally boot fine with Secure Boot enabled.
If you've installed unsigned kernel modules (for example, some third-party drivers, VirtualBox modules, NVIDIA drivers installed outside the Ubuntu packages, or custom-built kernel modules), Secure Boot may prevent those modules from loading unless they're signed or enrolled via MOK (Machine Owner Key).
If you've replaced the bootloader or are using a custom kernel, Secure Boot may also prevent the system from booting until the necessary components are signed.
So if the installation is relatively stock, it's generally safe to enable Secure Boot after installation. If the system has been customized, it's worth checking what third-party modules or boot components are in use first.
ʟɨռʊӼ ʄօʀ ʟɨʄɛ
- Top
- Bottom
Comment
Users Viewing This Topic
Collapse
There are 0 users viewing this topic.




Comment