Announcement

Collapse
No announcement yet.

error: prohibited by secure boot policy. Press any key to continue...

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

    #16
    When I am back at the house. Out for coffee.
    Windows no longer obstruct my view.
    Using Kubuntu Linux since March 23, 2007.
    "It is a capital mistake to theorize before one has data." - Sherlock Holmes

    Comment


      #17
      paul@DesktopPC:~$ mokutil --sb-state
      SecureBoot enabled

      ​paul@DesktopPC:~$ sudo dmesg | grep -Ei "secure|lockdown|efi"
      [ 0.000000] efi: EFI v2.7 by American Megatrends
      [ 0.000000] efi: ACPI=0xdcbe2000 ACPI 2.0=0xdcbe2014 TPMFinalLog=0xdcbac000 SMBIOS=0xdd9fd000 MEMATTR=0xd8e10118 MOKvar=0xdda2a000 INITRD=0xd6fea998 RNG=0xdb4b4018 TPMEventLog=0xdb4a8018
      [ 0.000000] efi: Remove mem292: MMIO range=[0xf0000000-0xf7ffffff] (128MB) from e820 map
      [ 0.000000] efi: Remove mem293: MMIO range=[0xfd200000-0xfd2fffff] (1MB) from e820 map
      [ 0.000000] efi: Remove mem294: MMIO range=[0xfd400000-0xfd5fffff] (2MB) from e820 map
      [ 0.000000] efi: Not removing mem295: MMIO range=[0xfea00000-0xfea0ffff] (64KB) from e820 map
      [ 0.000000] efi: Remove mem296: MMIO range=[0xfeb80000-0xfec01fff] (0MB) from e820 map
      [ 0.000000] efi: Not removing mem297: MMIO range=[0xfec10000-0xfec10fff] (4KB) from e820 map
      [ 0.000000] efi: Not removing mem298: MMIO range=[0xfed00000-0xfed00fff] (4KB) from e820 map
      [ 0.000000] efi: Not removing mem299: MMIO range=[0xfed40000-0xfed44fff] (20KB) from e820 map
      [ 0.000000] efi: Not removing mem300: MMIO range=[0xfed80000-0xfed8ffff] (64KB) from e820 map
      [ 0.000000] efi: Not removing mem301: MMIO range=[0xfedc2000-0xfedcffff] (56KB) from e820 map
      [ 0.000000] efi: Not removing mem302: MMIO range=[0xfedd4000-0xfedd5fff] (8KB) from e820 map
      [ 0.000000] efi: Remove mem303: MMIO range=[0xff000000-0xffffffff] (16MB) from e820 map
      [ 0.000000] secureboot: Secure boot enabled
      [ 0.000000] Kernel is locked down from EFI Secure Boot mode; see man kernel_lockdown.7
      [ 0.003217] secureboot: Secure boot enabled
      [ 0.004706] clocksource: refined-jiffies: mask: 0xffffffff max_cycles: 0xffffffff, max_idle_ns: 1910969940391419 ns
      [ 0.663594] efi: Freeing EFI boot services memory: 80036K
      [ 0.739453] efivars: Registered efivars operations
      [ 1.024450] Loaded X.509 cert 'Canonical Ltd. Secure Boot Signing: 61482aa2830d0ab2ad5af10b7250da9033ddcef0'
      [ 1.024461] Loaded X.509 cert 'Canonical Ltd. Secure Boot Signing (2017): 242ade75ac4a15e50d50c84b0d45ff3eae707a03'
      [ 1.024479] Loaded X.509 cert 'Canonical Ltd. Secure Boot Signing (ESM 2018): 365188c1d374d6b07c3c8f240f8ef722433d6a8b'
      [ 1.024489] Loaded X.509 cert 'Canonical Ltd. Secure Boot Signing (2019): c0746fd6c5da3ae827864651ad66ae47fe24b3e8'
      [ 1.024500] Loaded X.509 cert 'Canonical Ltd. Secure Boot Signing (2021 v1): a8d54bbb3825cfb94fa13c9f8a594a195c107b8d'
      [ 1.024511] Loaded X.509 cert 'Canonical Ltd. Secure Boot Signing (2021 v2): 4cf046892d6fd3c9a5b03f98d845f90851dc6a8c'
      [ 1.024524] Loaded X.509 cert 'Canonical Ltd. Secure Boot Signing (2021 v3): 100437bb6de6e469b581e61cd66bce3ef4ed53af'
      [ 1.024535] Loaded X.509 cert 'Canonical Ltd. Secure Boot Signing (Ubuntu Core 2019): c1d57b8f6b743f23ee41f4f7ee292f06eecadfb9'
      [ 1.085495] integrity: Loading X.509 certificate: UEFI:db
      [ 1.085529] integrity: Loaded X.509 cert 'Microsoft Corporation UEFI CA 2011: 13adbf4309bd82709c8cd54f316ed522988a1bd4'
      [ 1.085531] integrity: Loading X.509 certificate: UEFI:db
      [ 1.085549] integrity: Loading X.509 certificate: UEFI:db
      [ 1.085563] integrity: Loaded X.509 cert 'Microsoft Corporation: Windows UEFI CA 2023: aefc5fbbbe055d8f8daa585473499417ab5a5272'
      [ 1.085565] integrity: Loading X.509 certificate: UEFI:db
      [ 1.085581] integrity: Loaded X.509 cert 'Microsoft UEFI CA 2023: 81aa6b3244c935bce0d6628af39827421e32497d'
      [ 1.085583] integrity: Loading X.509 certificate: UEFI:db
      [ 1.086701] integrity: Loading X.509 certificate: UEFI:MokListRT (MOKvar table)
      [ 1.086871] integrity: Loading X.509 certificate: UEFI:MokListRT (MOKvar table)
      [ 1.086983] integrity: Loaded X.509 cert 'paul-MS-7D53 Secure Boot Module Signature key: 0a8e2e72cee75efc7d60106ab062a3490b6bf215'
      [ 1.087777] Lockdown: swapper/0: hibernation is restricted; see man kernel_lockdown.7
      [ 1.845556] tsc: Refined TSC clocksource calibration: 3399.998 MHz
      [ 4.778544] systemd[1]: Starting modprobe@efi_pstore.service - Load Kernel Module efi_pstore...
      [ 4.780399] systemd[1]: systemd-hibernate-clear.service - Clear Stale Hibernate Storage Info skipped, unmet condition check ConditionPathExists=/sys/firmware/efi/efivars/HibernateLocation-8cf2644b-4b0b-428f-9387-6d876050dc67
      [ 4.787243] pstore: Registered efi_pstore as persistent store backend
      [ 4.789047] systemd[1]: modprobe@efi_pstore.service: Deactivated successfully.
      [ 4.789190] systemd[1]: Finished modprobe@efi_pstore.service - Load Kernel Module efi_pstore.
      [ 21.262054] Lockdown: systemd-logind: hibernation is restricted; see man kernel_lockdown.7
      [ 21.262611] Lockdown: systemd-logind: hibernation is restricted; see man kernel_lockdown.7
      [ 21.262907] Lockdown: systemd-logind: hibernation is restricted; see man kernel_lockdown.7
      [ 26.137920] soundcore mac_hid sch_fq_codel lp ppdev parport msr efi_pstore dmi_sysfs autofs4 btrfs libblake2b xor raid6_pq r8169 ahci hid_generic libahci realtek usbhid hid nvme nvme_core ghash_clmulni_intel nvme_keyring nvme_auth hkdf wmi aesni_intel
      [ 27.436724] Lockdown: systemd-logind: hibernation is restricted; see man kernel_lockdown.7
      [ 27.438931] Lockdown: systemd-logind: hibernation is restricted; see man kernel_lockdown.7
      [ 27.439121] Lockdown: systemd-logind: hibernation is restricted; see man kernel_lockdown.7
      [ 27.439314] Lockdown: systemd-logind: hibernation is restricted; see man kernel_lockdown.7
      [ 27.439328] Lockdown: systemd-logind: hibernation is restricted; see man kernel_lockdown.7
      [ 27.452608] Lockdown: systemd-logind: hibernation is restricted; see man kernel_lockdown.7
      [ 27.455145] Lockdown: systemd-logind: hibernation is restricted; see man kernel_lockdown.7
      [ 27.455401] Lockdown: systemd-logind: hibernation is restricted; see man kernel_lockdown.7
      [ 27.455647] Lockdown: systemd-logind: hibernation is restricted; see man kernel_lockdown.7
      [ 27.455665] Lockdown: systemd-logind: hibernation is restricted; see man kernel_lockdown.7

      ​paul@DesktopPC:~$ uname -r
      7.0.0-29-generic

      ​aul@DesktopPC:~$ dpkg -l | grep linux-image
      ii linux-image-6.8.0-56-generic 6.8.0-56.58+1 amd64 Signed kernel image generic
      ii linux-image-7.0.0-29-generic 7.0.0-29.29 amd64 Signed kernel image generic
      ii linux-image-generic 7.0.0-29.29 amd64 Generic Linux kernel image

      ​Output of sudo journalctl -b | grep -Ei "secure|shim|grub|lockdown|prohibited" attached as journalctl_output.txt

      journalctl_output.txt
      Attached Files
      Windows no longer obstruct my view.
      Using Kubuntu Linux since March 23, 2007.
      "It is a capital mistake to theorize before one has data." - Sherlock Holmes

      Comment

      Users Viewing This Topic

      Collapse

      There are 0 users viewing this topic.

      Working...
      X