When I am back at the house. Out for coffee.
Announcement
Collapse
No announcement yet.
error: prohibited by secure boot policy. Press any key to continue...
Collapse
X
-
Slava Ukraini! πΊπ¦
Windows no longer obstruct my view.
Using Kubuntu Linux since March 23, 2007.
"It is a capital mistake to theorize before one has data." - Sherlock Holmesβ
- Top
- Bottom
-
paul@DesktopPC:~$ mokutil --sb-state
SecureBoot enabled
βpaul@DesktopPC:~$ sudo dmesg | grep -Ei "secure|lockdown|efi"
[ 0.000000] efi: EFI v2.7 by American Megatrends
[ 0.000000] efi: ACPI=0xdcbe2000 ACPI 2.0=0xdcbe2014 TPMFinalLog=0xdcbac000 SMBIOS=0xdd9fd000 MEMATTR=0xd8e10118 MOKvar=0xdda2a000 INITRD=0xd6fea998 RNG=0xdb4b4018 TPMEventLog=0xdb4a8018
[ 0.000000] efi: Remove mem292: MMIO range=[0xf0000000-0xf7ffffff] (128MB) from e820 map
[ 0.000000] efi: Remove mem293: MMIO range=[0xfd200000-0xfd2fffff] (1MB) from e820 map
[ 0.000000] efi: Remove mem294: MMIO range=[0xfd400000-0xfd5fffff] (2MB) from e820 map
[ 0.000000] efi: Not removing mem295: MMIO range=[0xfea00000-0xfea0ffff] (64KB) from e820 map
[ 0.000000] efi: Remove mem296: MMIO range=[0xfeb80000-0xfec01fff] (0MB) from e820 map
[ 0.000000] efi: Not removing mem297: MMIO range=[0xfec10000-0xfec10fff] (4KB) from e820 map
[ 0.000000] efi: Not removing mem298: MMIO range=[0xfed00000-0xfed00fff] (4KB) from e820 map
[ 0.000000] efi: Not removing mem299: MMIO range=[0xfed40000-0xfed44fff] (20KB) from e820 map
[ 0.000000] efi: Not removing mem300: MMIO range=[0xfed80000-0xfed8ffff] (64KB) from e820 map
[ 0.000000] efi: Not removing mem301: MMIO range=[0xfedc2000-0xfedcffff] (56KB) from e820 map
[ 0.000000] efi: Not removing mem302: MMIO range=[0xfedd4000-0xfedd5fff] (8KB) from e820 map
[ 0.000000] efi: Remove mem303: MMIO range=[0xff000000-0xffffffff] (16MB) from e820 map
[ 0.000000] secureboot: Secure boot enabled
[ 0.000000] Kernel is locked down from EFI Secure Boot mode; see man kernel_lockdown.7
[ 0.003217] secureboot: Secure boot enabled
[ 0.004706] clocksource: refined-jiffies: mask: 0xffffffff max_cycles: 0xffffffff, max_idle_ns: 1910969940391419 ns
[ 0.663594] efi: Freeing EFI boot services memory: 80036K
[ 0.739453] efivars: Registered efivars operations
[ 1.024450] Loaded X.509 cert 'Canonical Ltd. Secure Boot Signing: 61482aa2830d0ab2ad5af10b7250da9033ddcef0'
[ 1.024461] Loaded X.509 cert 'Canonical Ltd. Secure Boot Signing (2017): 242ade75ac4a15e50d50c84b0d45ff3eae707a03'
[ 1.024479] Loaded X.509 cert 'Canonical Ltd. Secure Boot Signing (ESM 2018): 365188c1d374d6b07c3c8f240f8ef722433d6a8b'
[ 1.024489] Loaded X.509 cert 'Canonical Ltd. Secure Boot Signing (2019): c0746fd6c5da3ae827864651ad66ae47fe24b3e8'
[ 1.024500] Loaded X.509 cert 'Canonical Ltd. Secure Boot Signing (2021 v1): a8d54bbb3825cfb94fa13c9f8a594a195c107b8d'
[ 1.024511] Loaded X.509 cert 'Canonical Ltd. Secure Boot Signing (2021 v2): 4cf046892d6fd3c9a5b03f98d845f90851dc6a8c'
[ 1.024524] Loaded X.509 cert 'Canonical Ltd. Secure Boot Signing (2021 v3): 100437bb6de6e469b581e61cd66bce3ef4ed53af'
[ 1.024535] Loaded X.509 cert 'Canonical Ltd. Secure Boot Signing (Ubuntu Core 2019): c1d57b8f6b743f23ee41f4f7ee292f06eecadfb9'
[ 1.085495] integrity: Loading X.509 certificate: UEFI:db
[ 1.085529] integrity: Loaded X.509 cert 'Microsoft Corporation UEFI CA 2011: 13adbf4309bd82709c8cd54f316ed522988a1bd4'
[ 1.085531] integrity: Loading X.509 certificate: UEFI:db
[ 1.085549] integrity: Loading X.509 certificate: UEFI:db
[ 1.085563] integrity: Loaded X.509 cert 'Microsoft Corporation: Windows UEFI CA 2023: aefc5fbbbe055d8f8daa585473499417ab5a5272'
[ 1.085565] integrity: Loading X.509 certificate: UEFI:db
[ 1.085581] integrity: Loaded X.509 cert 'Microsoft UEFI CA 2023: 81aa6b3244c935bce0d6628af39827421e32497d'
[ 1.085583] integrity: Loading X.509 certificate: UEFI:db
[ 1.086701] integrity: Loading X.509 certificate: UEFI:MokListRT (MOKvar table)
[ 1.086871] integrity: Loading X.509 certificate: UEFI:MokListRT (MOKvar table)
[ 1.086983] integrity: Loaded X.509 cert 'paul-MS-7D53 Secure Boot Module Signature key: 0a8e2e72cee75efc7d60106ab062a3490b6bf215'
[ 1.087777] Lockdown: swapper/0: hibernation is restricted; see man kernel_lockdown.7
[ 1.845556] tsc: Refined TSC clocksource calibration: 3399.998 MHz
[ 4.778544] systemd[1]: Starting modprobe@efi_pstore.service - Load Kernel Module efi_pstore...
[ 4.780399] systemd[1]: systemd-hibernate-clear.service - Clear Stale Hibernate Storage Info skipped, unmet condition check ConditionPathExists=/sys/firmware/efi/efivars/HibernateLocation-8cf2644b-4b0b-428f-9387-6d876050dc67
[ 4.787243] pstore: Registered efi_pstore as persistent store backend
[ 4.789047] systemd[1]: modprobe@efi_pstore.service: Deactivated successfully.
[ 4.789190] systemd[1]: Finished modprobe@efi_pstore.service - Load Kernel Module efi_pstore.
[ 21.262054] Lockdown: systemd-logind: hibernation is restricted; see man kernel_lockdown.7
[ 21.262611] Lockdown: systemd-logind: hibernation is restricted; see man kernel_lockdown.7
[ 21.262907] Lockdown: systemd-logind: hibernation is restricted; see man kernel_lockdown.7
[ 26.137920] soundcore mac_hid sch_fq_codel lp ppdev parport msr efi_pstore dmi_sysfs autofs4 btrfs libblake2b xor raid6_pq r8169 ahci hid_generic libahci realtek usbhid hid nvme nvme_core ghash_clmulni_intel nvme_keyring nvme_auth hkdf wmi aesni_intel
[ 27.436724] Lockdown: systemd-logind: hibernation is restricted; see man kernel_lockdown.7
[ 27.438931] Lockdown: systemd-logind: hibernation is restricted; see man kernel_lockdown.7
[ 27.439121] Lockdown: systemd-logind: hibernation is restricted; see man kernel_lockdown.7
[ 27.439314] Lockdown: systemd-logind: hibernation is restricted; see man kernel_lockdown.7
[ 27.439328] Lockdown: systemd-logind: hibernation is restricted; see man kernel_lockdown.7
[ 27.452608] Lockdown: systemd-logind: hibernation is restricted; see man kernel_lockdown.7
[ 27.455145] Lockdown: systemd-logind: hibernation is restricted; see man kernel_lockdown.7
[ 27.455401] Lockdown: systemd-logind: hibernation is restricted; see man kernel_lockdown.7
[ 27.455647] Lockdown: systemd-logind: hibernation is restricted; see man kernel_lockdown.7
[ 27.455665] Lockdown: systemd-logind: hibernation is restricted; see man kernel_lockdown.7
βpaul@DesktopPC:~$ uname -r
7.0.0-29-generic
βaul@DesktopPC:~$ dpkg -l | grep linux-image
ii linux-image-6.8.0-56-generic 6.8.0-56.58+1 amd64 Signed kernel image generic
ii linux-image-7.0.0-29-generic 7.0.0-29.29 amd64 Signed kernel image generic
ii linux-image-generic 7.0.0-29.29 amd64 Generic Linux kernel image
βOutput of sudo journalctl -b | grep -Ei "secure|shim|grub|lockdown|prohibited" attached as journalctl_output.txt
journalctl_output.txt
βAttached FilesSlava Ukraini! πΊπ¦
Windows no longer obstruct my view.
Using Kubuntu Linux since March 23, 2007.
"It is a capital mistake to theorize before one has data." - Sherlock Holmesβ
- Top
- Bottom
Comment
-
looks fine there too
can we look at the GRUB configuration:
andCode:grep -E "insmod|linux|initrd" /boot/grub/grub.cfg | head -80
Code:sudo grub-install --verbose
β β β β β β β αIΠΠ¦X FΣ¨Π― αIFΞ£ β β β β β β β
- Top
- Bottom
Comment
-
Output from sudo grub-install --verbose attached as grub_output.txtCode:sudo grep -E "insmod|linux|initrd" /boot/grub/grub.cfg | head -80 [sudo: authenticate] Password: if [ "${initrdfail}" = 2 ]; then set initrdfail= elif [ "${initrdfail}" = 1 ]; then set initrdfail=2 function initrdfail { if [ -z "${initrdfail}" ]; then set initrdfail=1 save_env initrdfail insmod all_video insmod efi_gop insmod efi_uga insmod ieee1275_fb insmod vbe insmod vga insmod video_bochs insmod video_cirrus insmod part_gpt insmod btrfs insmod gfxterm insmod gettext insmod png ### BEGIN /etc/grub.d/10_linux ### set linux_gfx_mode=keep set linux_gfx_mode=keep set linux_gfx_mode=text set linux_gfx_mode=text set linux_gfx_mode=keep set linux_gfx_mode=text export linux_gfx_mode menuentry 'Ubuntu' --class ubuntu --class gnu-linux --class gnu --class os $menuentry_id_option 'gnulinux-simple-385f976d-f28d-4c25-a6c3-550b01d21e89' { set gfxpayload=$linux_gfx_mode insmod gzio if [ x$grub_platform = xxen ]; then insmod xzio; insmod lzopio; fi insmod part_gpt insmod btrfs linux /@/boot/vmlinuz-7.0.0-29-generic root=UUID=385f976d-f28d-4c25-a6c3-550b01d21e89 ro rootflags=subvol=@ quiet splash initrd /@/boot/initrd.img-7.0.0-29-generic submenu 'Advanced options for Ubuntu' $menuentry_id_option 'gnulinux-advanced-385f976d-f28d-4c25-a6c3-550b01d21e89' { menuentry 'Ubuntu, with Linux 7.0.0-29-generic' --class ubuntu --class gnu-linux --class gnu --class os $menuentry_id_option 'gnulinux-7.0.0-29-generic-advanced-385f976d-f28d-4c25-a6c3-550b01d21e89' { set gfxpayload=$linux_gfx_mode insmod gzio if [ x$grub_platform = xxen ]; then insmod xzio; insmod lzopio; fi insmod part_gpt insmod btrfs linux /@/boot/vmlinuz-7.0.0-29-generic root=UUID=385f976d-f28d-4c25-a6c3-550b01d21e89 ro rootflags=subvol=@ quiet splash initrd /@/boot/initrd.img-7.0.0-29-generic menuentry 'Ubuntu, with Linux 7.0.0-29-generic (recovery mode)' --class ubuntu --class gnu-linux --class gnu --class os $menuentry_id_option 'gnulinux-7.0.0-29-generic-recovery-385f976d-f28d-4c25-a6c3-550b01d21e89' { insmod gzio if [ x$grub_platform = xxen ]; then insmod xzio; insmod lzopio; fi insmod part_gpt insmod btrfs linux /@/boot/vmlinuz-7.0.0-29-generic root=UUID=385f976d-f28d-4c25-a6c3-550b01d21e89 ro recovery nomodeset dis_ucode_ldr rootflags=subvol=@ initrd /@/boot/initrd.img-7.0.0-29-generic menuentry 'Ubuntu, with Linux 6.8.0-56-generic' --class ubuntu --class gnu-linux --class gnu --class os $menuentry_id_option 'gnulinux-6.8.0-56-generic-advanced-385f976d-f28d-4c25-a6c3-550b01d21e89' { set gfxpayload=$linux_gfx_mode insmod gzio if [ x$grub_platform = xxen ]; then insmod xzio; insmod lzopio; fi insmod part_gpt insmod btrfs linux /@/boot/vmlinuz-6.8.0-56-generic root=UUID=385f976d-f28d-4c25-a6c3-550b01d21e89 ro rootflags=subvol=@ quiet splash initrd /@/boot/initrd.img-6.8.0-56-generic menuentry 'Ubuntu, with Linux 6.8.0-56-generic (recovery mode)' --class ubuntu --class gnu-linux --class gnu --class os $menuentry_id_option 'gnulinux-6.8.0-56-generic-recovery-385f976d-f28d-4c25-a6c3-550b01d21e89' { insmod gzio if [ x$grub_platform = xxen ]; then insmod xzio; insmod lzopio; fi insmod part_gpt insmod btrfs linux /@/boot/vmlinuz-6.8.0-56-generic root=UUID=385f976d-f28d-4c25-a6c3-550b01d21e89 ro recovery nomodeset dis_ucode_ldr rootflags=subvol=@ initrd /@/boot/initrd.img-6.8.0-56-generic ### END /etc/grub.d/10_linux ### ### BEGIN /etc/grub.d/10_linux_zfs ### ### END /etc/grub.d/10_linux_zfs ### ### BEGIN /etc/grub.d/20_linux_xen ### ### END /etc/grub.d/20_linux_xen ### insmod part_gpt insmod btrfs linux /@/boot/mt86+x64 insmod part_gpt insmod btrfs linux /@/boot/mt86+x64 console=ttyS0,115200 insmod part_gpt paul@DesktopPC:~$ β
grub_output.txt
Last edited by Snowhog; Aug 07, 2026, 09:37 AM.Slava Ukraini! πΊπ¦
Windows no longer obstruct my view.
Using Kubuntu Linux since March 23, 2007.
"It is a capital mistake to theorize before one has data." - Sherlock Holmesβ
- Top
- Bottom
Comment
-
Your grub-install --verbose output contains this:β
Registering with EFI: distributor = `ubuntu',
path = `\EFI\ubuntu\shimx64.efi',
ESP at hostdisk//dev/nvme1n1,gpt1.β
That is not the ESP you previously showed as /boot/efi. Your earlier parted/mount information showed:β
/dev/nvme0n1p1 -> /boot/efi
/dev/nvme1n1p1 -> second, unused ESPβ
So something is inconsistent.
More importantly: grub-install has just written to the other EFI partition
The same output says it copied:
βgrubx64.efi
shimx64.efi
mmx64.efiβ
and registered the Ubuntu boot entry against /dev/nvme1n1p1.β
please post output of these 3 :
Code:findmnt /boot/efi
Code:sudo efibootmgr -v
Code:lsblk -o NAME,FSTYPE,SIZE,MOUNTPOINTS,PARTUUID
β β β β β β β αIΠΠ¦X FΣ¨Π― αIFΞ£ β β β β β β β
- Top
- Bottom
Comment
-
Now reporting:
sudo efibootmgr -v
[sudo: authenticate] Password:
BootCurrent: 0000
Timeout: 1 seconds
BootOrder: 0000
Boot0000* Ubuntu HD(1,GPT,8a304aea-6cf7-4ea9-81bd-f8452e1e6b2c,0x800,0x100000)/\EFI\ubuntu\shimx64.efi
dp: 04 01 2a 00 01 00 00 00 00 08 00 00 00 00 00 00 00 00 10 00 00 00 00 00 ea 4a 30 8a f7 6c a9 4e 81 bd f8 45 2e 1e 6b 2c 02 02 / 04 04 34 00 5c 00 45 00 46 00 49 00 5c 00 75 00 62 00 75 00 6e 00 74 00 75 00 5c 00 73 00 68 00 69 00 6d 00 78 00 36 00 34 00 2e 00 65 00 66 00 69 00 00 00 / 7f ff 04 00β
findmnt /boot/efi
TARGET SOURCE FSTYPE OPTIONS
/boot/efi /dev/nvme1n1p1 vfat rw,relatime,fmask=0077,dmask=0077,codepage=437,ioc harset=iso8859-1,shortname=mixed,errors=remount-ro
paul@DesktopPC:~$
βsudo efibootmgr -v
BootCurrent: 0000
Timeout: 1 seconds
BootOrder: 0000
Boot0000* Ubuntu HD(1,GPT,8a304aea-6cf7-4ea9-81bd-f8452e1e6b2c,0x800,0x100000)/\EFI\ubuntu\shimx64.efi
dp: 04 01 2a 00 01 00 00 00 00 08 00 00 00 00 00 00 00 00 10 00 00 00 00 00 ea 4a 30 8a f7 6c a9 4e 81 bd f8 45 2e 1e 6b 2c 02 02 / 04 04 34 00 5c 00 45 00 46 00 49 00 5c 00 75 00 62 00 75 00 6e 00 74 00 75 00 5c 00 73 00 68 00 69 00 6d 00 78 00 36 00 34 00 2e 00 65 00 66 00 69 00 00 00 / 7f ff 04 00β
lsblk -o NAME,FSTYPE,SIZE,MOUNTPOINTS,PARTUUID
NAME FSTYPE SIZE MOUNTPOINTS PARTUUID
loop0 squashfs 13.5M /snap/canonical-livepatch/406
loop1 squashfs 74M /snap/core22/2411
loop2 squashfs 4K /snap/bare/5
loop3 squashfs 66.8M /snap/core24/1643
loop4 squashfs 257.7M /snap/firefox/8736
loop5 squashfs 531.5M /snap/gnome-42-2204/263
loop6 squashfs 614.5M /snap/gnome-46-2404/164
loop7 squashfs 91.7M /snap/gtk-common-themes/1535
loop8 squashfs 402M /snap/mesa-2404/1839
loop9 squashfs 50.1M /snap/snapd/27591
loop10 squashfs 219.9M /snap/thunderbird/1201
nvme0n1 1.8T
ββnvme0n1p1 vfat 512M 89fce8b0-6e11-4a4b-8399-a1db3ff4f759
ββnvme0n1p2 btrfs 1.8T /mnt/data 699d0ed9-f50f-40d6-a3f6-0b31bca42edf
nvme1n1 1.8T
ββnvme1n1p1 vfat 512M /boot/efi 8a304aea-6cf7-4ea9-81bd-f8452e1e6b2c
ββnvme1n1p2 btrfs 1.8T /var/snap/firefox/common/host-hunspell 11d76047-bbdb-4b1a-b821-0bcb6fe938d2
/home
/βSlava Ukraini! πΊπ¦
Windows no longer obstruct my view.
Using Kubuntu Linux since March 23, 2007.
"It is a capital mistake to theorize before one has data." - Sherlock Holmesβ
- Top
- Bottom
Comment
-
getting out of ideas here lol
can you run these 2 too ?
Code:dpkg -l | egrep 'grub-efi|grub-common|shim-signed'
Code:apt policy grub-efi-amd64-signed grub-efi-amd64 shim-signed shim
β β β β β β β αIΠΠ¦X FΣ¨Π― αIFΞ£ β β β β β β β
- Top
- Bottom
Comment
-
another thing to try:
At the GRUB menu, press c for the command line and run these suspect modules one at a time β insmod all_video, insmod gfxterm, insmod png, insmod video_bochs, etc. β to see exactly which one throws "prohibited by secure boot policy".
EDIT: even better , at GRUB , press c , and runand show the outputCode:insmod all_video
Last edited by die.boer; Aug 09, 2026, 12:01 AM.β β β β β β β αIΠΠ¦X FΣ¨Π― αIFΞ£ β β β β β β β
- Top
- Bottom
Comment
-
Error persists.Originally posted by die.boer View Postalso please check if you boot into an older kernel , if you get the error too ? (with secure boot enabled)
insmod all_video and insmod video_bochs both produce the error.Originally posted by die.boer View PostAt the GRUB menu, press c for the command line and run these suspect modules one at a time β insmod all_video, insmod gfxterm, insmod png, insmod video_bochs, etc. β to see exactly which one throws "prohibited by secure boot policy".
Slava Ukraini! πΊπ¦
Windows no longer obstruct my view.
Using Kubuntu Linux since March 23, 2007.
"It is a capital mistake to theorize before one has data." - Sherlock Holmesβ
- Top
- Bottom
Comment
-
So.....disable secure boot? There is little reason to have it turned on in this case.Originally posted by Snowhog View PostI only have Kubuntu Linux installed on this PC (Windows is gone forever).
And the error here seems to indicate that a third-party driver module -- nvidia drivers, Virtualbox drivers, etc may not be signed, or not signed properly? It might just be enough to reinstall these, and see if there are any messages or errors when DKMS is rebuilding them.
Another option might be to clear out any secure boot keys/settings in the BIOS and start from scratch, in terms of MOK and signing and all those annoyances.
Or disable secure boot, which really does little.Self-built: Asus PRIME B550M-K/Ryzen 5600GT/32Gb/Intel ARC B580 12Gb/KDE neon
HP Elitedesk 800 G3 Mini: i5-7500T(35w)/32Gb/Kubuntu LTS
HP Chromebook 14: i5-1135G7/8Gb/512Gb SSD/KDE Linuxβ
- Top
- Bottom
Comment
-
Which is what Iβll go with.Originally posted by claydoh View PostOr disable secure boot, which really does little.Slava Ukraini! πΊπ¦
Windows no longer obstruct my view.
Using Kubuntu Linux since March 23, 2007.
"It is a capital mistake to theorize before one has data." - Sherlock Holmesβ
- Top
- Bottom
Comment
Users Viewing This Topic
Collapse
There are 0 users viewing this topic.







Comment