Announcement

Collapse
No announcement yet.

error: prohibited by secure boot policy. Press any key to continue...

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

    #16
    When I am back at the house. Out for coffee.
    Slava Ukraini! πŸ‡ΊπŸ‡¦
    Windows no longer obstruct my view.
    Using Kubuntu Linux since March 23, 2007.
    "It is a capital mistake to theorize before one has data." - Sherlock Holmes​

    Comment


      #17
      paul@DesktopPC:~$ mokutil --sb-state
      SecureBoot enabled

      ​paul@DesktopPC:~$ sudo dmesg | grep -Ei "secure|lockdown|efi"
      [ 0.000000] efi: EFI v2.7 by American Megatrends
      [ 0.000000] efi: ACPI=0xdcbe2000 ACPI 2.0=0xdcbe2014 TPMFinalLog=0xdcbac000 SMBIOS=0xdd9fd000 MEMATTR=0xd8e10118 MOKvar=0xdda2a000 INITRD=0xd6fea998 RNG=0xdb4b4018 TPMEventLog=0xdb4a8018
      [ 0.000000] efi: Remove mem292: MMIO range=[0xf0000000-0xf7ffffff] (128MB) from e820 map
      [ 0.000000] efi: Remove mem293: MMIO range=[0xfd200000-0xfd2fffff] (1MB) from e820 map
      [ 0.000000] efi: Remove mem294: MMIO range=[0xfd400000-0xfd5fffff] (2MB) from e820 map
      [ 0.000000] efi: Not removing mem295: MMIO range=[0xfea00000-0xfea0ffff] (64KB) from e820 map
      [ 0.000000] efi: Remove mem296: MMIO range=[0xfeb80000-0xfec01fff] (0MB) from e820 map
      [ 0.000000] efi: Not removing mem297: MMIO range=[0xfec10000-0xfec10fff] (4KB) from e820 map
      [ 0.000000] efi: Not removing mem298: MMIO range=[0xfed00000-0xfed00fff] (4KB) from e820 map
      [ 0.000000] efi: Not removing mem299: MMIO range=[0xfed40000-0xfed44fff] (20KB) from e820 map
      [ 0.000000] efi: Not removing mem300: MMIO range=[0xfed80000-0xfed8ffff] (64KB) from e820 map
      [ 0.000000] efi: Not removing mem301: MMIO range=[0xfedc2000-0xfedcffff] (56KB) from e820 map
      [ 0.000000] efi: Not removing mem302: MMIO range=[0xfedd4000-0xfedd5fff] (8KB) from e820 map
      [ 0.000000] efi: Remove mem303: MMIO range=[0xff000000-0xffffffff] (16MB) from e820 map
      [ 0.000000] secureboot: Secure boot enabled
      [ 0.000000] Kernel is locked down from EFI Secure Boot mode; see man kernel_lockdown.7
      [ 0.003217] secureboot: Secure boot enabled
      [ 0.004706] clocksource: refined-jiffies: mask: 0xffffffff max_cycles: 0xffffffff, max_idle_ns: 1910969940391419 ns
      [ 0.663594] efi: Freeing EFI boot services memory: 80036K
      [ 0.739453] efivars: Registered efivars operations
      [ 1.024450] Loaded X.509 cert 'Canonical Ltd. Secure Boot Signing: 61482aa2830d0ab2ad5af10b7250da9033ddcef0'
      [ 1.024461] Loaded X.509 cert 'Canonical Ltd. Secure Boot Signing (2017): 242ade75ac4a15e50d50c84b0d45ff3eae707a03'
      [ 1.024479] Loaded X.509 cert 'Canonical Ltd. Secure Boot Signing (ESM 2018): 365188c1d374d6b07c3c8f240f8ef722433d6a8b'
      [ 1.024489] Loaded X.509 cert 'Canonical Ltd. Secure Boot Signing (2019): c0746fd6c5da3ae827864651ad66ae47fe24b3e8'
      [ 1.024500] Loaded X.509 cert 'Canonical Ltd. Secure Boot Signing (2021 v1): a8d54bbb3825cfb94fa13c9f8a594a195c107b8d'
      [ 1.024511] Loaded X.509 cert 'Canonical Ltd. Secure Boot Signing (2021 v2): 4cf046892d6fd3c9a5b03f98d845f90851dc6a8c'
      [ 1.024524] Loaded X.509 cert 'Canonical Ltd. Secure Boot Signing (2021 v3): 100437bb6de6e469b581e61cd66bce3ef4ed53af'
      [ 1.024535] Loaded X.509 cert 'Canonical Ltd. Secure Boot Signing (Ubuntu Core 2019): c1d57b8f6b743f23ee41f4f7ee292f06eecadfb9'
      [ 1.085495] integrity: Loading X.509 certificate: UEFI:db
      [ 1.085529] integrity: Loaded X.509 cert 'Microsoft Corporation UEFI CA 2011: 13adbf4309bd82709c8cd54f316ed522988a1bd4'
      [ 1.085531] integrity: Loading X.509 certificate: UEFI:db
      [ 1.085549] integrity: Loading X.509 certificate: UEFI:db
      [ 1.085563] integrity: Loaded X.509 cert 'Microsoft Corporation: Windows UEFI CA 2023: aefc5fbbbe055d8f8daa585473499417ab5a5272'
      [ 1.085565] integrity: Loading X.509 certificate: UEFI:db
      [ 1.085581] integrity: Loaded X.509 cert 'Microsoft UEFI CA 2023: 81aa6b3244c935bce0d6628af39827421e32497d'
      [ 1.085583] integrity: Loading X.509 certificate: UEFI:db
      [ 1.086701] integrity: Loading X.509 certificate: UEFI:MokListRT (MOKvar table)
      [ 1.086871] integrity: Loading X.509 certificate: UEFI:MokListRT (MOKvar table)
      [ 1.086983] integrity: Loaded X.509 cert 'paul-MS-7D53 Secure Boot Module Signature key: 0a8e2e72cee75efc7d60106ab062a3490b6bf215'
      [ 1.087777] Lockdown: swapper/0: hibernation is restricted; see man kernel_lockdown.7
      [ 1.845556] tsc: Refined TSC clocksource calibration: 3399.998 MHz
      [ 4.778544] systemd[1]: Starting modprobe@efi_pstore.service - Load Kernel Module efi_pstore...
      [ 4.780399] systemd[1]: systemd-hibernate-clear.service - Clear Stale Hibernate Storage Info skipped, unmet condition check ConditionPathExists=/sys/firmware/efi/efivars/HibernateLocation-8cf2644b-4b0b-428f-9387-6d876050dc67
      [ 4.787243] pstore: Registered efi_pstore as persistent store backend
      [ 4.789047] systemd[1]: modprobe@efi_pstore.service: Deactivated successfully.
      [ 4.789190] systemd[1]: Finished modprobe@efi_pstore.service - Load Kernel Module efi_pstore.
      [ 21.262054] Lockdown: systemd-logind: hibernation is restricted; see man kernel_lockdown.7
      [ 21.262611] Lockdown: systemd-logind: hibernation is restricted; see man kernel_lockdown.7
      [ 21.262907] Lockdown: systemd-logind: hibernation is restricted; see man kernel_lockdown.7
      [ 26.137920] soundcore mac_hid sch_fq_codel lp ppdev parport msr efi_pstore dmi_sysfs autofs4 btrfs libblake2b xor raid6_pq r8169 ahci hid_generic libahci realtek usbhid hid nvme nvme_core ghash_clmulni_intel nvme_keyring nvme_auth hkdf wmi aesni_intel
      [ 27.436724] Lockdown: systemd-logind: hibernation is restricted; see man kernel_lockdown.7
      [ 27.438931] Lockdown: systemd-logind: hibernation is restricted; see man kernel_lockdown.7
      [ 27.439121] Lockdown: systemd-logind: hibernation is restricted; see man kernel_lockdown.7
      [ 27.439314] Lockdown: systemd-logind: hibernation is restricted; see man kernel_lockdown.7
      [ 27.439328] Lockdown: systemd-logind: hibernation is restricted; see man kernel_lockdown.7
      [ 27.452608] Lockdown: systemd-logind: hibernation is restricted; see man kernel_lockdown.7
      [ 27.455145] Lockdown: systemd-logind: hibernation is restricted; see man kernel_lockdown.7
      [ 27.455401] Lockdown: systemd-logind: hibernation is restricted; see man kernel_lockdown.7
      [ 27.455647] Lockdown: systemd-logind: hibernation is restricted; see man kernel_lockdown.7
      [ 27.455665] Lockdown: systemd-logind: hibernation is restricted; see man kernel_lockdown.7

      ​paul@DesktopPC:~$ uname -r
      7.0.0-29-generic

      ​aul@DesktopPC:~$ dpkg -l | grep linux-image
      ii linux-image-6.8.0-56-generic 6.8.0-56.58+1 amd64 Signed kernel image generic
      ii linux-image-7.0.0-29-generic 7.0.0-29.29 amd64 Signed kernel image generic
      ii linux-image-generic 7.0.0-29.29 amd64 Generic Linux kernel image

      ​Output of sudo journalctl -b | grep -Ei "secure|shim|grub|lockdown|prohibited" attached as journalctl_output.txt

      journalctl_output.txt
      ​
      Attached Files
      Slava Ukraini! πŸ‡ΊπŸ‡¦
      Windows no longer obstruct my view.
      Using Kubuntu Linux since March 23, 2007.
      "It is a capital mistake to theorize before one has data." - Sherlock Holmes​

      Comment


        #18
        looks fine there too
        can we look at the GRUB configuration:
        Code:
        grep -E "insmod|linux|initrd" /boot/grub/grub.cfg | head -80
        and

        Code:
        sudo grub-install --verbose
        ▁ β–‚ β–„ β–… β–† β–‡ β–ˆ α„‚IПЦX FΣ¨Π― α„‚IFΞ£ β–ˆ β–‡ β–† β–… β–„ β–‚ ▁

        Comment


          #19
          Code:
          sudo grep -E "insmod|linux|initrd" /boot/grub/grub.cfg | head -80
          [sudo: authenticate] Password:        
          if [ "${initrdfail}" = 2 ]; then
             set initrdfail=
          elif [ "${initrdfail}" = 1 ]; then
                set initrdfail=2
          function initrdfail {
                if [ -z "${initrdfail}" ]; then
                  set initrdfail=1
                save_env initrdfail
              insmod all_video
              insmod efi_gop
              insmod efi_uga
              insmod ieee1275_fb
              insmod vbe
              insmod vga
              insmod video_bochs
              insmod video_cirrus
          insmod part_gpt
          insmod btrfs
            insmod gfxterm
            insmod gettext
            insmod png
          ### BEGIN /etc/grub.d/10_linux ###
                set linux_gfx_mode=keep
                  set linux_gfx_mode=keep
                  set linux_gfx_mode=text
                set linux_gfx_mode=text
              set linux_gfx_mode=keep
            set linux_gfx_mode=text
          export linux_gfx_mode
          menuentry 'Ubuntu' --class ubuntu --class gnu-linux --class gnu --class os $menuentry_id_option 'gnulinux-simple-385f976d-f28d-4c25-a6c3-550b01d21e89' {
                  set gfxpayload=$linux_gfx_mode
                  insmod gzio
                  if [ x$grub_platform = xxen ]; then insmod xzio; insmod lzopio; fi
                  insmod part_gpt
                  insmod btrfs
                  linux   /@/boot/vmlinuz-7.0.0-29-generic root=UUID=385f976d-f28d-4c25-a6c3-550b01d21e89 ro rootflags=subvol=@  quiet splash
                  initrd  /@/boot/initrd.img-7.0.0-29-generic
          submenu 'Advanced options for Ubuntu' $menuentry_id_option 'gnulinux-advanced-385f976d-f28d-4c25-a6c3-550b01d21e89' {
                  menuentry 'Ubuntu, with Linux 7.0.0-29-generic' --class ubuntu --class gnu-linux --class gnu --class os $menuentry_id_option 'gnulinux-7.0.0-29-generic-advanced-385f976d-f28d-4c25-a6c3-550b01d21e89' {
                          set gfxpayload=$linux_gfx_mode
                          insmod gzio
                          if [ x$grub_platform = xxen ]; then insmod xzio; insmod lzopio; fi
                          insmod part_gpt
                          insmod btrfs
                          linux   /@/boot/vmlinuz-7.0.0-29-generic root=UUID=385f976d-f28d-4c25-a6c3-550b01d21e89 ro rootflags=subvol=@  quiet splash
                          initrd  /@/boot/initrd.img-7.0.0-29-generic
                  menuentry 'Ubuntu, with Linux 7.0.0-29-generic (recovery mode)' --class ubuntu --class gnu-linux --class gnu --class os $menuentry_id_option 'gnulinux-7.0.0-29-generic-recovery-385f976d-f28d-4c25-a6c3-550b01d21e89' {
                          insmod gzio
                          if [ x$grub_platform = xxen ]; then insmod xzio; insmod lzopio; fi
                          insmod part_gpt
                          insmod btrfs
                          linux   /@/boot/vmlinuz-7.0.0-29-generic root=UUID=385f976d-f28d-4c25-a6c3-550b01d21e89 ro recovery nomodeset dis_ucode_ldr rootflags=subvol=@
                          initrd  /@/boot/initrd.img-7.0.0-29-generic
                  menuentry 'Ubuntu, with Linux 6.8.0-56-generic' --class ubuntu --class gnu-linux --class gnu --class os $menuentry_id_option 'gnulinux-6.8.0-56-generic-advanced-385f976d-f28d-4c25-a6c3-550b01d21e89' {
                          set gfxpayload=$linux_gfx_mode
                          insmod gzio
                          if [ x$grub_platform = xxen ]; then insmod xzio; insmod lzopio; fi
                          insmod part_gpt
                          insmod btrfs
                          linux   /@/boot/vmlinuz-6.8.0-56-generic root=UUID=385f976d-f28d-4c25-a6c3-550b01d21e89 ro rootflags=subvol=@  quiet splash
                          initrd  /@/boot/initrd.img-6.8.0-56-generic
                  menuentry 'Ubuntu, with Linux 6.8.0-56-generic (recovery mode)' --class ubuntu --class gnu-linux --class gnu --class os $menuentry_id_option 'gnulinux-6.8.0-56-generic-recovery-385f976d-f28d-4c25-a6c3-550b01d21e89' {
                          insmod gzio
                          if [ x$grub_platform = xxen ]; then insmod xzio; insmod lzopio; fi
                          insmod part_gpt
                          insmod btrfs
                          linux   /@/boot/vmlinuz-6.8.0-56-generic root=UUID=385f976d-f28d-4c25-a6c3-550b01d21e89 ro recovery nomodeset dis_ucode_ldr rootflags=subvol=@
                          initrd  /@/boot/initrd.img-6.8.0-56-generic
          ### END /etc/grub.d/10_linux ###
          ### BEGIN /etc/grub.d/10_linux_zfs ###
          ### END /etc/grub.d/10_linux_zfs ###
          ### BEGIN /etc/grub.d/20_linux_xen ###
          ### END /etc/grub.d/20_linux_xen ###
                          insmod part_gpt
                          insmod btrfs
                          linux /@/boot/mt86+x64
                          insmod part_gpt
                          insmod btrfs
                          linux /@/boot/mt86+x64 console=ttyS0,115200
                          insmod part_gpt
          paul@DesktopPC:~$
          
          ​
          Output from sudo grub-install --verbose attached as grub_output.txt

          grub_output.txt
          Last edited by Snowhog; Aug 07, 2026, 09:37 AM.
          Slava Ukraini! πŸ‡ΊπŸ‡¦
          Windows no longer obstruct my view.
          Using Kubuntu Linux since March 23, 2007.
          "It is a capital mistake to theorize before one has data." - Sherlock Holmes​

          Comment


            #20
            Your grub-install --verbose output contains this:​
            Registering with EFI: distributor = `ubuntu',
            path = `\EFI\ubuntu\shimx64.efi',
            ESP at hostdisk//dev/nvme1n1,gpt1.​


            That is not the ESP you previously showed as /boot/efi. Your earlier parted/mount information showed:​
            /dev/nvme0n1p1 -> /boot/efi
            /dev/nvme1n1p1 -> second, unused ESP​


            So something is inconsistent.

            More importantly: grub-install has just written to the other EFI partition
            The same output says it copied:
            ​grubx64.efi
            shimx64.efi
            mmx64.efi​

            and registered the Ubuntu boot entry against /dev/nvme1n1p1.​

            please post output of these 3 :
            Code:
            findmnt /boot/efi
            Code:
            sudo efibootmgr -v
            Code:
            lsblk -o NAME,FSTYPE,SIZE,MOUNTPOINTS,PARTUUID
            ▁ β–‚ β–„ β–… β–† β–‡ β–ˆ α„‚IПЦX FΣ¨Π― α„‚IFΞ£ β–ˆ β–‡ β–† β–… β–„ β–‚ ▁

            Comment


              #21
              Now reporting:

              sudo efibootmgr -v
              [sudo: authenticate] Password:
              BootCurrent: 0000
              Timeout: 1 seconds
              BootOrder: 0000
              Boot0000* Ubuntu HD(1,GPT,8a304aea-6cf7-4ea9-81bd-f8452e1e6b2c,0x800,0x100000)/\EFI\ubuntu\shimx64.efi
              dp: 04 01 2a 00 01 00 00 00 00 08 00 00 00 00 00 00 00 00 10 00 00 00 00 00 ea 4a 30 8a f7 6c a9 4e 81 bd f8 45 2e 1e 6b 2c 02 02 / 04 04 34 00 5c 00 45 00 46 00 49 00 5c 00 75 00 62 00 75 00 6e 00 74 00 75 00 5c 00 73 00 68 00 69 00 6d 00 78 00 36 00 34 00 2e 00 65 00 66 00 69 00 00 00 / 7f ff 04 00​

              findmnt /boot/efi
              TARGET SOURCE FSTYPE OPTIONS
              /boot/efi /dev/nvme1n1p1 vfat rw,relatime,fmask=0077,dmask=0077,codepage=437,ioc harset=iso8859-1,shortname=mixed,errors=remount-ro
              paul@DesktopPC:~$

              ​sudo efibootmgr -v
              BootCurrent: 0000
              Timeout: 1 seconds
              BootOrder: 0000
              Boot0000* Ubuntu HD(1,GPT,8a304aea-6cf7-4ea9-81bd-f8452e1e6b2c,0x800,0x100000)/\EFI\ubuntu\shimx64.efi
              dp: 04 01 2a 00 01 00 00 00 00 08 00 00 00 00 00 00 00 00 10 00 00 00 00 00 ea 4a 30 8a f7 6c a9 4e 81 bd f8 45 2e 1e 6b 2c 02 02 / 04 04 34 00 5c 00 45 00 46 00 49 00 5c 00 75 00 62 00 75 00 6e 00 74 00 75 00 5c 00 73 00 68 00 69 00 6d 00 78 00 36 00 34 00 2e 00 65 00 66 00 69 00 00 00 / 7f ff 04 00​

              lsblk -o NAME,FSTYPE,SIZE,MOUNTPOINTS,PARTUUID
              NAME FSTYPE SIZE MOUNTPOINTS PARTUUID
              loop0 squashfs 13.5M /snap/canonical-livepatch/406
              loop1 squashfs 74M /snap/core22/2411
              loop2 squashfs 4K /snap/bare/5
              loop3 squashfs 66.8M /snap/core24/1643
              loop4 squashfs 257.7M /snap/firefox/8736
              loop5 squashfs 531.5M /snap/gnome-42-2204/263
              loop6 squashfs 614.5M /snap/gnome-46-2404/164
              loop7 squashfs 91.7M /snap/gtk-common-themes/1535
              loop8 squashfs 402M /snap/mesa-2404/1839
              loop9 squashfs 50.1M /snap/snapd/27591
              loop10 squashfs 219.9M /snap/thunderbird/1201
              nvme0n1 1.8T
              β”œβ”€nvme0n1p1 vfat 512M 89fce8b0-6e11-4a4b-8399-a1db3ff4f759
              └─nvme0n1p2 btrfs 1.8T /mnt/data 699d0ed9-f50f-40d6-a3f6-0b31bca42edf
              nvme1n1 1.8T
              β”œβ”€nvme1n1p1 vfat 512M /boot/efi 8a304aea-6cf7-4ea9-81bd-f8452e1e6b2c
              └─nvme1n1p2 btrfs 1.8T /var/snap/firefox/common/host-hunspell 11d76047-bbdb-4b1a-b821-0bcb6fe938d2
              /home
              /​
              Slava Ukraini! πŸ‡ΊπŸ‡¦
              Windows no longer obstruct my view.
              Using Kubuntu Linux since March 23, 2007.
              "It is a capital mistake to theorize before one has data." - Sherlock Holmes​

              Comment


                #22
                getting out of ideas here lol
                can you run these 2 too ?
                Code:
                dpkg -l | egrep 'grub-efi|grub-common|shim-signed'
                Code:
                apt policy grub-efi-amd64-signed grub-efi-amd64 shim-signed shim
                ▁ β–‚ β–„ β–… β–† β–‡ β–ˆ α„‚IПЦX FΣ¨Π― α„‚IFΞ£ β–ˆ β–‡ β–† β–… β–„ β–‚ ▁

                Comment


                  #23
                  also please check if you boot into an older kernel , if you get the error too ? (with secure boot enabled)
                  ▁ β–‚ β–„ β–… β–† β–‡ β–ˆ α„‚IПЦX FΣ¨Π― α„‚IFΞ£ β–ˆ β–‡ β–† β–… β–„ β–‚ ▁

                  Comment


                    #24
                    another thing to try:
                    At the GRUB menu, press c for the command line and run these suspect modules one at a time β€” insmod all_video, insmod gfxterm, insmod png, insmod video_bochs, etc. β€” to see exactly which one throws "prohibited by secure boot policy".

                    EDIT: even better , at GRUB , press c , and run
                    Code:
                    insmod all_video
                    and show the output
                    Last edited by die.boer; Aug 09, 2026, 12:01 AM.
                    ▁ β–‚ β–„ β–… β–† β–‡ β–ˆ α„‚IПЦX FΣ¨Π― α„‚IFΞ£ β–ˆ β–‡ β–† β–… β–„ β–‚ ▁

                    Comment


                      #25
                      Originally posted by die.boer View Post
                      also please check if you boot into an older kernel , if you get the error too ? (with secure boot enabled)
                      Error persists.

                      Originally posted by die.boer View Post
                      At the GRUB menu, press c for the command line and run these suspect modules one at a time β€” insmod all_video, insmod gfxterm, insmod png, insmod video_bochs, etc. β€” to see exactly which one throws "prohibited by secure boot policy".
                      insmod all_video and insmod video_bochs both produce the error.
                      Slava Ukraini! πŸ‡ΊπŸ‡¦
                      Windows no longer obstruct my view.
                      Using Kubuntu Linux since March 23, 2007.
                      "It is a capital mistake to theorize before one has data." - Sherlock Holmes​

                      Comment


                        #26
                        Originally posted by Snowhog View Post
                        I only have Kubuntu Linux installed on this PC (Windows is gone forever).
                        So.....disable secure boot? There is little reason to have it turned on in this case.

                        And the error here seems to indicate that a third-party driver module -- nvidia drivers, Virtualbox drivers, etc may not be signed, or not signed properly? It might just be enough to reinstall these, and see if there are any messages or errors when DKMS is rebuilding them.


                        Another option might be to clear out any secure boot keys/settings in the BIOS and start from scratch, in terms of MOK and signing and all those annoyances.


                        Or disable secure boot, which really does little.
                        Self-built: Asus PRIME B550M-K/Ryzen 5600GT/32Gb/Intel ARC B580 12Gb/KDE neon
                        HP Elitedesk 800 G3 Mini: i5-7500T(35w)/32Gb/Kubuntu LTS
                        HP Chromebook 14: i5-1135G7/8Gb/512Gb SSD/KDE Linux​

                        Comment


                          #27
                          Originally posted by claydoh View Post
                          Or disable secure boot, which really does little.
                          Which is what I’ll go with.
                          Slava Ukraini! πŸ‡ΊπŸ‡¦
                          Windows no longer obstruct my view.
                          Using Kubuntu Linux since March 23, 2007.
                          "It is a capital mistake to theorize before one has data." - Sherlock Holmes​

                          Comment

                          Users Viewing This Topic

                          Collapse

                          There are 0 users viewing this topic.

                          Working...
                          X