Help installing MX Linux with Secure Boot

When you run into problems installing MX Linux XFCE
Message
Author
User avatar
richb
Administrator
Posts: 10927
Joined: Wed Jul 12, 2006 2:17 pm

Re: Help installing MX Linux with Secure Boot

#11 Post by richb »

@MultipleX
I would suggest you wait for the RC. It should be coming soon.
Forum Rules
Guide - How to Ask for Help

richb Administrator
System: MX 23 KDE
AMD A8 7600 FM2+ CPU R7 Graphics, 16 GIG Mem. Three Samsung EVO SSD's 250 GB

User avatar
fehlix
Developer
Posts: 12740
Joined: Wed Apr 11, 2018 5:09 pm

Re: Help installing MX Linux with Secure Boot

#12 Post by fehlix »

MultipleX wrote: Mon Sep 27, 2021 8:14 am Coming back to my original issue, one thing that I realised when running through the instructions contained in the links from #2 and #3 is that at no point did mukutil come up and ask me to enrol the Debian key in the BIOS so it might this have been what was missing? The instructions in the link above show you how to enrol one's own generated key, but where do I get the Debian public key from?
B/c Debians signing key is signed by a Microsoft key, where MS's public counterpart is available already within the UEFI firmware, hence no key-enrolement using mokutil are required.

MultipleX
Posts: 48
Joined: Sat Sep 25, 2021 2:26 pm

Re: Help installing MX Linux with Secure Boot

#13 Post by MultipleX »

richb wrote: Mon Sep 27, 2021 8:33 am @MultipleX
I would suggest you wait for the RC. It should be coming soon.
No problem. Happy to wait. Seems reasonable.
fehlix wrote: Mon Sep 27, 2021 8:38 am
MultipleX wrote: Mon Sep 27, 2021 8:14 am Coming back to my original issue, one thing that I realised when running through the instructions contained in the links from #2 and #3 is that at no point did mukutil come up and ask me to enrol the Debian key in the BIOS so it might this have been what was missing? The instructions in the link above show you how to enrol one's own generated key, but where do I get the Debian public key from?
B/c Debians signing key is signed by a Microsoft key, where MS's public counterpart is available already within the UEFI firmware, hence no key-enrolement using mokutil are required.
Ah, that would explain it then. Thank you.

Wouldn't that presumably mean that any DKMS drivers (e.g. VirtualBox, Nvidia) would need to be signed with Microsoft's key as well?

User avatar
fehlix
Developer
Posts: 12740
Joined: Wed Apr 11, 2018 5:09 pm

Re: Help installing MX Linux with Secure Boot

#14 Post by fehlix »

MultipleX wrote: Tue Sep 28, 2021 4:39 am
richb wrote: Mon Sep 27, 2021 8:33 am @MultipleX
I would suggest you wait for the RC. It should be coming soon.
No problem. Happy to wait. Seems reasonable.
fehlix wrote: Mon Sep 27, 2021 8:38 am
MultipleX wrote: Mon Sep 27, 2021 8:14 am Coming back to my original issue, one thing that I realised when running through the instructions contained in the links from #2 and #3 is that at no point did mukutil come up and ask me to enrol the Debian key in the BIOS so it might this have been what was missing? The instructions in the link above show you how to enrol one's own generated key, but where do I get the Debian public key from?
B/c Debians signing key is signed by a Microsoft key, where MS's public counterpart is available already within the UEFI firmware, hence no key-enrolement using mokutil are required.
Ah, that would explain it then. Thank you.

Wouldn't that presumably mean that any DKMS drivers (e.g. VirtualBox, Nvidia) would need to be signed with Microsoft's key as well?
I think, one would generate one-time a local signing key, which would need to be put into UEFI firmware by using mokutil key-enrolement, and sign the driver with that key. I think, but I might be wrong, that's still the way Ubuntu and co. are doing it, but need to check where they are now with latest releases.

Huckleberry Finn

Re: Help installing MX Linux with Secure Boot

#15 Post by Huckleberry Finn »

Meanwhile, these may be useful in general about what secure boot is and also what it's not :

https://wiki.debian.org/SecureBoot

https://linuxhint.com/secure-boot-linux/

User avatar
dolphin_oracle
Developer
Posts: 22400
Joined: Sun Dec 16, 2007 12:17 pm

Re: Help installing MX Linux with Secure Boot

#16 Post by dolphin_oracle »

@fehlix that's how they do it with the modules. upon reboot, there is a prompt to accept the self-signed modules, IIRC. this happens when you do broadcom drivers on ubuntu.
http://www.youtube.com/runwiththedolphin
lenovo ThinkPad X1 Extreme Gen 4 - MX-23
FYI: mx "test" repo is not the same thing as debian testing repo.

MultipleX
Posts: 48
Joined: Sat Sep 25, 2021 2:26 pm

Re: Help installing MX Linux with Secure Boot

#17 Post by MultipleX »

I discovered kvm and QEMU today as an alternative to VirtualBox. It seems kvm already has hooks into the kernel so doesn't need dkms drivers and Debian provides signed drivers. I tried it on Mint and it seems to works fine. The Debian VM that was created using virt-manager also seemed to run without any problems in a secure boot environment. I suspect the drivers are bundled with the package supplied on the Ubuntu repository as I didn't have to install anything else than the usually recommended packages. I have yet to test an OS that is not secure boot aware.

I have decided to go with a dual-boot setup with Mint20.2 and MX-21 when the release candidate becomes available. In the meantime the MX partition has MX-19 installed on it. MX feels a little snappier than Mint and I hope to move over to it in due course.
Last edited by MultipleX on Thu Sep 30, 2021 9:27 am, edited 1 time in total.

User avatar
mtnstatetechie
Posts: 3
Joined: Tue Sep 14, 2021 10:42 am

Re: Help installing MX Linux with Secure Boot

#18 Post by mtnstatetechie »

I had to turn off Secure Boot on my Dell 7380 laptop to get my system to boot, couldn't get it to work any other way.
Eric :fishing:

User avatar
Arnox
Posts: 507
Joined: Sat Sep 18, 2021 10:50 pm

Re: Help installing MX Linux with Secure Boot

#19 Post by Arnox »

MultipleX wrote: Sat Sep 25, 2021 3:59 pm With Microsoft using its clout to force the issue in its next OS release, this is going to prove interesting. Will we have to go into BIOS and enable/disable SecureBoot every time we want to switch between Linux and Windows?
As if I'm going to be caught dead using Windows 11... 10 is already bad enough. And I say all this as a big former Windows fan too.

The good news though is that you won't need to run Windows 11 any time soon for compatibility reasons. What runs on Windows 11 will run on 10 as well for the foreseeable future.
MultipleX wrote: Sat Sep 25, 2021 3:59 pm How long will it be before disabling SecureBoot is no longer supported in BIOS?
Pretty sure that won't happen. There's no reason to take it out.
richb wrote: Mon Sep 27, 2021 8:33 am @MultipleX
I would suggest you wait for the RC. It should be coming soon.
WHEN

Image

User avatar
Eadwine Rose
Administrator
Posts: 14872
Joined: Wed Jul 12, 2006 2:10 am

Re: Help installing MX Linux with Secure Boot

#20 Post by Eadwine Rose »

richb wrote: Mon Sep 27, 2021 8:33 am @MultipleX
I would suggest you wait for the RC. It should be coming soon.
WHEN

Image
When it's ready ;)
MX-23.6_x64 July 31 2023 * 6.1.0-37amd64 ext4 Xfce 4.20.0 * 8-core AMD Ryzen 7 2700
Asus TUF B450-Plus Gaming UEFI * Asus GTX 1050 Ti Nvidia 535.247.01 * 2x16Gb DDR4 2666 Kingston HyperX Predator
Samsung 870EVO * Samsung S24D330 & P2250 * HP Envy 5030

Post Reply

Return to “Installation”