To enable Secure Boot first remove the various DKMS-related packages, as explained above:
Code: Select all
sudo apt purge dkms broadcom-sta-dkms ndiswrapper{,-dkms,-utils-1.9} virtualbox-guest-{dkms,utils{,-modified-init},x11}
Code: Select all
sudo apt install shim-signed grub-efi-amd64-{signed,bin=2.02+dfsg1-20} grub{,2}-common=2.02+dfsg1-20 linux-image-amd64
Also copy the old 30_os-prober script back if dual-booting with Manjaro:
Code: Select all
sudo cp /usr/local/share/live-files/files/etc/grub.d/30_os-prober /etc/grub.d/30_os-prober
Code: Select all
sudo tee /etc/apt/preferences.d/secure-boot <<END
Package: grub-common grub2-common grub-efi-amd64-bin
Pin: release o=Debian
Pin-Priority: 1001
END
EDIT: corrected purge command and simplified procedure.
EDIT2: added fehlix's fix.