[From nobody Thu Sep 24 11:37:10 2026
Received: (at submit) by bugs.debian.org; 22 Sep 2026 13:59:59 +0000
X-Spam-Checker-Version: SpamAssassin 4.0.1-bugs.debian.org_2005_01_02
 (2024-03-25) on buxtehude.debian.org
X-Spam-Level: 
X-Spam-Status: No, score=-7.9 required=4.0 tests=BAYES_00,FOURLA,NO_RELAYS,
 XMAILER_REPORTBUG autolearn=ham autolearn_force=no
 version=4.0.1-bugs.debian.org_2005_01_02
X-Spam-Bayes: score:0.0000 Tokens: new, 18; hammy, 149; neutral, 44; spammy,
 1. spammytokens:0.940-+--H*r:bugs.debian.org
 hammytokens:0.000-+--XDebbugsCc, 0.000-+--X-Debbugs-Cc,
 0.000-+--H*Ad:N*Bug, 0.000-+--HTo:N*Debian, 0.000-+--forky
Return-path: &lt;ardb@kernel.org&gt;
Received: via submission by buxtehude.debian.org with esmtp (Exim 4.96)
 (envelope-from &lt;ardb@kernel.org&gt;) id 1x912N-000vd9-1P
 for submit@bugs.debian.org; Tue, 22 Sep 2026 13:59:59 +0000
Content-Type: text/plain; charset=&quot;us-ascii&quot;
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: Ard Biesheuvel &lt;ardb@kernel.org&gt;
To: Debian Bug Tracking System &lt;submit@bugs.debian.org&gt;
Subject: grub2: boot fails with secure boot enabled but mok validation disabled
Message-ID: &lt;179008559584.5336.16099674089867768999.reportbug@eva&gt;
X-Mailer: reportbug 13.2.0+nmu1
Date: Tue, 22 Sep 2026 15:59:55 +0200
Delivered-To: submit@bugs.debian.org

Source: grub2
Version: 2.14-3
Severity: critical
Justification: breaks the whole system
X-Debbugs-Cc: debian-amd64@lists.debian.org, ardb@kernel.org
User: debian-amd64@lists.debian.org
Usertags: amd64

Dear Maintainer,

mokutil --disable-validation breaks the boot on systems with secure boot
enabled.

GRUB 2.14-3 no longer falls back to peimage when it sees that shim's image
loader protocol exists in the firmware's protocol database.

However, it does not actually make use of the shim loader protocol when
validation is disabled via mokutil, as it thinks secure boot is disabled
and there is no need. Instead, it falls back to the firmware's image
loader, which only accepts images that are signed against certificates
in the firmware's db database. Debian's signing cert is not in that
database and so the boot fails.


-- System Information:
Debian Release: forky/sid
  APT prefers testing
  APT policy: (500, 'testing')
Architecture: amd64 (x86_64)

Kernel: Linux 7.1.13+deb14-amd64 (SMP w/4 CPU threads; PREEMPT)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8), LANGUAGE=en_US:en
Shell: /bin/sh linked to /usr/bin/dash
Init: systemd (via /run/systemd/system)
LSM: AppArmor: enabled
]