Bug#1148719: grub2: boot fails with secure boot enabled but mok validation disabled
Ard Biesheuvel
ardb at kernel.org
Tue Sep 22 14:59:55 BST 2026
Source: grub2
Version: 2.14-3
Severity: critical
Justification: breaks the whole system
X-Debbugs-Cc: debian-amd64 at lists.debian.org, ardb at kernel.org
User: debian-amd64 at lists.debian.org
Usertags: amd64
Dear Maintainer,
mokutil --disable-validation breaks the boot on systems with secure boot
enabled.
GRUB 2.14-3 no longer falls back to peimage when it sees that shim's image
loader protocol exists in the firmware's protocol database.
However, it does not actually make use of the shim loader protocol when
validation is disabled via mokutil, as it thinks secure boot is disabled
and there is no need. Instead, it falls back to the firmware's image
loader, which only accepts images that are signed against certificates
in the firmware's db database. Debian's signing cert is not in that
database and so the boot fails.
-- System Information:
Debian Release: forky/sid
APT prefers testing
APT policy: (500, 'testing')
Architecture: amd64 (x86_64)
Kernel: Linux 7.1.13+deb14-amd64 (SMP w/4 CPU threads; PREEMPT)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8), LANGUAGE=en_US:en
Shell: /bin/sh linked to /usr/bin/dash
Init: systemd (via /run/systemd/system)
LSM: AppArmor: enabled
More information about the Pkg-grub-devel
mailing list