• TheCheddarCheese@lemmy.worldOP
      link
      fedilink
      English
      arrow-up
      1
      ·
      5 months ago

      I have the kernel in the bootloader, problem is I need to enroll it with MOK manager to actually boot it in secure boot. But it starts in /boot/efi with no option to go back to /boot so I don’t really understand how exactly I’m supposed to do it.

  • TheCheddarCheese@lemmy.worldOP
    link
    fedilink
    English
    arrow-up
    1
    ·
    5 months ago

    Update: The file selection seems to begin at /boot/efi/ while the kernel is located in /boot/. Don’t know the reason for this.

  • kewjo@lemmy.world
    link
    fedilink
    arrow-up
    1
    ·
    5 months ago

    generally you need to put your bios into secure boot “setup mode”, this changes based on bios but generally requires wiping any keys already enrolled. once you are in setup mode you can boot into your install. depending on your distro you can then sign your kernel+modules and update the tpm. arch wiki has a good guide. also beware each time you update your kernel you need to resign kernel and modules otherwise you won’t be able to boot