# Rocky Linux 8.5 Secure Boot Error

**URL:** <https://forums.rockylinux.org/t/rocky-linux-8-5-secure-boot-error/4760>\
**Category:** Rocky Linux Help & Support\
**Created:** [December 1, 2021, 5:04pm UTC](https://forums.rockylinux.org/t/rocky-linux-8-5-secure-boot-error/4760 "2021-12-01T17:04:40Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![Badou\_Dream](https://avatars.discourse-cdn.com/v4/letter/b/4491bb/32.png) [@Badou\_Dream](https://forums.rockylinux.org/u/Badou_Dream)\
**Post date:** [December 1, 2021, 5:04pm UTC](https://forums.rockylinux.org/t/rocky-linux-8-5-secure-boot-error/4760/1 "2021-12-01T17:04:40Z")

</div>

Hi,

I have a fresh install of RockyLinux 8.5 with UEFI and Secure Boot. My hypervisor is Esxi 7.0U2 and I have configured VM profile to CentOs 8 (64bits).

With bootSecure desactivate, kdump running. But if I activate Secure Boot, kdump failed.

```auto
systemctl status kdump
● kdump.service - Crash recovery kernel arming
   Loaded: loaded (/usr/lib/systemd/system/kdump.service; enabled; vendor preset: enabled)
   Active: failed (Result: exit-code) since Wed 2021-12-01 17:49:43 CET; 28s ago
  Process: 1276 ExecStart=/usr/bin/kdumpctl start (code=exited, status=1/FAILURE)
 Main PID: 1276 (code=exited, status=1/FAILURE)

déc. 01 17:49:42 srv-proxy-era.codradmz.local systemd[1]: Starting Crash recovery kernel arming...
déc. 01 17:49:43 srv-proxy-era.codradmz.local kdumpctl[1276]: kdump: Secure Boot is enabled. Using kexec file based syscall.
déc. 01 17:49:43 srv-proxy-era.codradmz.local kdumpctl[1276]: kdump: kexec: failed to load kdump kernel
déc. 01 17:49:43 srv-proxy-era.codradmz.local kdumpctl[1276]: kdump: Starting kdump: [FAILED]
déc. 01 17:49:43 srv-proxy-era.codradmz.local systemd[1]: kdump.service: Main process exited, code=exited, status=1/FAILURE
déc. 01 17:49:43 srv-proxy-era.codradmz.local systemd[1]: kdump.service: Failed with result 'exit-code'.
déc. 01 17:49:43 srv-proxy-era.codradmz.local systemd[1]: Failed to start Crash recovery kernel arming.

```

kdump.log

```auto
+ 2021-12-01 15:24:52 /usr/bin/kdumpctl@708: /sbin/kexec -s -s -d -p '--command-line=BOOT_IMAGE=(hd0,gpt2)/vmlinuz-4.18.0-348.2.1.el8_5.x86_64 ro resume=/dev/mapper/rl-swap irqpoll nr_cpus=1 reset_devices cgroup_disable=memory mce=off numa=off udev.children-max=2 panic=10 rootflags=nofail acpi_no_memhotplug transparent_hugepage=never nokaslr novmcoredd hest_disable disable_cpu_apicid=0' --initrd=/boot/initramfs-4.18.0-348.2.1.el8_5.x86_64kdump.img /boot/vmlinuz-4.18.0-348.2.1.el8_5.x86_64
Try gzip decompression.
Try LZMA decompression.
lzma_decompress_file: read on /boot/vmlinuz-4.18.0-348.2.1.el8_5.x86_64 of 65536 bytes failed
kexec_file_load failed: Operation not permitted
+ 2021-12-01 15:24:52 /usr/bin/kdumpctl@712: ret=255
+ 2021-12-01 15:24:52 /usr/bin/kdumpctl@713: set +x

```

Thanks for your help

---

<div class="post-metadata">

**Author:** ![label](https://avatars.discourse-cdn.com/v4/letter/l/c5a1d2/32.png) [@label](https://forums.rockylinux.org/u/label)\
**Post date:** [December 2, 2021, 4:13pm UTC](https://forums.rockylinux.org/t/rocky-linux-8-5-secure-boot-error/4760/2 "2021-12-02T16:13:22Z")

</div>

This is a known issue. [https://bugs.rockylinux.org/show\_bug.cgi?id=174](https://bugs.rockylinux.org/show_bug.cgi?id=174)

---

<div class="post-metadata">

**Author:** ![Badou\_Dream](https://avatars.discourse-cdn.com/v4/letter/b/4491bb/32.png) [@Badou\_Dream](https://forums.rockylinux.org/u/Badou_Dream)\
**Post date:** [December 2, 2021, 5:09pm UTC](https://forums.rockylinux.org/t/rocky-linux-8-5-secure-boot-error/4760/3 "2021-12-02T17:09:26Z")

</div>

Oh Thank’s.

I test some version to replace CentOs on my production server. I can’t choose a distribution woth No UEFI or no SecureBoot. I hope this problem will be solved quickly, otherwise I would have to turn to AlmaLinux.

Thanks

---

<div class="post-metadata">

**Author:** ![label](https://avatars.discourse-cdn.com/v4/letter/l/c5a1d2/32.png) [@label](https://forums.rockylinux.org/u/label)\
**Post date:** [December 3, 2021, 1:00am UTC](https://forums.rockylinux.org/t/rocky-linux-8-5-secure-boot-error/4760/4 "2021-12-03T01:00:52Z")

</div>

From the bug report:

> Looks like it is a shim bug: [mok: delete the existing RT variables only when only\_first=TRUE by lcp · Pull Request #387 · rhboot/shim · GitHub](https://github.com/rhboot/shim/pull/387) and hopefully will be fixed when shim 15.5 released  
> Also someone else did test some versions of ESXi 7.0.2 and kdump was working fine with SB enabled, so not all ESXi version are affected by this.

When shim 15.5 is released, it will be fixed. I don’t have an ETA on that though (that’s more of an upstream thing). According to Sherif though, there are some versions of ESXi that are working just fine with kdump. @Sherif are you able to give a bit more info here?

---

<div class="post-metadata">

**Author:** ![Sherif](https://sea2.discourse-cdn.com/flex020/user_avatar/forums.rockylinux.org/sherif/32/42_2.png) [@Sherif](https://forums.rockylinux.org/u/Sherif)\
**Post date:** [December 3, 2021, 9:11am UTC](https://forums.rockylinux.org/t/rocky-linux-8-5-secure-boot-error/4760/5 "2021-12-03T09:11:34Z")

</div>

Secureboot is working fine on RockyLinux 8.5, you will be able to boot the machine in secureboot and verify that everything is signed with correct certs. We are using shim 15.4 + few critical patches that didn’t make it yet to the upstream distro, more info here about our review and the patches that we included based on the shim-review committee [Shim 15.4 for Rocky Linux 8 · Issue #194 · rhboot/shim-review · GitHub](https://github.com/rhboot/shim-review/issues/194)

However, there was a bug that seems to be solved with 15.5 which still in RC and didn’t make it to the upstream as well, we did some tests as far as we can since we can’t load certs into EXSi UEFI firmware and we do have an internal ticket open with vmware and they recommend us to include the patch @label mentioned, which will be included with shim 15.5 once it is released by the upstream distro. The bug is only effecting kexec which is needed to load kdump, doesn’t effect the secureboot verify and booting process. We still have no ETA regarding when 15.5 will be released by the upstream vendor.

Some members managed to get Rocky with secrureboot running without kdump on ESXi 7.0.3 and some other members managed to get secureboot running with kdump on esxi 7.0.2.

---

<div class="post-metadata">

**Author:** ![joebeasley3](https://sea2.discourse-cdn.com/flex020/user_avatar/forums.rockylinux.org/joebeasley3/32/1242_2.png) [@joebeasley3](https://forums.rockylinux.org/u/joebeasley3)\
**Post date:** [December 3, 2021, 6:37pm UTC](https://forums.rockylinux.org/t/rocky-linux-8-5-secure-boot-error/4760/6 "2021-12-03T18:37:44Z")

</div>

I can confirm Rocky 8.5 with secure boot and kdump working with esxi 6.7.

shim 15.4-2.el8\_5.2.rocky  
kexec-tools 2.0.20.el8

---

<div class="post-metadata">

**Author:** ![Sherif](https://sea2.discourse-cdn.com/flex020/user_avatar/forums.rockylinux.org/sherif/32/42_2.png) [@Sherif](https://forums.rockylinux.org/u/Sherif)\
**Post date:** [December 6, 2021, 11:13pm UTC](https://forums.rockylinux.org/t/rocky-linux-8-5-secure-boot-error/4760/7 "2021-12-06T23:13:38Z")

</div>

Thank you so much for the update @joebeasley3

---

<div class="post-metadata">

**Author:** ![Badou\_Dream](https://avatars.discourse-cdn.com/v4/letter/b/4491bb/32.png) [@Badou\_Dream](https://forums.rockylinux.org/u/Badou_Dream)\
**Post date:** [December 7, 2021, 10:51am UTC](https://forums.rockylinux.org/t/rocky-linux-8-5-secure-boot-error/4760/8 "2021-12-07T10:51:51Z")

</div>

Thank.

I do to update every esxi and Vcenter, but I need time for this. If I have some news, i answer in this topic. For the moment, with Esxi 7.0.2build17867351, shim 15.4-2.el8\_5.2.rocky and kexec-tools 2.0.20.el8 this is not good.

Many thanks

---

<div class="post-metadata">

**Author:** ![reindan](https://avatars.discourse-cdn.com/v4/letter/r/f19dbf/32.png) [@reindan](https://forums.rockylinux.org/u/reindan)\
**Post date:** [December 7, 2021, 11:46am UTC](https://forums.rockylinux.org/t/rocky-linux-8-5-secure-boot-error/4760/9 "2021-12-07T11:46:10Z")

</div>

I just stumbled across this thread and can confirm the same issue with Rocky 8.5 on ESXi 7.0.1, 17168206

---

<div class="post-metadata">

**Author:** ![roc](https://avatars.discourse-cdn.com/v4/letter/r/858c86/32.png) [@roc](https://forums.rockylinux.org/u/roc)\
**Post date:** [December 26, 2021, 3:11am UTC](https://forums.rockylinux.org/t/rocky-linux-8-5-secure-boot-error/4760/10 "2021-12-26T03:11:06Z")

</div>

Secure boot appears to be working, but kdump is not working with secure boot, in Rocky 8.5 with ESXi 6.7U3 (18828794) , kexec-tools-2.0.20-57.el8\_5.1.x86\_64 and shim-x64-15.4-2.el8\_5.2.rocky.x86\_64.

---

<div class="post-metadata">

**Author:** ![grydan](https://avatars.discourse-cdn.com/v4/letter/g/82dd89/32.png) [@grydan](https://forums.rockylinux.org/u/grydan)\
**Post date:** [April 6, 2022, 1:02pm UTC](https://forums.rockylinux.org/t/rocky-linux-8-5-secure-boot-error/4760/11 "2022-04-06T13:02:38Z")

</div>

I have the same problem with the latest version of Rocky look the image, any idea how to fix? The machine is under VMWARE ESXi Version 6.7 P05… I have also changed the **/etc/default/grub** in the line from **auto** to 256M but don’t solve  
GRUB\_CMDLINE\_LINUX=“crashkernel= **256M** resume=/dev/mapper/rl-swap rd.lvm.lv=rl/root rd.lvm.lv=rl/swap”

 ![image](https://us1.discourse-cdn.com/flex020/uploads/rockylinux/original/2X/3/340dca8f0e066d576cb71b57e7a2b0d9ab8bbed3.png)

---

<div class="post-metadata">

**Author:** ![gerry666uk](https://avatars.discourse-cdn.com/v4/letter/g/dbc845/32.png) [@gerry666uk](https://forums.rockylinux.org/u/gerry666uk)\
**Post date:** [April 7, 2022, 6:38pm UTC](https://forums.rockylinux.org/t/rocky-linux-8-5-secure-boot-error/4760/12 "2022-04-07T18:38:23Z")

</div>

Are you saying that Rocky 8.5 works perfectly on VMWARE ESXi Version 6.7 P05, and it’s just the kdump service that doesn’t work?

---

<div class="post-metadata">

**Author:** ![grydan](https://avatars.discourse-cdn.com/v4/letter/g/82dd89/32.png) [@grydan](https://forums.rockylinux.org/u/grydan)\
**Post date:** [April 7, 2022, 8:31pm UTC](https://forums.rockylinux.org/t/rocky-linux-8-5-secure-boot-error/4760/13 "2022-04-07T20:31:39Z")

</div>

Yes if you disable “secure boot” into VMware setting all work without any problem.  
Kdump seem don’t work when “secure boot” option is enable into VMware settings.

---

<div class="post-metadata">

**Author:** ![Opa114](https://avatars.discourse-cdn.com/v4/letter/o/73ab20/32.png) [@Opa114](https://forums.rockylinux.org/u/Opa114)\
**Post date:** [May 31, 2022, 2:53pm UTC](https://forums.rockylinux.org/t/rocky-linux-8-5-secure-boot-error/4760/14 "2022-05-31T14:53:59Z")

</div>

Any news about this issue with secure boot enables in VMWare ESXi?

---

<div class="post-metadata">

**Author:** ![Badou\_Dream](https://avatars.discourse-cdn.com/v4/letter/b/4491bb/32.png) [@Badou\_Dream](https://forums.rockylinux.org/u/Badou_Dream)\
**Post date:** [June 9, 2022, 8:08am UTC](https://forums.rockylinux.org/t/rocky-linux-8-5-secure-boot-error/4760/15 "2022-06-09T08:08:47Z")

</div>

Hi everybody,

All my server are upgrade in 8.6 GreenObside and kdump is Ok.

Thanks everybody

---

<div class="post-metadata">

**Author:** ![Opa114](https://avatars.discourse-cdn.com/v4/letter/o/73ab20/32.png) [@Opa114](https://forums.rockylinux.org/u/Opa114)\
**Post date:** [June 9, 2022, 1:56pm UTC](https://forums.rockylinux.org/t/rocky-linux-8-5-secure-boot-error/4760/16 "2022-06-09T13:56:38Z")

</div>

@Badou_Dream interesting. Are you using VMware ESX (vcenter). Secure Boot enabled in vm options?  
I’m using 8.6, too and kdump there did not start (secure boot enabled in vm options)

---

<div class="post-metadata">

**Author:** ![Badou\_Dream](https://avatars.discourse-cdn.com/v4/letter/b/4491bb/32.png) [@Badou\_Dream](https://forums.rockylinux.org/u/Badou_Dream)\
**Post date:** [June 14, 2022, 8:15am UTC](https://forums.rockylinux.org/t/rocky-linux-8-5-secure-boot-error/4760/17 "2022-06-14T08:15:33Z")

</div>

Sorry Somebody has deactivate the Secure Boot.

No solution for this problem ?

---

<div class="post-metadata">

**Author:** ![simple\_user](https://avatars.discourse-cdn.com/v4/letter/s/9fc348/32.png) [@simple\_user](https://forums.rockylinux.org/u/simple_user)\
**Post date:** [June 15, 2022, 1:52pm UTC](https://forums.rockylinux.org/t/rocky-linux-8-5-secure-boot-error/4760/18 "2022-06-15T13:52:21Z")

</div>

@Opa114 and @Badou_Dream, as I understand it, there’s a bug in the secure boot process that most vendors ignore, which means secure boot works for most people. VMWare doesn’t ignore it, and so secure boot is broken.

shim 15.5 fixes this. It was released in the upstream 8.6 edition, but is not yet in the Rocky one. That’s because MS needs to sign the shim to help secure the entire secure boot chain. Rocky put in a request to sign that shim in March.

> <https://github.com/rhboot/shim-review/issues/234>
>
> Make sure you have provided the following information:
> 
> - \[x\] link to your co…de branch cloned from rhboot/shim-review in the form user/repo@tag
> - \[x\] completed README.md file with the necessary information
> - \[x\] shim.efi to be signed
> - \[x\] public portion of your certificate(s) embedded in shim (the file passed to VENDOR\_CERT\_FILE)
> - \[x\] binaries, for which hashes are added to vendor\_db ( if you use vendor\_db and have hashes allow-listed )
> - \[x\] any extra patches to shim via your own git tree or as files
> - \[x\] any extra patches to grub via your own git tree or as files
> - \[x\] build logs
> - \[x\] a Dockerfile to reproduce the build of the provided shim EFI binaries
> 
> Review avilable at https://github.com/rocky-linux/shim-review/tree/rockylinux-8-shim-x86\_64-20220325
> 
> \-------------------------------------------------------------------------------
> \### What organization or people are asking to have this signed?
> \-------------------------------------------------------------------------------
> Rocky Enterprise Software Foundation
> 
> \-------------------------------------------------------------------------------
> \### What product or service is this for?
> \-------------------------------------------------------------------------------
> Rocky Linux 8
> 
> \-------------------------------------------------------------------------------
> \### Please create your shim binaries starting with the 15.4 shim release tar file: https://github.com/rhboot/shim/releases/download/15.4/shim-15.4.tar.bz2
> \### This matches https://github.com/rhboot/shim/releases/tag/15.4 and contains the appropriate gnu-efi source.
> \### Please confirm this as the origin your shim.
> \-------------------------------------------------------------------------------
> shim 15.5 from https://github.com/rhboot/shim/tree/15.5
> 
> \-------------------------------------------------------------------------------
> \### What's the justification that this really does need to be signed for the whole world to be able to boot it?
> \-------------------------------------------------------------------------------
> Rocky Linux is a community enterprise operating system designed to be 100% bug-for-bug compatible with RHEL
> 
> \-------------------------------------------------------------------------------
> \### How do you manage and protect the keys used in your SHIM?
> \-------------------------------------------------------------------------------
> Keys stored in FIPS-140-2 level 2 certified HSM and managed by our security team
> 
> \-------------------------------------------------------------------------------
> \### Do you use EV certificates as embedded certificates in the SHIM?
> \-------------------------------------------------------------------------------
> No
> 
> \-------------------------------------------------------------------------------
> \### If you use new vendor\_db functionality, are any hashes allow-listed?
> \### If yes: for what binaries?
> \-------------------------------------------------------------------------------
> We don't use vendor\_db functionality in this build
> 
> \-------------------------------------------------------------------------------
> \### Is kernel upstream commit 75b0cea7bf307f362057cc778efe89af4c615354 present in your kernel, if you boot chain includes a Linux kernel ?
> \-------------------------------------------------------------------------------
> We have validated that all those commits present:
> \`\`\`
> 475fb4e8b2f4444d1d7b406ff3a7d21bc89a1e6f
> 1957a85b0032a81e6482ca4aab883643b8dae06e
> 612bd01fc6e04c3ce9eb59587b4a7e4ebd6aff35
> 75b0cea7bf307f362057cc778efe89af4c615354
> 435d1a471598752446a72ad1201b3c980526d869
> \`\`\`
> And the configuration setting CONFIG\_EFI\_CUSTOM\_SSDT\_OVERLAYS is disabled.
> 
> \-------------------------------------------------------------------------------
> \### if SHIM is loading GRUB2 bootloader, are CVEs CVE-2020-14372, CVE-2020-25632, CVE-2020-25647, CVE-2020-27749, CVE-2020-27779, CVE-2021-20225, CVE-2021-20233, CVE-2020-10713, CVE-2020-14308, CVE-2020-14309, CVE-2020-14310, CVE-2020-14311, CVE-2020-15705, ( July 2020 grub2 CVE list + March 2021 grub2 CVE list ) and if you are shipping the shim\_lock module CVE-2021-3418 fixed ?
> \-------------------------------------------------------------------------------
> We never built any shim before SBAT support, we only started building and signing shim from shim 15.4 with SBAT support, so the cert that shim uses never used with any grub2 / kernel that effected with those vulnerabilities.
> 
> \-------------------------------------------------------------------------------
> \### "Please specifically confirm that you add a vendor specific SBAT entry for SBAT header in each binary that supports SBAT metadata ( grub2, fwupd, fwupdate, shim + all child shim binaries )" to shim review doc ?
> \### Please provide exact SBAT entries for all SBAT binaries you are booting or planning to boot directly through shim
> \### Where your code is only slightly modified from an upstream vendor's, please also preserve their SBAT entries to simplify revocation.
> \-------------------------------------------------------------------------------
> For shim we have the following SBAT:
> \`\`\`
> sbat,1,SBAT Version,sbat,1,https://github.com/rhboot/shim/blob/main/SBAT.md
> shim,1,UEFI shim,shim,1,https://github.com/rhboot/shim
> shim.rocky,1,Rocky Linux,shim,15.5,security@rockylinux.org
> \`\`\`
> 
> For grub:
> \`\`\`
> sbat,1,SBAT Version,sbat,1,https://github.com/rhboot/shim/blob/main/SBAT.md
> grub,1,Free Software Foundation,grub,2.02,https://www.gnu.org/software/grub/
> grub.rhel8,1,Red Hat Enterprise Linux 8,grub2,@@VERSION@@,mail:secalert@redhat.com
> grub.rocky8,1,Rocky Linux 8,grub2,@@VERSION@@,mail:security@rockylinux.org
> \`\`\`
> For fwupd binaries will have the following entries:
> \`\`\`
> sbat,1,UEFI shim,sbat,1,https://github.com/rhboot/shim/blob/main/SBAT.md
> fwupd,1,Firmware update daemon,fwupd,1.5.9,https://github.com/fwupd/fwupd
> fwupd.rocky,1,Rocky Linux,fwupd,1.5.9,mail:security@rockylinux.org
> \`\`\`
> 
> \-------------------------------------------------------------------------------
> \### Were your old SHIM hashes provided to Microsoft ?
> \-------------------------------------------------------------------------------
> yes, they were provided during signing
> 
> \-------------------------------------------------------------------------------
> \### Did you change your certificate strategy, so that affected by CVE-2020-14372, CVE-2020-25632, CVE-2020-25647, CVE-2020-27749, CVE-2020-27779, CVE-2021-20225, CVE-2021-20233, CVE-2020-10713, CVE-2020-14308, CVE-2020-14309, CVE-2020-14310, CVE-2020-14311, CVE-2020-15705 ( July 2020 grub2 CVE list + March 2021 grub2 CVE list ) grub2 bootloaders can not be verified ?
> \-------------------------------------------------------------------------------
> No, since we never signed any shim , grub2 or kernel before shim 15.4 with SBAT support
> 
> \-------------------------------------------------------------------------------
> \### What exact implementation of Secureboot in grub2 ( if this is your bootloader ) you have ?
> \### \* Upstream grub2 shim\_lock verifier or \* Downstream RHEL/Fedora/Debian/Canonical like implementation ?
> \-------------------------------------------------------------------------------
> RHEL downstream like implementation
> 
> \-------------------------------------------------------------------------------
> \### Which modules are built into your signed grub image?
> \-------------------------------------------------------------------------------
> all\_video boot blscfg btrfs cat configfile cryptodisk echo ext2 fat font
> gcry\_rijndael gcry\_rsa gcry\_serpent gcry\_sha256 gcry\_twofish gcry\_whirlpool
> gfxmenu gfxterm gzio halt hfsplus http increment iso9660 jpeg loadenv loopback
> linux lvm luks mdraid09 mdraid1x minicmd net normal part\_apple part\_msdos
> part\_gpt password\_pbkdf2 png reboot regexp search search\_fs\_uuid search\_fs\_file
> search\_label serial sleep syslinuxcfg test tftp video xfs efi\_netfs efifwsetup
> efinet lsefi lsefimmap connectefi backtrace chain usb usbserial\_common
> usbserial\_pl2303 usbserial\_ftdi usbserial\_usbdebug keylayouts at\_keyboard
> 
> \-------------------------------------------------------------------------------
> \### What is the origin and full version number of your bootloader (GRUB or other)?
> \-------------------------------------------------------------------------------
> RHEL downstream, grub2-2.02-106.el8.0.2 https://git.rockylinux.org/staging/rpms/grub2
> 
> \-------------------------------------------------------------------------------
> \### If your SHIM launches any other components, please provide further details on what is launched.
> \-------------------------------------------------------------------------------
> It launches fwupd
> 
> \-------------------------------------------------------------------------------
> \### If your GRUB2 launches any other binaries that are not the Linux kernel in SecureBoot mode, please provide further details on what is launched and how it enforces Secureboot lockdown.
> \-------------------------------------------------------------------------------
> Grub validates signatures using shim's protocol for boot kernel. fwupd only loads UEFI updates
> 
> \-------------------------------------------------------------------------------
> \### If you are re-using a previously used (CA) certificate, you will need to add the hashes of the previous GRUB2 binaries exposed to the CVEs to vendor\_dbx in shim in order to prevent GRUB2 from being able to chainload those older GRUB2 binaries. If you are changing to a new (CA) certificate, this does not apply.
> \### Please describe your strategy.
> \-------------------------------------------------------------------------------
> We only started signing shim after 15.4 with SBAT support
> 
> \-------------------------------------------------------------------------------
> \### How do the launched components prevent execution of unauthenticated code?
> \-------------------------------------------------------------------------------
> Grub validates signatures using shim's protocol for boot kernel. fwupd only loads UEFI updates
> 
> \-------------------------------------------------------------------------------
> \### Does your SHIM load any loaders that support loading unsigned kernels (e.g. GRUB)?
> \-------------------------------------------------------------------------------
> No
> 
> \-------------------------------------------------------------------------------
> \### What kernel are you using? Which patches does it includes to enforce Secure Boot?
> \-------------------------------------------------------------------------------
> RHEL kernel 4.18.0 and all signed kernels are all patched for the kernel boothole CVEs and have the CONFIG\_EFI\_CUSTOM\_SSDT\_OVERLAYS config option disabled.
> 
> \-------------------------------------------------------------------------------
> \### What changes were made since your SHIM was last signed?
> \-------------------------------------------------------------------------------
> Our latest signed shim was shim 15.4 + cherry picked patches based on the shim review board recommendation, we dropped all that and using latest shim 15.5
> 
> \-------------------------------------------------------------------------------
> \### What is the SHA256 hash of your final SHIM binary?
> \-------------------------------------------------------------------------------
> \`\`\`
> 945511223c674a99cbf2fe459f6b5d1643d92e352342d52b9560ec2397ff6c0d shimx64.efi
> 465e03b7af50b04bb92ed708c0997c9c728ff45e7153d664b1d6905f79678089 shimia32.efi
> \`\`\`

They responded to a few questions and up until yesterday, all of the recent posts have been Rocky asking if there are any updates or any more information needed.

That request was closed yesterday without signing the shim because of new CVE’s and Rocky needs to open a new request.

So, there is a fix for this. The ability to implement is out of the Rocky Linux’ team hands. I wouldn’t expect any solution soon, because of both the time this request languished and the need to stay bug for bug compatible with upstream, which already has a signed 15.5 shim.

---

<div class="post-metadata">

**Author:** ![windacplay](https://avatars.discourse-cdn.com/v4/letter/w/f04885/32.png) [@windacplay](https://forums.rockylinux.org/u/windacplay)\
**Post date:** [July 30, 2022, 4:39pm UTC](https://forums.rockylinux.org/t/rocky-linux-8-5-secure-boot-error/4760/19 "2022-07-30T16:39:28Z")

</div>

Please has anyone solved this problem?  
Use environment:  
Use the latest version rocky8.6  
dnf update to the latest version  
Esxi7.0.3f 20036589  
After a fresh install, the problem still occurs  
And try to change the crashkernel=auto value in grub2-efi.cfg  
128/192/256M still can’t start

---

<div class="post-metadata">

**Author:** ![brian](https://sea2.discourse-cdn.com/flex020/user_avatar/forums.rockylinux.org/brian/32/5777_2.png) [@brian](https://forums.rockylinux.org/u/brian)\
**Post date:** [August 25, 2023, 3:43am UTC](https://forums.rockylinux.org/t/rocky-linux-8-5-secure-boot-error/4760/20 "2023-08-25T03:43:54Z")

</div>


