[bug #67455] Can't Secure Boot via sbctl

Sosal Dva Raza <[email protected]> Sun, 24 Aug 2025 08:49:44 -0400 (EDT)
Newsgroups gmane.comp.boot-loaders.grub.bugs
Message-ID <[email protected]>
--8323329-1663969994-1756039784=:1651364
Content-Type: TEXT/plain; CHARSET=utf-8
Content-Transfer-Encoding: QUOTED-PRINTABLE
Content-Disposition: inline

URL:=0A  <https://savannah.gnu.org/bugs/?67455>=0A=0A                 Summa=
ry: Can't Secure Boot via sbctl=0A                   Group: GNU GRUB=0A    =
           Submitter: sosaldvaraza=0A               Submitted: =D0=92=D1=81=
 24 =D0=B0=D0=B2=D0=B3 2025 12:49:40=0A                Category: Booting=0A=
                Severity: Major=0A                Priority: 5 - Normal=0A  =
            Item Group: None=0A                  Status: None=0A           =
      Privacy: Public=0A             Assigned to: None=0A         Originato=
r Name: sosaldvaraza=0A        Originator Email:=0A             Open/Closed=
: Open=0A         Discussion Lock: Any=0A                 Release: other=0A=
                 Release:=0A         Reproducibility: None=0A         Plann=
ed Release: None=0A=0A=0A    ______________________________________________=
_________=0A=0AFollow-up Comments:=0A=0A=0A--------------------------------=
-----------------------=0ADate: =D0=92=D1=81 24 =D0=B0=D0=B2=D0=B3 2025 12:=
49:40   By: Sosal Dva Raza <sosaldvaraza>=0AGRUB 2:2.12.r292.g73d1c959-1=0A=
https://github.com/Foxboron/sbctl=0A=0Are-installed grub with tpm module=0A=
grub-install --target=3Dx86_64-efi --efi-directory=3D/boot --bootloader-id=
=3DGRUB=0A--modules=3D"normal test efi_gop efi_uga search echo linux all_vi=
deo gfxmenu=0Agfxterm_background gfxterm_menu gfxterm loadenv configfile tp=
m"=0A--disable-shim-lock=0A=0Avia bios set the Secure Boot to setup mode=0A=
=0APrepared sbctl=0Asudo -i=0Asbctl create-keys=0Asbctl enroll-keys -m=0Asb=
ctl verfiy=0A=0A=0AIn addition to the files that need to be signed, I recei=
ved a lot of errors in=0Aresponse related to the files inside /grub=0AThey =
are all the same, so I will insert one example=0Afailed to verify file /boo=
t/grub/x86_64-efi/tpm.mod:=0A/boot/grub/x86_64-efi/tpm.mod: invalid pe head=
er=0A=0Ai signed:=0AVerifying file database and EFI images in /boot...=0A=
=E2=9C=93 /boot/EFI/BOOT/BOOTX64.EFI is signed=0A=E2=9C=93 /boot/EFI/GRUB/g=
rubx64.efi is signed=0A=E2=9C=93 /boot/grub/x86_64-efi/core.efi is signed=
=0A=E2=9C=93 /boot/grub/x86_64-efi/grub.efi is signed=0A=E2=9C=93 /boot/vml=
inuz-linux is signed=0A=0A=0A=0Ai boot in GRUB, grub looks broken visually,=
 like some fonts didn't load, but=0Ait's readable=0AWhen I try to boot into=
 the system GRUB gives an error =0Aerror: verification requested but nobody=
 cares & need to load the kernel=0Afirst=0AI hope the picture is acceptable=
 to you:=0Ahttps://www.radikal.host/i/uO8yxE=0A=0A=0A=0A=0A=0A=0A=0A=0A    =
_______________________________________________________=0A=0AReply to this =
item at:=0A=0A  <https://savannah.gnu.org/bugs/?67455>=0A=0A_______________=
________________________________=0A=D0=A1=D0=BE=D0=BE=D0=B1=D1=89=D0=B5=D0=
=BD=D0=B8=D0=B5 =D0=BE=D1=82=D0=BF=D1=80=D0=B0=D0=B2=D0=BB=D0=B5=D0=BD=D0=
=BE =D0=BF=D0=BE Savannah=0Ahttps://savannah.gnu.org/=0A
--8323329-1663969994-1756039784=:1651364
Content-Type: APPLICATION/pgp-signature; name=signature.asc

-----BEGIN PGP SIGNATURE-----

iHUEABYIAB0WIQQk97aszIMMAvLLwm6qLAuaBUf3TgUCaKsKaAAKCRCqLAuaBUf3
TtqxAP9FzULCULKJz4qfmq4PMDIFbR03DUFexsjKprYfjGdN5gD/V0wpdcgI4ZCS
Yflzun5j7WaY3Cxpy9Sumkucr1XsRg0=
=EK3x
-----END PGP SIGNATURE-----

--8323329-1663969994-1756039784=:1651364--