Bug#1127556: grub-efi-amd64-signed: 'shim_lock verifier_init:177:prohibited by secure boot policy' error

Adilson dos Santos Dantas <[email protected]> Mon, 9 Feb 2026 16:46:15 -0300
Newsgroups gmane.linux.debian.ports.amd64
Message-ID <CAEsAu2NbkTJvqP4C6M2ti0Zeb9QaqYv7498X_qT=+nRzXeNEfQ__34475.5804793508$1770666520$gmane$org@mail.gmail.com>
--0000000000007df1ce064a6966b0
Content-Type: text/plain; charset="UTF-8"

Package: grub-efi-amd64-unsigned
Version: 1+2.14+1
Severity: normal
X-Debbugs-Cc: [email protected]
User: [email protected]
Usertags: amd64

Dear Maintainer,

I got this error after updating grub and it appears after a kernel update.

It can be reproduced by these steps.

Update grub2 and grub-efi-amd64-signed to 2.14-1

Install any new kernel or

Run the following commands

update-grub
grub-install

Reboot and, for a few seconds, it's throw this error:

grub-core/kern/efi/sb.c/shim_lock verifier_init:177:prohibited by secure
boot policy

And it boots normally after this error.

Reverting back to 2.14~git20250718.0e36779+2 fixes this.


-- System Information:
Debian Release: forky/sid
  APT prefers unstable
  APT policy: (500, 'unstable')
Architecture: amd64 (x86_64)
Foreign Architectures: i386

Kernel: Linux 6.19.0 (SMP w/8 CPU threads; PREEMPT)
Kernel taint flags: TAINT_PROPRIETARY_MODULE, TAINT_OOT_MODULE
Locale: LANG=pt_BR.UTF-8, LC_CTYPE=pt_BR.UTF-8 (charmap=UTF-8),
LANGUAGE=pt_BR:pt:en
Shell: /bin/sh linked to /usr/bin/dash
Init: systemd (via /run/systemd/system)

Versions of packages grub-efi-amd64-signed depends on:
ii  grub2-common  2.14-1

Versions of packages grub-efi-amd64-signed recommends:
ii  shim-signed  1.47+15.8-1

grub-efi-amd64-signed suggests no packages.

Versions of packages grub-efi-amd64-unsigned depends on:
ii  grub2-common  2.14-1

-- no debconf information

-- 
Adilson dos Santos Dantas
https://www.adilson.net.br
https://bsky.adilson.net.br

--0000000000007df1ce064a6966b0
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div>Package: grub-efi-amd64-unsigned<br>Version: 1+2.14+1=
<br>Severity: normal<br>X-Debbugs-Cc: <a href=3D"mailto:debian-amd64@lists.=
debian.org">[email protected]</a><br>User: <a href=3D"mailto:de=
[email protected]">[email protected]</a><br>Usertags:=
 amd64<br><br>Dear Maintainer,<br><br>I got this error after updating grub =
and it appears after a kernel update.<br><br>It can be reproduced by these =
steps.<br><br>Update grub2 and grub-efi-amd64-signed to 2.14-1<br><br>Insta=
ll any new kernel or<br><br>Run the following commands<br><br>update-grub<b=
r>grub-install<br><br>Reboot and, for a few seconds, it&#39;s throw this er=
ror:<br><br>grub-core/kern/efi/sb.c/shim_lock verifier_init:177:prohibited =
by secure boot policy<br><br>And it boots normally after this error.<br><br=
>Reverting back to 2.14~git20250718.0e36779+2 fixes this.<br><br><br>-- Sys=
tem Information:<br>Debian Release: forky/sid<br>=C2=A0 APT prefers unstabl=
e<br>=C2=A0 APT policy: (500, &#39;unstable&#39;)<br>Architecture: amd64 (x=
86_64)<br>Foreign Architectures: i386<br><br>Kernel: Linux 6.19.0 (SMP w/8 =
CPU threads; PREEMPT)<br>Kernel taint flags: TAINT_PROPRIETARY_MODULE, TAIN=
T_OOT_MODULE<br>Locale: LANG=3Dpt_BR.UTF-8, LC_CTYPE=3Dpt_BR.UTF-8 (charmap=
=3DUTF-8), LANGUAGE=3Dpt_BR:pt:en<br>Shell: /bin/sh linked to /usr/bin/dash=
<br>Init: systemd (via /run/systemd/system)<br><br>Versions of packages gru=
b-efi-amd64-signed depends on:<br>ii =C2=A0grub2-common =C2=A02.14-1<br><br=
>Versions of packages grub-efi-amd64-signed recommends:<br>ii =C2=A0shim-si=
gned =C2=A01.47+15.8-1<br><br>grub-efi-amd64-signed suggests no packages.<b=
r><br>Versions of packages grub-efi-amd64-unsigned depends on:<br>ii =C2=A0=
grub2-common =C2=A02.14-1<br><br>-- no debconf information<br></div><div><b=
r></div><span class=3D"gmail_signature_prefix">-- </span><br><div dir=3D"lt=
r" class=3D"gmail_signature" data-smartmail=3D"gmail_signature"><div dir=3D=
"ltr"><div>Adilson dos Santos Dantas</div><div><a href=3D"https://www.adils=
on.net.br" target=3D"_blank">https://www.adilson.net.br</a></div><div><a hr=
ef=3D"https://bsky.adilson.net.br" target=3D"_blank">https://bsky.adilson.n=
et.br</a></div></div></div></div>

--0000000000007df1ce064a6966b0--