How to enforce Secure Boot on the following setup : ubunutu 16.04 with grub2

The name of the pictureThe name of the pictureThe name of the pictureClash Royale CLAN TAG#URR8PPP








up vote
0
down vote

favorite












Problem:
Unsigned kernels boot up on UEFI Secure Boot enabled machine



Setup:

OS: Canonical signed Ubuntu 16.04

GRUB2: Canonical signed 2.02~beta2-36ubuntu3.17

SHIM: Microsoft signed, Canonical keys in DB



Normal secure boot works and confirmed via demsg BOOT_IMAGE log to observe *...efi.signed image loads and 'sbverify' to check whether the same is signed with Canonical key.



I intend to disable unsigned kernel load on a UEFI machine with secure boot enabled. I referred to #1401532.
and other links related to the issue.



Is there any way to force only signed kernel load and block all unsigned kernel with the current setup mentioned above ?
with minimal changes in grub.cfg, any patch, etc.



Thanks,
AT







share|improve this question


























    up vote
    0
    down vote

    favorite












    Problem:
    Unsigned kernels boot up on UEFI Secure Boot enabled machine



    Setup:

    OS: Canonical signed Ubuntu 16.04

    GRUB2: Canonical signed 2.02~beta2-36ubuntu3.17

    SHIM: Microsoft signed, Canonical keys in DB



    Normal secure boot works and confirmed via demsg BOOT_IMAGE log to observe *...efi.signed image loads and 'sbverify' to check whether the same is signed with Canonical key.



    I intend to disable unsigned kernel load on a UEFI machine with secure boot enabled. I referred to #1401532.
    and other links related to the issue.



    Is there any way to force only signed kernel load and block all unsigned kernel with the current setup mentioned above ?
    with minimal changes in grub.cfg, any patch, etc.



    Thanks,
    AT







    share|improve this question
























      up vote
      0
      down vote

      favorite









      up vote
      0
      down vote

      favorite











      Problem:
      Unsigned kernels boot up on UEFI Secure Boot enabled machine



      Setup:

      OS: Canonical signed Ubuntu 16.04

      GRUB2: Canonical signed 2.02~beta2-36ubuntu3.17

      SHIM: Microsoft signed, Canonical keys in DB



      Normal secure boot works and confirmed via demsg BOOT_IMAGE log to observe *...efi.signed image loads and 'sbverify' to check whether the same is signed with Canonical key.



      I intend to disable unsigned kernel load on a UEFI machine with secure boot enabled. I referred to #1401532.
      and other links related to the issue.



      Is there any way to force only signed kernel load and block all unsigned kernel with the current setup mentioned above ?
      with minimal changes in grub.cfg, any patch, etc.



      Thanks,
      AT







      share|improve this question














      Problem:
      Unsigned kernels boot up on UEFI Secure Boot enabled machine



      Setup:

      OS: Canonical signed Ubuntu 16.04

      GRUB2: Canonical signed 2.02~beta2-36ubuntu3.17

      SHIM: Microsoft signed, Canonical keys in DB



      Normal secure boot works and confirmed via demsg BOOT_IMAGE log to observe *...efi.signed image loads and 'sbverify' to check whether the same is signed with Canonical key.



      I intend to disable unsigned kernel load on a UEFI machine with secure boot enabled. I referred to #1401532.
      and other links related to the issue.



      Is there any way to force only signed kernel load and block all unsigned kernel with the current setup mentioned above ?
      with minimal changes in grub.cfg, any patch, etc.



      Thanks,
      AT









      share|improve this question













      share|improve this question




      share|improve this question








      edited May 16 at 4:29

























      asked May 15 at 14:15









      aditya ece

      12




      12

























          active

          oldest

          votes











          Your Answer







          StackExchange.ready(function()
          var channelOptions =
          tags: "".split(" "),
          id: "89"
          ;
          initTagRenderer("".split(" "), "".split(" "), channelOptions);

          StackExchange.using("externalEditor", function()
          // Have to fire editor after snippets, if snippets enabled
          if (StackExchange.settings.snippets.snippetsEnabled)
          StackExchange.using("snippets", function()
          createEditor();
          );

          else
          createEditor();

          );

          function createEditor()
          StackExchange.prepareEditor(
          heartbeatType: 'answer',
          convertImagesToLinks: true,
          noModals: false,
          showLowRepImageUploadWarning: true,
          reputationToPostImages: 10,
          bindNavPrevention: true,
          postfix: "",
          onDemand: true,
          discardSelector: ".discard-answer"
          ,immediatelyShowMarkdownHelp:true
          );



          );








           

          draft saved


          draft discarded


















          StackExchange.ready(
          function ()
          StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2faskubuntu.com%2fquestions%2f1036553%2fhow-to-enforce-secure-boot-on-the-following-setup-ubunutu-16-04-with-grub2%23new-answer', 'question_page');

          );

          Post as a guest



































          active

          oldest

          votes













          active

          oldest

          votes









          active

          oldest

          votes






          active

          oldest

          votes










           

          draft saved


          draft discarded


























           


          draft saved


          draft discarded














          StackExchange.ready(
          function ()
          StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2faskubuntu.com%2fquestions%2f1036553%2fhow-to-enforce-secure-boot-on-the-following-setup-ubunutu-16-04-with-grub2%23new-answer', 'question_page');

          );

          Post as a guest













































































          Popular posts from this blog

          pylint3 and pip3 broken

          Missing snmpget and snmpwalk

          How to enroll fingerprints to Ubuntu 17.10 with VFS491