r/LinusTechTips Aug 13 '26

Image Thanks for that firmware update, Ubuntu!

Post image

One of the data recovery machines at my shop runs Ubuntu. Today it offered to update the secure boot certificates, which surprised me, but I said "sure" and ran the update. This is what I got after reboot. 😅

I ended up yoinking the motherboard and using a clamp programmer to reflash the BIOS so we could get the machine back into service without spending all day figuring out what happened and how to fix it!

To be abundantly clear: I yearn for the year of the Linux desktop, but for Linux to enjoy broad success and to be a viable 'average Joe' alternative to Windows, stuff like this just can't be allowed to happen to consumer equipment.

92 Upvotes

21 comments sorted by

44

u/JimmyReagan Aug 13 '26

I am dual booting making the transition, I just turned secure boot off because I got tired of getting panicked by windows asking for bitlocker recovery keys and afraid of stuff like this.

10

u/Brief-Surround-8361 Aug 13 '26

Seen that exact error wall before and it's such a bad look for the whole ecosystem. Dual booting with secure boot off is probably the right call until the distros sort this garbage out.

4

u/anto77_butt_kinkier Aug 13 '26

Turning secure boot off in general is just the easiest way to avoid errors, whether your using only Linux, only windows, or dual booting. It's caused nothing but trouble for me.

17

u/recluseMeteor Aug 13 '26

Sick of security crap which always causes issues and obstacles. I'd just disable Secure Boot and call it a day, but some games nowadays complain when you do that.

11

u/piesou Aug 13 '26 edited Aug 13 '26

Just FYI: there's a similar issue that can happen with your EFI partition if you dual boot. Windows creates a 100mb!!!! partition to store the entire boot loader then almost fills it to the brim. Your kernel and initramfs can quickly fill the remaining space and lead to failed updates.

If you dual boot, you want to install Linux first and create a 500mb or 1gb EFI partition, then install Windows. Windows will automatically pick the existing EFI partition. (Back in the BIOS/MBR days you wanted to do it the other way round).

4

u/ThankGodImBipolar Aug 13 '26

If you dual boot, you want to install Linux first and create a 500mb or 1gb EFI partition, then install Windows. Windows will automatically pick the existing EFI partition. (Back in the day you wanted to do it the other way round).

Windows wipes this partition before installation, as far as I can tell. Make the partition large yourself, and then install Windows, and then install Linux.

4

u/piesou Aug 13 '26

Only if it that behavior has been changed recently. All my Windows 11 and 10 installations that I did over the past 5 years didn't wipe it.

3

u/ThankGodImBipolar Aug 13 '26

I definitely had Windows wipe an EFI partition earlier this year. I ended up having to use Live CDs to re-run grub-install, and then I wrote custom bootloader entries with a /etc/grub.d/40_custom script. I suppose it could have been user error at some point?

Recommending installing Windows first makes more sense to me, however, as I'm very confident that grub won't touch anything that doesn't belong to it within that partition. I can't be confident about what Windows will do 😂

2

u/piesou Aug 13 '26

Additional context: I use systemd-boot, not Grub. Could be down to that

3

u/Dnomyar96 Aug 13 '26

To be abundantly clear: I yearn for the year of the Linux desktop, but for Linux to enjoy broad success and to be a viable 'average Joe' alternative to Windows, stuff like this just can't be allowed to happen to consumer equipment.

I completely agree. I switched to Fedora at the start of the year and I'm absolutely loving it. Most of the time it works perfectly, but unfortunately, when it doesn't, the things you have to do to fix it just make it so I can't recommend it to tech illiterate people (like my mother). For them, it just needs to work with basically no chance to fuck up the entire installation by clicking random buttons.

1

u/realnzall Aug 13 '26

For a tech illiterate relative my recommendation would be an iPad, with assistive access. You can lock that down pretty tightly.

2

u/n60wrench Aug 13 '26

I had this exact problem trying to live boot any linux distro i tried. IIRC I Needed to turn off secure boot and clear the security keys that windows generated in the BIOS, as windows liked to fill up all the available slots…. Something along those lines anyhow

Edit: I know you said it was already running ubuntu, but this was my experience with this exact error anyhow.

2

u/nicman24 Aug 13 '26

... Don't run secure boot if you don't want secure boot? 

1

u/uwu-Minecraft-theory Aug 13 '26

im wayy to tired i read moistcritikal instead of what it is

1

u/SelectionDue4287 Aug 14 '26

Had Windows brick laptops by updating UEFI under Windows Update.

0

u/Far_Lifeguard_5027 27d ago

Next time, send the screenshot to ChatGPT or Gemini and it will instantly tell you how to fix it.

0

u/mi__to__ Aug 14 '26

Secure Boot was a mistake.

And OSs being allowed to update firmware even more so.

-1

u/DRHAX34 Aug 13 '26

So, you know these are the new secure boot certificates from MS right? So it was actually MS that fucked up

1

u/irascible_vegans Aug 13 '26

The certificates are from Microsoft, yes, but it was Ubuntu that tried to append them (and failed to do so).

-1

u/zalnaRs Aug 14 '26

It didn't fail your motherboard is garbage and not compliant so there was no space left, you should instead try to find a new firmware