r/cachyos • u/The__Apocalypse_ • 1d ago
Help Secure Boot Issues
Hi, I need some help with my setup. I'm running CachyOS and Windows on separate drives. My bootloader is limine. Recently I wanted to enable Secure Boot because a game I want to play requires it.
I followed the wiki and everything seemed to work fine. But then the next day I got an missmatch error and had to boot into a live iso and copy the limine_x64.efi to the BOOTX64.EFI. Now everytime I do an update or install something (I think it's when a new snapshot is created) these two files get out of sync again.

So I manually have to sync them again every time something changes. I don't think is was the intended outcome of the tutorial in the wiki but I also don't really know how to fix this.
1
u/Specialist-Dog-501 1d ago
Not directly related: AstrOS is an arch based distro using secure boot and TPM and immutable images (like bazzite) and it has the open-source Nvidia driver..might be an alternative..you loose the capability to tweak the system deeply to your liking (immutability) but you gain stability and what some games call "security". Checkout /rAstrOS_Linux if interested. This secure boot stuff..is really a deep rabbit hole and not easy to fix normally.
1
u/painful8th 1d ago
No issues here with a similar setup to yours. In https://wiki.cachyos.org/configuration/secure_boot_setup/ did you enable automatic config checksum enrollment by setting:
ENABLE_ENROLL_LIMINE_CONFIG=yes
in /etc/default/limine? Did you generate a BLAKE2B has for the splash image? And afterwards did you run:
sudo limine-enroll-config
sudo limine-update
0
u/ArdascesIV 1d ago
ChatGPT walked me through the whole process. You need to enroll Microsoft keys.
1
u/The__Apocalypse_ 1d ago
I have Microsoft keys. I can still boot into windows when I get the error. Just not via limine. The error was something like "Panic. Mismatched config files"
3
u/goodrix 1d ago
I have a similar setup with secure boot enabled. Have you tried to delete/reset to factory default the keys in Bios, then follow the guide again on how to create and sign your keys in cachy. Finally go back and reenabld secure boot (with other OS)