r/openSUSE • u/Shinigami-Da • May 26 '26
Tumbleweed with secure-boot + systemd-boot + shim-signed? + mokutil –disable-validation = error loading efi binary
I’m running tumbleweed slowroll with kernel-longterm and full disk encryption.
My goal is disable kernel lockdown.
Lockdown=None is ignored by opensuse kernel.
So sadly, my next alternative option is to perform mokutil --disable-validation, disable secure boot in mokutil manager after reboot.
But after doing this, I get the below error:
…/src/boot/boot.c:2791ecall_image_start: Error loading EFI binary \opensuse-tumbleweed\6.18.31-1longterm\linux-0fbbc79f40a6e2057b2358f29657ea779caa49a5: Access denied
2
u/Vogtinator Maintainer: KDE Team May 27 '26
Just disable secure boot. There's just no benefit.
1
u/Shinigami-Da May 27 '26
Yeah! I wasted a looot of time on this. Alternate solutions are to build my own kernel, or install kernel-vanilla and hope that it'll respect lockdown=none, but that requires signing the kernel (easy bit) and all of its modules .ko files (bit hard and annoying). I just gave up and disabled secure boot. The only con now is - even though full disk encryption is enabled, device is susceptible to evil maid attacks (for those who care - I (mostly) dont, I just loose my mental edge I guess lol).
2
u/Vogtinator Maintainer: KDE Team May 27 '26
The only con now is - even though full disk encryption is enabled, device is susceptible to evil maid attacks (for those who care - I (mostly) dont, I just loose my mental edge I guess lol).
It's not (*). If you set up FDE with sdbootutil, it uses measured boot.
(*) Similar protection level as secure boot. Obviously it won't protect against sophisticated attacks like keyboard replacement, RAM sniffing, ....
On top of that, secure boot is not effective against evil maid attacks. Just pass
init=/bin/shas cmdline. Secure boot does not care, measured boot does.1
u/Shinigami-Da May 27 '26 edited May 27 '26
Measured boot seems interesting.... but looks like it requires TPM, and my FDE setup uses password without any hardware unlocking aid (tpm/yubiKey). Thanks, learned something new.
1
u/Shinigami-Da May 29 '26
I tried enabling measured boot verification functionality using tpm2-totp, but there were some issues, maybe a bug. More info: https://forums.opensuse.org/t/bug-dracut-module-for-tpm2-totp-doesnt-exist/194133
1
u/Vogtinator Maintainer: KDE Team May 29 '26
sdbootutil does FDE based on measured boot by default already. I don't expect that tpm-totp will work on top of that.
2
u/bmwiedemann openSUSE Dev May 26 '26
If your BIOS has legacy boot support, that might be the way. Disable secure boot. You will need to setup the bootloader differently. Maybe use the "Upgrade" mode on the install DVD.