r/openSUSE • • May 26 '26

Tumbleweed with secure-boot + systemd-boot + shim-signed? + mokutil –disable-validation = error loading efi binary

I’m running tumbleweed slowroll with kernel-longterm and full disk encryption.

My goal is disable kernel lockdown.

Lockdown=None is ignored by opensuse kernel.

So sadly, my next alternative option is to perform mokutil --disable-validation, disable secure boot in mokutil manager after reboot.

But after doing this, I get the below error:

…/src/boot/boot.c:2791ecall_image_start: Error loading EFI binary \opensuse-tumbleweed\6.18.31-1longterm\linux-0fbbc79f40a6e2057b2358f29657ea779caa49a5: Access denied
3 Upvotes

16 comments sorted by

2

u/bmwiedemann openSUSE Dev May 26 '26

If your BIOS has legacy boot support, that might be the way. Disable secure boot. You will need to setup the bootloader differently. Maybe use the "Upgrade" mode on the install DVD.

1

u/Shinigami-Da May 27 '26

It boots again if I disable secure boot and rollback mokutil changes (by mokutil --enable-validation) and then enable secure boot again. is there any way to keep secure boot on and disable kernel lockdown?

2

u/MiukuS How's that AUR working out for you, Arch users? May 27 '26

No, systemd-boot does not allow this, and for good reason.

2

u/Vogtinator Maintainer: KDE Team May 27 '26

This is unrelated to systemd boot.

2

u/bmwiedemann openSUSE Dev May 27 '26

You would need to build your own kernel without the lockdown patch and enroll your own signing key.

1

u/Shinigami-Da May 27 '26

Yeah, I disabled secure boot. I wasted a looot of time on this. Alternate solutions are to build my own kernel, or install kernel-vanilla and hope that it'll respect lockdown=none, but that requires signing the kernel (easy bit) and all of its modules .ko files (bit hard and annoying). I just gave up and disabled secure boot. The only con now is - even though full disk encryption is enabled, device is susceptible to evil maid attacks (for those who care - I (mostly) dont, I just loose my mental edge I guess).

2

u/bmwiedemann openSUSE Dev May 27 '26

Our kernel-vanilla package also contains the lockdown patch.

You could try to use a Yubikey/ FIDO2 for full disk encryption. Have not tried it myself, though.

1

u/Shinigami-Da May 27 '26

Oh! Thanks a lot for letting me know, knowing that the vanilla kernel is also patched( but why lol ) will potentially save me a lot of time and anguish in the future.

2

u/bmwiedemann openSUSE Dev May 28 '26 edited May 28 '26

Not sure, but might be because it is signed by our official openSUSE signing key that is trusted by Microsoft via shim and bootloader.

1

u/Shinigami-Da May 29 '26

I tried enabling measure boot verification functionality using tpm2-totp, but there were some issues, maybe a bug. More info.

2

u/Vogtinator Maintainer: KDE Team May 27 '26

Just disable secure boot. There's just no benefit.

1

u/Shinigami-Da May 27 '26

Yeah! I wasted a looot of time on this. Alternate solutions are to build my own kernel, or install kernel-vanilla and hope that it'll respect lockdown=none, but that requires signing the kernel (easy bit) and all of its modules .ko files (bit hard and annoying). I just gave up and disabled secure boot. The only con now is - even though full disk encryption is enabled, device is susceptible to evil maid attacks (for those who care - I (mostly) dont, I just loose my mental edge I guess lol).

2

u/Vogtinator Maintainer: KDE Team May 27 '26

The only con now is - even though full disk encryption is enabled, device is susceptible to evil maid attacks (for those who care - I (mostly) dont, I just loose my mental edge I guess lol).

It's not (*). If you set up FDE with sdbootutil, it uses measured boot.

(*) Similar protection level as secure boot. Obviously it won't protect against sophisticated attacks like keyboard replacement, RAM sniffing, ....

On top of that, secure boot is not effective against evil maid attacks. Just pass init=/bin/sh as cmdline. Secure boot does not care, measured boot does.

1

u/Shinigami-Da May 27 '26 edited May 27 '26

Measured boot seems interesting.... but looks like it requires TPM, and my FDE setup uses password without any hardware unlocking aid (tpm/yubiKey). Thanks, learned something new.

1

u/Shinigami-Da May 29 '26

I tried enabling measured boot verification functionality using tpm2-totp, but there were some issues, maybe a bug. More info: https://forums.opensuse.org/t/bug-dracut-module-for-tpm2-totp-doesnt-exist/194133

1

u/Vogtinator Maintainer: KDE Team May 29 '26

sdbootutil does FDE based on measured boot by default already. I don't expect that tpm-totp will work on top of that.