Secure Boot Explained: What It Is and How Linux Handles It

Secure Boot Explained: What It Is and How Linux Handles It

Secure Boot is one of those features that either works transparently or becomes an obstacle depending on what Linux setup you are building. Understanding how it works helps you know when to leave it enabled, when to disable it, and how to work with it when installing drivers or custom kernels.

The problem Secure Boot solves

A bootkit is malware that installs itself before the operating system loads. Because the OS security tools have not started yet, the bootkit can hide from antivirus software and intercept system calls. Bootkits are persistent — reinstalling the OS does not remove them because they sit in the bootloader, not the filesystem.

Secure Boot addresses this by having the UEFI firmware verify the bootloader’s digital signature before executing it. If the signature is absent or invalid, the firmware refuses to boot. This prevents an attacker who has compromised your system from replacing the bootloader with a malicious version.

How the Secure Boot chain works

UEFI firmware startup
        |
        v
Check bootloader signature against:
  - Platform Key (PK)      <- set by hardware manufacturer
  - Key Exchange Key (KEK) <- Microsoft + manufacturer keys
  - Signature Database (db)<- trusted bootloader signatures
  - MOK database           <- user-enrolled keys
        |
        v
Signature valid?  --> No --> REFUSE TO BOOT
        |
       Yes
        v
Load shim (signed by Microsoft key)
        |
        v
shim loads GRUB (signed by distro key or MOK key)
        |
        v
GRUB loads Linux kernel (signed by distro key)
        |
        v
Kernel loads signed modules only

The default UEFI key database already trusts Microsoft’s key. Linux distributions obtain their shim signed by Microsoft, which is why major distributions work with Secure Boot enabled on any standard PC.

Checking Secure Boot status

# Method 1: mokutil (most straightforward)
mokutil --sb-state
# SecureBoot enabled
# or
# SecureBoot disabled
# or
# This system doesn't support Secure Boot

# Method 2: bootctl (systemd-boot)
bootctl status | grep -i "secure boot"
# Secure Boot: enabled (user)

# Method 3: read the EFI variable directly
# The last byte: 01 = enabled, 00 = disabled
cat /sys/firmware/efi/efivars/SecureBoot-8be4df61-93ca-11d2-aa0d-00e098032b8c \
  | xxd | tail -1

# Method 4: from dmesg (shows at boot)
dmesg | grep -i "secure boot"
# [    0.000000] secureboot: Secure boot enabled

# Method 5: from the UEFI firmware at startup
# Enter UEFI setup (Del, F2, F10 at startup)
# Look under Security or Boot tab

Distributions and Secure Boot support

DistributionSecure Boot supportNotes
Ubuntu (22.04+)Native, no action neededSigned shim; Nvidia driver auto-enrolls MOK
Fedora (37+)Native, no action neededSigned shim; fully supported
Debian (10+)Native with signed shimInstall shim-signed if not present
Linux Mint (21+)Native (inherits Ubuntu shim)Works out of the box
openSUSENativeSigned shim included
Arch LinuxNot supported nativelyRequires manual key enrollment or disable Secure Boot
ManjaroPartialSigned shim available but some kernels are not signed
NixOSManual setup required
GentooManual setup requiredCustom kernel needs manual signing

Working with MOK (Machine Owner Key)

The MOK database lets you enroll your own keys into the Secure Boot trust chain without modifying the main UEFI Secure Boot databases.

Checking enrolled MOK keys

# List all enrolled MOK keys
mokutil --list-enrolled

# Check what the shim trusts
mokutil --list-enrolled | grep -A5 "Subject:"

# List keys pending enrollment (waiting for reboot confirmation)
mokutil --list-new

Enrolling a key (for custom modules or kernels)

# Generate a key pair
openssl req -new -x509 -newkey rsa:2048 -keyout MOK.key \
  -out MOK.crt -days 3650 -subj "/CN=My Secure Boot Key/" -nodes

# Enroll the certificate
sudo mokutil --import MOK.crt
# You will be prompted to set a one-time password
# Enter a password you will remember -- you will need it at next reboot

# Reboot
# The MOK management screen will appear before GRUB
# Select "Enroll MOK" -> "Continue" -> enter your password
# The key is now enrolled

# Sign a kernel module with the new key
sudo /usr/src/linux-headers-$(uname -r)/scripts/sign-file \
  sha256 MOK.key MOK.crt /lib/modules/$(uname -r)/updates/mymodule.ko

Ubuntu: automatic module signing

Ubuntu automates MOK enrollment for DKMS modules (Nvidia, VirtualBox, etc.):

# Install Nvidia proprietary driver on Ubuntu with Secure Boot enabled
sudo apt install nvidia-driver-550

# The system generates a machine-specific signing key at /var/lib/shim-signed/mok/
# MOK.key and MOK.der

# Prompts you to set a one-time password during installation
# On next reboot: MOK enrollment screen appears
# Select "Enroll MOK" -> enter the password you set
# After reboot, the Nvidia module loads correctly

# Check that the module is signed
sudo modinfo nvidia | grep sig
# sig_id: PKCS#7
# sig_key: ...
# sig_hashalgo: sha512

Disabling Secure Boot

Some situations genuinely require disabling Secure Boot:

  • Installing a distribution without a signed shim
  • Loading unsigned kernel modules that cannot be signed
  • Using a custom-compiled kernel without signing it
  • Debugging boot issues where Secure Boot may be the cause

To disable Secure Boot, enter the UEFI firmware setup at startup (the key varies by manufacturer: Del, F2, F10, or Esc). Find the Secure Boot setting (usually under Security, Boot, or Authentication) and set it to Disabled. Save and exit.

# Verify it is disabled after rebooting
mokutil --sb-state
# SecureBoot disabled

# Note: on Windows 11 machines, disabling Secure Boot
# may cause Windows to refuse to boot.
# Check if Windows requires Secure Boot before disabling.

Secure Boot and the Nvidia driver

The Nvidia proprietary driver ships as a kernel module that must be signed when Secure Boot is enabled. Modern distributions handle this automatically:

Ubuntu: the ubuntu-drivers tool manages key generation and MOK enrollment automatically. You will see a one-time password prompt and a MOK enrollment screen on first reboot after driver installation.

Fedora: akmods handles signing. The akmods-ostree and akmods packages use keys in /etc/akmods/ to sign modules.

Arch: requires manual steps. Install nvidia-dkms, then use sbctl or the manual sign-file approach above.

# Ubuntu: install Nvidia and let it handle Secure Boot automatically
sudo apt install nvidia-driver-550
# Follow prompts, reboot, enroll MOK at the blue screen

# Check after reboot
nvidia-smi    # should show GPU info if driver loaded correctly
lsmod | grep nvidia

Secure Boot and custom kernels

If you compile your own kernel and want Secure Boot to remain enabled, you need to sign the kernel image:

# Sign a custom kernel image
sudo sbsign --key MOK.key --cert MOK.crt --output vmlinuz-signed vmlinuz

# Install the signed kernel
sudo cp vmlinuz-signed /boot/vmlinuz-$(make kernelversion)-custom

# Update GRUB
sudo update-grub

# Alternatively, use sbctl (a modern Secure Boot management tool)
# Available on Arch and can be installed on other distributions
sudo pacman -S sbctl          # Arch
sbctl status
sbctl create-keys
sbctl enroll-keys --microsoft
sbctl sign /boot/EFI/BOOT/BOOTX64.EFI
sbctl sign /boot/EFI/Linux/linux.efi

Frequently Asked Questions

What does Secure Boot do?

Secure Boot is a UEFI security feature that verifies the cryptographic signature of the bootloader before the firmware hands control to it. At startup, the UEFI firmware checks the bootloader’s signature against a database of trusted keys stored in UEFI firmware variables. If the signature matches a trusted key, boot proceeds. If the signature is not recognized or is absent, the firmware refuses to boot and displays an error. The goal is to prevent bootkits: malware that installs itself in the bootloader and runs before the OS can load security software. Secure Boot does not protect against malware that runs after the OS loads; it only protects the boot chain.

Does Secure Boot prevent Linux from booting?

Not on most modern distributions. Ubuntu, Fedora, Debian, openSUSE, and other major distributions ship with a pre-signed shim bootloader. The shim is signed by Microsoft’s Secure Boot key, which is trusted by virtually all UEFI firmware. The shim then loads GRUB, which is signed by the distribution’s own key stored in the MOK (Machine Owner Key) database. This chain of trust allows these distributions to boot with Secure Boot enabled without requiring users to disable it. Distributions that do not have a signed shim — including some smaller or custom distributions, and custom kernels — require Secure Boot to be disabled or require manual enrollment of keys using mokutil.

What is MOK (Machine Owner Key)?

MOK (Machine Owner Key) is an extension to Secure Boot that allows users to enroll their own signing keys. The MOK database is a secondary key database maintained in UEFI firmware variables, separate from the main Secure Boot database. You can add your own keys to the MOK database using the mokutil tool, which means you can sign your own bootloaders or kernel modules and have them accepted by Secure Boot. This is used by distributions like Ubuntu when you install a third-party kernel module (such as the Nvidia proprietary driver or VirtualBox): the module is signed with a machine-specific key, and the user is prompted to enroll that key in MOK during the next reboot.

Should I disable Secure Boot to install Linux?

For major distributions (Ubuntu, Fedora, Debian, Linux Mint, openSUSE), disabling Secure Boot is not necessary and is not recommended. These distributions support Secure Boot through their signed shim bootloader and leaving it enabled provides the boot-chain protection it was designed for. Disable Secure Boot only when: you are installing a distribution that does not have a signed shim; you are loading a kernel module that cannot be signed (some out-of-tree drivers); you are using a custom-compiled kernel; or you are setting up a system where you control the entire boot chain manually. On Windows 11 machines, Secure Boot is a requirement to run Windows — disabling it prevents Windows 11 from running, which matters in dual-boot setups.

How do I check if Secure Boot is enabled?

From Linux, run: mokutil —sb-state. It will output “SecureBoot enabled” or “SecureBoot disabled.” You can also check: bootctl status | grep -i secure, or cat /sys/firmware/efi/efivars/SecureBoot-8be4df61-93ca-11d2-aa0d-00e098032b8c | xxd | tail -1 — if the last byte is 01, Secure Boot is enabled. From Windows, open System Information (msinfo32) and look for “Secure Boot State” in the right panel. At boot time, you can also see Secure Boot status in the UEFI firmware setup screen, usually under a Security tab.

How do I sign a kernel module for Secure Boot?

When Secure Boot is enabled, the kernel will only load modules that are signed. Official distribution kernels and their modules are pre-signed. For third-party modules (Nvidia driver, VirtualBox, DKMS modules), you need to sign them with a key enrolled in the MOK database. On Ubuntu and Debian, the process is mostly automated: when you install a DKMS package (like nvidia-dkms), the system generates a machine-specific signing key, signs the module, and prompts you to enroll the key in MOK on the next reboot (via the MOK enrollment screen that appears before GRUB). On Fedora, a similar automated process handles this. For manual signing: openssl genrsa -out signing.key 4096, openssl req -new -x509 -sha256 -key signing.key -out signing.crt -days 3650, mokutil —import signing.crt (enroll the key), then use the sign-file script from linux-headers to sign the module.