whatis secure-boot
Secure Boot
Also known as: shim, MOK
A UEFI feature that only runs bootloaders and kernels signed by trusted keys, blocking boot-level malware.
What Is Secure Boot in Linux?
Firmware ships with Microsoft's keys, so Linux distros boot through a small signed loader called shim, which then verifies the distro-signed GRUB and kernel. Unsigned kernel modules, like some out-of-tree drivers, will not load.
For NVIDIA drivers or DKMS modules you can enroll a Machine Owner Key (MOK) and sign modules yourself, or replace the firmware keys entirely with your own.
Example
mokutil --sb-state Learn more about Secure Boot
- Secure Boot Explained: What It Is and How Linux Handles It Secure Boot is a UEFI feature that verifies the digital signature of the bootloader before running it. Most major Linux distributions handle it transparently, but some setups require additional configuration. This guide explains how it works and what to do.
- Secure Boot with Your Own Keys Replacing Microsoft's keys with your own so Secure Boot verifies what you chose rather than what a vendor signed. Including how to avoid bricking the machine.
- NVIDIA Drivers on Linux: Proprietary, Open Modules, and Nouveau Three driver options, a Secure Boot complication, and a DKMS rebuild that has ruined many a reboot. Here is which driver to install and how to keep it working across kernel updates.