whatis secure-boot

Secure Boot

Also known as: shim, MOK

A UEFI feature that only runs bootloaders and kernels signed by trusted keys, blocking boot-level malware.

What Is Secure Boot in Linux?

Firmware ships with Microsoft's keys, so Linux distros boot through a small signed loader called shim, which then verifies the distro-signed GRUB and kernel. Unsigned kernel modules, like some out-of-tree drivers, will not load.

For NVIDIA drivers or DKMS modules you can enroll a Machine Owner Key (MOK) and sign modules yourself, or replace the firmware keys entirely with your own.

Example

mokutil --sb-state