Hello Andre, Steve,

On 07/07/2024 17:41, Steve McIntyre wrote:
On Sun, Jul 07, 2024 at 12:47:28PM +0200, Andre Gompel wrote:
The answer is the typical message "Verifying SBAT shim failed, etc...."
Let me add that with the very same hardware, and software (sha256sum
validation, and very reliable Fedora media writer), everything works fine with
two other distros Fedora, and the latest Open Suse Leap, both shim-EFI signed.

> What exact OSes have you booted on this hardware in the last 6 months
> or so? It's likely that one of those has revoked older versions of
> shim.

The latest openSUSE Leap contains shim 15.8, which causes this issue.
https://download.opensuse.org/distribution/leap/15.6/repo/oss/x86_64/

You can see the shim lockdown being requested:

cat /sys/firmware/efi/efivars/SbatLevelRT*

The output (after installing openSUSE 15.6 LEAP) is:
sbat,1,2024010900
shim,4
grub,3
grub.debian,4

The line 'shim,4' causes the mentioned error message.

As Steve already wrote, the next stable version will fix this.

If you are unable to access the UEFI firmware, and to reset the boot keys, you can't boot many other ISO files either (e.g. older versions of LEAP).

With kind regards,
Roland Clobus

Attachment: OpenPGP_signature.asc
Description: OpenPGP digital signature

Reply via email to