Everything about secure boot is a mistake.
I would disagree. The idea is great; eliminate preboot malware by trusting the whole boot stack. It has a place in computing and I would like to see it be something easier to work with.
Pretty much everything about how it’s currently implemented is a mistake, I’ll agree with.
Microsoft has unofficial support for ext4 for their EFI partitions on their azure cloud, which in itself is a violation of their standard.
More like who is implementing it. Take MS out of the picture and set it as an open standard.
It is open, oddly enough. It’s just that nobody ships anything other than Microsoft’s keys. You can add your own. It’s just that it is a tedious, manual process.
Depends on the distro! I could do it in 5 minutes with my bazzite installation: https://docs.bazzite.gg/General/Installation_Guide/secure_boot/
Very happy surprise when setting up my new PC :)
Yeah, Ventoy will import its key for you too. If what you’re using doesn’t come with that utility, you’ll be manually entering in public keys. 😭
Oof, I tried alpine for a bit, nothing worked. That was just beyond me for little gain.
Alpine is dead simple if used for what’s it’s good at. The LBU is its best feature. It’s great on shitty ARM boards that digest SD cards. I use it on NUT servers throughout my network.
That is not my use case, I don’t know any of those words !
Now I’m curious. What did you try that didn’t work?
It was on an 08/ish laptop I wanted to just use for simple dvd watching and such. Had a lot of sound and disc issues. I’m a noob tho so went back to mint.
Same here, I run Mint everywhere I can, and the XFCE edition works especially well in old machines.
Alpine is better suited for servers and especially containers, because the images can be really small. If you got enough RAM, there’s an installation mode that runs on it without writing to disk, pretty cool for systems where you want always to reboot in the same state.
Yea I wouldn’t choose a musl/BusyBox distro for my daily driver.
if only secureboot support hibernate
My secure boot with hibernate works perfectly fine, or rather it did work fine before hibernate started freezing my system, secure boot or not.
With Linux? Kernel signed with your own key to get out of lockdown mode restrictions?
There are no lockdown mode restrictions on my system. Kernel is not signed, but i switched to UKIs a couple months ago (hibernation worked fine with these).
It is worth noting that the failure is hibernating, not resuming. Normally hibernate takes ~1 minute with fans spinning at max speed, but it recently started not finishing and instead being stuck on a black screen for more than 30 minutes without the fans running until i run out of patience (i hibernate before i go to sleep or head out) and force power off the system (power button 10 second press on my system).
Did you maybe run out of swap space?
hibernate + amdgpu is unfortunately fucking cursed in my experience.
it worked fine before, so why break now?
5gb ram usage of 64gb total & 0gb used on a 128gb swap partition is quite unlikely to run out of swap space during hibernate
Deciding to turn on secureboot on any distro that doesn’t support it out of the box is always a mistake.
Still have nightmares from that one time i tried doing it under nixOS…







