Skip to main content

You are not logged in. Your edit will be placed in a queue until it is peer reviewed.

We welcome edits that make the post easier to understand and more valuable for readers. Because community members review edits, please try to make the post substantially better than how you found it, for example, by fixing grammar or adding additional resources and hyperlinks.

2
  • It sounds like you have removed the shim's certificate from the UEFI db storage. Run mokutil --db should show you a list of carious certs, of which Ubuntu's shim cert and your own cert have to be loaded, one for the shim, the other for the kernel. Commented May 6, 2022 at 18:25
  • I don't think so. As far as I understand, shim is signed with Microsoft's keys and only they need to be in DB. Once shim is running, it has its own key DB and my key is enrolled there. I have just checked, and in 'db' there are only MS' and Lenovo's keys, but not Canonical's - still their kerne; boots fine. Commented May 7, 2022 at 19:32