From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-0.5 required=3.0 tests=DKIM_ADSP_CUSTOM_MED, DKIM_INVALID,DKIM_SIGNED,FREEMAIL_FORGED_FROMDOMAIN,FREEMAIL_FROM, HEADER_FROM_DIFFERENT_DOMAINS,MAILING_LIST_MULTI,SPF_HELO_NONE,SPF_PASS, URIBL_BLOCKED autolearn=no autolearn_force=no version=3.4.0 Received: from mail.kernel.org (mail.kernel.org [198.145.29.99]) by smtp.lore.kernel.org (Postfix) with ESMTP id 151F6C3A59E for ; Mon, 2 Sep 2019 21:02:25 +0000 (UTC) Received: from shelob.surriel.com (shelob.surriel.com [96.67.55.147]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mail.kernel.org (Postfix) with ESMTPS id B0D8621670 for ; Mon, 2 Sep 2019 21:02:24 +0000 (UTC) Authentication-Results: mail.kernel.org; dkim=fail reason="signature verification failed" (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="gpgpoy+M" DMARC-Filter: OpenDMARC Filter v1.3.2 mail.kernel.org B0D8621670 Authentication-Results: mail.kernel.org; dmarc=fail (p=none dis=none) header.from=gmail.com Authentication-Results: mail.kernel.org; spf=fail smtp.mailfrom=kernelnewbies-bounces@kernelnewbies.org Received: from localhost ([::1] helo=shelob.surriel.com) by shelob.surriel.com with esmtp (Exim 4.92) (envelope-from ) id 1i4tSf-0001VM-G0; Mon, 02 Sep 2019 17:02:05 -0400 Received: from mail-io1-xd2f.google.com ([2607:f8b0:4864:20::d2f]) by shelob.surriel.com with esmtps (TLSv1.2:ECDHE-RSA-AES128-GCM-SHA256:128) (Exim 4.92) (envelope-from ) id 1i4tSb-0001VG-Rz for kernelnewbies@kernelnewbies.org; Mon, 02 Sep 2019 17:02:02 -0400 Received: by mail-io1-xd2f.google.com with SMTP id j5so31290965ioj.8 for ; Mon, 02 Sep 2019 14:01:59 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:reply-to:from:date:message-id:subject:to; bh=d+SsDGganyS0gl6R9I1jmf8tVCxYTj+IDzuv0j0/TV8=; b=gpgpoy+M2eJi3kHndSACc+ROQD590WzDDzZY0fQno/RV4gNq/O0BHW1OxMqWdmKvCq kpJCMORCxYS7Vb5j6dofHoY/sk2kuwAjiXHTDpf+x2DMvyb+cE+3XvMDkBpFnhmLfY36 QwLJuVoq9D0H0RL0pXhJclXOnuBjdn6GN4JXj6JG5l2sS6UZvMMsMLiDIf1EBl5vOp4z gVlnhc27XT/xv09s6JavqgPRDmri6GTiYmi2z1GzqCtTske9RHVhkJBqTS2A0J0lSTHk +fBT7lOJ3mo7VDcWEULnJdI798DwGXYIhJY71iTX4LCEGp1a8ExbOZ713/L0px6sR1R+ 4q6g== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:reply-to:from:date:message-id :subject:to; bh=d+SsDGganyS0gl6R9I1jmf8tVCxYTj+IDzuv0j0/TV8=; b=tMrDJKmBVNWtWLp1xqCNLdZHAUIapNM/pYEAOnr9E7W1ovQE6Ytkva+a0ZVTpiw90V VYGrtNwMHnQpoVmvnY2c4Tc9dbkTRflxse1xvLtjuJA7ZeXcLcHpUUoBE/fQnBlVoqV2 h9G0zXLMbiW9/0y900D0iH6gRGoswy3XuYH7ozxV/UbGERL3k/Te6/IdyoBGNl1GySZs XP6VHaxHocx+62po5WkLX5z+dQ4xIg3o7/tu6rLUxbsRPgs9bQRLR/m7V93akMiIg/eq xWJPU6sdOBOQJyKOxSpZ7Q9QbRbfqY+UXtKK3/4aNXaa48LuDnei/lJ5pcnndoiEFllb QeBw== X-Gm-Message-State: APjAAAWMOcEeD+M231gUycTAazrcksvIjaGowvY5FXFhPHfF7vI5jS0/ 2yBQwcHUYQCpfLfg52LVsKpL91jf5QJoW7TnaQbFkzWB X-Google-Smtp-Source: APXvYqyAwZE3HyEkygltFdRqNZJkooNyhns+1YpJZxJN9C3xIUEPL+15TcqogotcapYhXRKV3uKgIjhtxWj9SBSwgXI= X-Received: by 2002:a6b:d006:: with SMTP id x6mr35443620ioa.218.1567458057921; Mon, 02 Sep 2019 14:00:57 -0700 (PDT) MIME-Version: 1.0 From: Jeffrey Walton Date: Mon, 2 Sep 2019 17:00:29 -0400 Message-ID: Subject: Disable kernel signature checks during boot on Ubuntu? To: kernelnewbies X-BeenThere: kernelnewbies@kernelnewbies.org X-Mailman-Version: 2.1.15 Precedence: list List-Id: Learn about the Linux kernel List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Reply-To: noloader@gmail.com Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Errors-To: kernelnewbies-bounces@kernelnewbies.org Hi Everyone, Ubuntu provided 5.0.0-27-generic today. I attempted to reboot but booting fails due to a failed signature check. I'd like to tell the kernel to skip the signature check during boot. I found Ubuntu's UEFI | SecureBoot | DKMS (https://wiki.ubuntu.com/UEFI/SecureBoot/DKMS) wiki page. It discusses several ways to disable signature checks but they assume a working machine. I'm at the grub boot menu with the menu open ready for editing. What option should I use to disable the signature checks during boot? Thanks in advance, Jeff _______________________________________________ Kernelnewbies mailing list Kernelnewbies@kernelnewbies.org https://lists.kernelnewbies.org/mailman/listinfo/kernelnewbies