Enroll keys without clearing for Multi boot #460

Open
opened 2025-06-02 04:35:25 +00:00 by malachid · 2 comments
malachid commented 2025-06-02 04:35:25 +00:00 (Migrated from github.com)

I am currently using a Framework 16. I have multiple OS on different modules. They are all registered with Secure Boot.

I was going through the setup process for lanzaboote for Nix and sbctl says everything looks good.

The problem is that clearing all the existing ones is problematic. Is there any plan of allowing this to add to the existing keys (like mokutil or whatever)? Currently Nix is the only one not able to secure boot.

I am currently using a Framework 16. I have multiple OS on different modules. They are all registered with Secure Boot. I was going through the setup process for lanzaboote for Nix and sbctl says everything looks good. The problem is that clearing all the existing ones is problematic. Is there any plan of allowing this to add to the existing keys (like mokutil or whatever)? Currently Nix is the only one not able to secure boot.
Xarianne commented 2025-08-03 05:35:40 +00:00 (Migrated from github.com)

Would like Mokutil too. As soon as one of my other OSes re-updated the forbidden database, my Nix OS install started throwing a bad shim signature error and couldn't boot it again.

Also it seems to create several boot entries for me.

Would like Mokutil too. As soon as one of my other OSes re-updated the forbidden database, my Nix OS install started throwing a bad shim signature error and couldn't boot it again. Also it seems to create several boot entries for me.
RaitoBezarius commented 2025-08-03 13:54:32 +00:00 (Migrated from github.com)

You can keep the keys for shim if you want to be able to boot with shim.
As long as you keep the lanzaboote keys, this will work too.

You can keep the keys for shim if you want to be able to boot with shim. As long as you keep the lanzaboote keys, this will work too.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference: raito/lanzaboote#460
No description provided.