On Mon, 21 Nov 2022 18:54:49 +1100
Stephen Morris <samorris(a)netspace.net.au> wrote:
Hi,
I am getting the following error message displayed before the
display of the grub boot menu, can someone explain to me what this
means and why it is occurring in F37 when it was never produced in
F36, and what I need to do to rectify it?
error: ../../grub-core/kern/efi/sb.c:169:prohibited
by secure boot policy
I am running f37 and have nothing like sb.c or grub-core on my system.
I am guessing that those are some customization that you have installed
yourself? If so, my thought would be that the efi boot process
security has been tightened, and that those are not included in the
allowed boot policy. There seems to be an initiative to tighten the
efi boot procedure so that it is verifiably unalterable from repo to
the running system. This includes writing a 'measure' for all involved
files and ensuring they pass a check of that 'measure' before they are
used. I don't know how far this initiative has progressed, but you
might be seeing some fallout from that.