Jump to content

GRUB2: Difference between revisions

From SameTeem
Line 22: Line 22:
Reboot and verify everything is working with  
Reboot and verify everything is working with  
  sudo sbctl status
  sudo sbctl status
If you are getting and error when booting about "Prohibited by secure boot policy" you can just turn off Secure Boot in your BIOS again and troubleshoot what happened.


== grub_is_using_legacy_shim_lock_protocol while booting ==
== grub_is_using_legacy_shim_lock_protocol while booting ==

Revision as of 18:00, 18 June 2026

Secure Boot

You NEED to set your BIOS/UEFI settings to make Secure Boot is in "setup" mode, this is different on every motherboard but will usually be under the security settings in the BIOS settings. Some MSI motherboards force setup mode by using the options "Delete all platform variables" in the Secure Boot settings. This option is turned off after the next boot so make sure to do this in one sitting.

You also NEED to know which partition stores your boot loader in the case of EndeavourOS it is either /boot/efi OR /efi, look for the folder in the output of "df -h" Example:

/dev/nvme1n1p1          2.0G  708K  2.0G   1% /boot/efi

Install the tools for signing files

sudo pacman -S sbctl

Create the keys for your system

sudo sbctl create-keys

Enroll all the needed keys in to your EFI, do not run this without the -m argument or you can brick your system.

sudo sbctl enroll-keys -m -f

Sign all the needed files, at a minimum it needs these first 3 files, if you are using a custom kernel you will need to sign other files, for example "/boot/vmlinuz-linux-zen"

sudo sbctl sign -s /boot/vmlinuz-linux
sudo sbctl sign -s /boot/efi/EFI/boot/bootx64.efi
sudo sbctl sign -s /boot/efi/EFI/endeavouros/grubx64.efi

Install GRUB on your system with the extra TPM module so Secure Boot will work

sudo grub-install --target=x86_64-efi --efi-directory=/boot/efi --removable --modules="tpm" --disable-shim-lock


Reboot and verify everything is working with

sudo sbctl status


If you are getting and error when booting about "Prohibited by secure boot policy" you can just turn off Secure Boot in your BIOS again and troubleshoot what happened.

grub_is_using_legacy_shim_lock_protocol while booting

Problem; : You are using the old GRUB, probably because an upgrade broke or you didn't run grub-install when needed.

EndeavourOS EXAMPLE, commands need to be modified for your distribution, not modifying these will may your PC un-bootable

Boot in to the Live Installer for the OS (probably what you installed the OS from).

Open gparted from the applications menu and search for your drive in the top right hand corner. The correct drive will have at least 2 paritions, a small EFI partition, and a "File System" with EXT4/BTRFS/Encrypted types.

OPTIONAL : IF you have an encrypted drive (LUKS) you need to "open" the drive, so it can be mounted.

In Gparted an encrypted drive will look like this:

Take the "Partition" value for the LUKS [Encrypted] partition and put it in to this command

sudo cryptsetup open /dev/nvme1n1p2 endeavouros

endeavouros can be anything you like as long as you use the same name in the /dev/mapper line below.



Mount the root (/) partition

sudo mount /dev/nvme1n1p2 /mnt

sudo mount /dev/mapper/endeavouros /mnt

Also mount the boot (/boot/efi) partitions

sudo mount /dev/nvme1n1p2 /mnt/boot/efi

Enter an Arch chroot, this will only exist on Arch based systems.

sudo arch-chroot /mnt

Reinstall GRUB

grub-install

Run

ls -la /mnt/boot/efi/EFI/boot/bootx64.efi

IF you have this file (you see a line containing -rw-r----- 1 root root) then ALSO run the command

grub-install --target=x86_64-efi --efi-directory=/boot/efi --removable

This installs GRUB to the default location your BIOS searches for bootloaders, which is how your PC may be set up instead of using the normal location stored in the EFI memory.


Press Ctrl+D to exit the chroot, then type reboot to restart the system and everything should work.