Scheduled Maintenance: We are aware of an issue with Google, AOL, and Yahoo services as email providers which are blocking new registrations. We are trying to fix the issue and we have several internal and external support tickets in process to resolve the issue. Please see: viewtopic.php?t=158230

 

 

 

Installing Debian on secure boot blocked system

Here you can discuss every aspect of Debian. Note: not for support requests!
Post Reply
Message
Author
User avatar
woteb
Posts: 124
Joined: 2009-01-24 09:51
Location: Netherlands (Veluwe)

Installing Debian on secure boot blocked system

#1 Post by woteb »

Is it possible to install Debian on a system where secure boot can not be disabled. If so, how do you do that?
Laptops: HP 250 G6 i3 7th gen + Lenovo: Debian Testing XFCE
HP based chromebooks: Debian Testing and other variations
"The simple reality of the matter is that Debian is essentially the backbone of Linux - for all practical purposes."

User avatar
Head_on_a_Stick
Posts: 14114
Joined: 2014-06-01 17:46
Location: London, England
Has thanked: 81 times
Been thanked: 132 times

Re: Installing Debian on secure boot blocked system

#2 Post by Head_on_a_Stick »

Dual boot with a distribution that does support Secure Boot (such as Fedora, openSUSE or Ubuntu) and use the other distribution to install and control GRUB.

Alternatively, use a "live" version of Ubuntu to install Debian with debootstrap [1] and then try the Linux Foundation's Secure Boot system:

https://blog.hansenpartnership.com/linu ... -released/

I did have that working with wheezy but my UEFI laptop is no longer UEFI so I can't test it now.

[1] https://www.debian.org/releases/stretch ... 03.html.en

EDIT: you could also try some self-signed keys:

https://www.rodsbooks.com/efi-bootloade ... ml#signing

https://packages.debian.org/stretch/sbsigntool
deadbang

User avatar
woteb
Posts: 124
Joined: 2009-01-24 09:51
Location: Netherlands (Veluwe)

Re: Installing Debian on secure boot blocked system

#3 Post by woteb »

Thanks!! It seems useful to me. I understand that with the admin password setting in the uefi settings it is often (read: not always) also necessary to enable / disable on secure boot.
Laptops: HP 250 G6 i3 7th gen + Lenovo: Debian Testing XFCE
HP based chromebooks: Debian Testing and other variations
"The simple reality of the matter is that Debian is essentially the backbone of Linux - for all practical purposes."

Post Reply