Scheduled Maintenance: We are aware of an issue with Google, AOL, and Yahoo services as email providers which are blocking new registrations. We are trying to fix the issue and we have several internal and external support tickets in process to resolve the issue. Please see: viewtopic.php?t=158230

 

 

 

Secure Boot on MSI H510M Plus V3

Need help with peripherals or devices?
Post Reply
Message
Author
Zumamudin
Posts: 2
Joined: 2024-03-25 23:03

Secure Boot on MSI H510M Plus V3

#1 Post by Zumamudin »

Hello everyone!

I got new PC with MSI H510M Plus V3 motherboard but it always failed to boot Bookworm even though the installation process done successfully when secure boot is enabled.
Every time it boot, there's a warning says this:

shim lock protocol not found you need to load the kernel first

I wonder how to solve it because on other distro like Neon it doesn't happen and on my Lenovo laptop Bookworm could run with secure boot enabled. Whereas, the installation process are the same with no MOK shows up at all just like on Bookworm also.

That's it, thank you! :D

User avatar
pbear
Posts: 329
Joined: 2023-08-27 15:05
Location: San Francisco
Has thanked: 1 time
Been thanked: 57 times

Re: Secure Boot on MSI H510M Plus V3

#2 Post by pbear »

Your hardware might be too new for the 6.1 kernel used in Bookworm.

Zumamudin
Posts: 2
Joined: 2024-03-25 23:03

Re: Secure Boot on MSI H510M Plus V3

#3 Post by Zumamudin »

So waiting for newer release is the only easy option? Waiting for new kernel?

It turns out even other problem, not only secure boot but my front panel audio also made no output at all 🤦🏻‍♂️

User avatar
FreewheelinFrank
Global Moderator
Global Moderator
Posts: 2117
Joined: 2010-06-07 16:59
Has thanked: 38 times
Been thanked: 232 times

Re: Secure Boot on MSI H510M Plus V3

#4 Post by FreewheelinFrank »

Zumamudin wrote: 2024-03-26 04:50 So waiting for newer release is the only easy option? Waiting for new kernel?

It turns out even other problem, not only secure boot but my front panel audio also made no output at all 🤦🏻‍♂️
Newer kernels are available from Debian Backports:

https://backports.debian.org/

User avatar
Hetzer
Posts: 80
Joined: 2024-01-05 22:30
Location: /etc/fstab
Has thanked: 45 times
Been thanked: 21 times

Re: Secure Boot on MSI H510M Plus V3

#5 Post by Hetzer »

pbear wrote: 2024-03-26 04:22 Your hardware might be too new for the 6.1 kernel used in Bookworm.
Can't be true as I could run Bookworm on MSI z490 PRO-A and B550M PRO-VDH, which are boards of similiar age, without any problems
Zumamudin wrote: 2024-03-25 23:25 Hello everyone!

I got new PC with MSI H510M Plus V3 motherboard but it always failed to boot Bookworm even though the installation process done successfully when secure boot is enabled.
Every time it boot, there's a warning says this:

shim lock protocol not found you need to load the kernel first

I wonder how to solve it because on other distro like Neon it doesn't happen and on my Lenovo laptop Bookworm could run with secure boot enabled. Whereas, the installation process are the same with no MOK shows up at all just like on Bookworm also.

That's it, thank you! :D
So it's probably not a SB blacklist problem* as Neon (which is Ubuntu derivative) can run on it. Though I think it's still worth a check
It's interesting why it fails to boot as I was able to get both mentioned boards to work with and without "Secure Boot". Though I was installing on these with 12.0 installer I've burned onto DVD back when Bookworm was released, so I have no idea of state of today's 12.X Bookworm install image.
I suspect that either it's something with UEFI (though it should throw "blacklisted crap, blabla..." instead) or installer installs non-signed kernel. Maybe try 12.0 installer which, in my case, worked as it should work?
Me question is if you really need to get it working. It's later problematic to get it working with modified kernel / new modules (like ones to make VirtualBox work) while doesn't really improve security as everyone can sign any EFI executable
I would instead just turn it off and, if ye want real security, LUKS-encrypt root + data partitions instead

*: MSI was blocking Debian && Ubuntu SB keys by default for some time (first mentions from 2021, UEFI update for z490 from 08/2023 removed that restriction)
Heave 'er up, and away we'll go...

Aki
Global Moderator
Global Moderator
Posts: 2979
Joined: 2014-07-20 18:12
Location: Europe
Has thanked: 75 times
Been thanked: 407 times

Re: Secure Boot on MSI H510M Plus V3

#6 Post by Aki »

Moved to "Hardware" sub-forum.
⢀⣴⠾⠻⢶⣦⠀
⣾⠁⢠⠒⠀⣿⡁ Debian - The universal operating system
⢿⡄⠘⠷⠚⠋⠀ https://www.debian.org
⠈⠳⣄⠀

Post Reply