Secure Boot Violation. Invalid signature detected. Check secure boot policy in Setup.

YouTube

Quand je dis que la réinitialisation de toute la Vram c'est pas forcément une bonne idée : dans ces variables y'a "BootOrder", qui dicte à l'Uefi l'ordre des entrées de boot, que l'on obtient habituellement par :

$ efibootmgr

et cette variable, j'y joue pas mal puisque quand on a plusieurs distris, plusieurs grub et un rEFInd, cette commande permet de jongler avec tout ce petit monde (il m'arrive d'avoir 4 distributions sur la même machine) pour faire des test (au passage, j'ai un petit challenge avec NixOs qui faut que je règle, question amour propre).

Voilà mon exploration du jour dans le merveilleux monde de #uefi

#linux
#mac
#macbook
#efi

5/fin

Upgrade System Firmware with no EFI space after relocating most I can do #boot #uefi #bios #grubefi #firmware

https://askubuntu.com/q/1566928/612

Upgrade System Firmware with no EFI space after relocating most I can do

My /boot/efi does not have sufficient space. Even after temporarily relocating /boot/Nicrosoft to /home, Upgrade System Firmware required 71,4 MB, but only got 69,7 MB. > $ df -h /boot/efi >...

Ask Ubuntu

Mood : https://www.youtube.com/shorts/o56qL2t4swA

Doing network booting (#DHCP, #TFTP, #iPXE, #UEFI, #SecureBoot)
I haven't reached the “Oh, that's why” so far. But very annoyed

https://ipxe.org/secboot
“The Secure Boot shim (e.g. ipxe-shim.efi or snponly-shim.efi) will automatically load the iPXE binary with the corresponding name (e.g. ipxe.efi or snponly.efi).”
Definitely not what's happening…
So It kept loading the wrong iPXE firmware (not the snmponly) and I kept wondering why my keyboard wasn't working :<

Why? Why? Oh, that's why 🤣🤣 || #thebigbangtheory #shorts

YouTube

Now it is a great time to ensure you've updated your #UEFI #Windows #SecureBoot Certificate Authority to 2023 versions. The old keys from 2011 are set to expire in June 2026.

Quoting microsoft:

"Devices that haven’t received the newer 2023 certificates will continue to start and operate normally, and standard Windows updates will continue to install. However, these devices will no longer be able to receive new security protections for the early boot process, including updates to Windows Boot Manager, Secure Boot databases, revocation lists, or mitigations for newly discovered boot level vulnerabilities.

Over time, this limits the device’s protection against emerging threats and may affect scenarios that rely on Secure Boot trust, such as BitLocker hardening or third-party bootloaders. Most Windows devices will receive the updated certificates automatically, and many OEMs provide firmware updates when needed. Keeping your device current with these updates helps ensures it can continue receiving the full set of security protections that Secure Boot is designed to provide."

https://support.microsoft.com/en-gb/topic/windows-secure-boot-certificate-expiration-and-ca-updates-7ff40d33-95dc-4c3c-8725-a9b95457578e

Windows Secure Boot certificate expiration and CA updates - Microsoft Support

heise+ | Ein Blick auf den Inhalt der EFI System Partition

Der UEFI-Bootloader für Windows liegt in einer gut versteckten Partition. Ein c’t-Skript zeigt, welche Dateien dort liegen. Wir erklären, wozu sie da sind.

https://www.heise.de/ratgeber/Ein-Blick-auf-den-Inhalt-der-EFI-System-Partition-11269203.html?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege&utm_source=mastodon

#IT #Linux #UEFI #Windows #Windows #Windows #news

Ein Blick auf den Inhalt der EFI System Partition

Der UEFI-Bootloader für Windows liegt in einer gut versteckten Partition. Ein c’t-Skript zeigt, welche Dateien dort liegen. Wir erklären, wozu sie da sind.

c't Magazin

Ce week-end j'ai un peu trifouillé le matériel de mon PC (installation d'un CPU qui a grillé à cause d'une mauvaise manip de ma part, puis réinstallation de l'ancien CPU), et depuis j'ai ce message qui apparaît au démarrage.
J'ai vérifié la pile, elle semble toujours bonne, l'UEFI garde bien la date et l'heure. J'ai tenté de réinitialiser la config #UEFI, sans succès.

Quelqu'un a une idée de comment se débarrasser de cet écran ?

My experience upgrading the BIOS of a Windows 11 mini PC (with BitLocker) in 2026

I don't always update the BIOS of my system, but when I do, I always make sure to waste several hours doing so. Last time I did that was in 2020, but this happened again when I updated the BIOS for the Khadas Mind 2 to test it with the Mind xPlay display and Mind Graphics 2 dock. Khadas provides the BIOS with instructions to update the Mind 2 mini PC, and it's supposed to take five minutes, but I ended up wasting two about hours... The first step is to download and extract a zip file (mind-2-bios-v1.07-260122.zip), then start the Flash_BIOS upgrade program, and finally wait for the upgrade to complete. That part went great. No problem, but when the system rebooted, I was greeted by a BitLocker window asking me to enter a recovery key to carry on with the boot process. There's no way to avoid this,

CNX Software - Embedded Systems News

How to remove one OS from a triple boot system that shows incongruent boot lists #dualboot #uefi

https://askubuntu.com/q/1566610/612

How to remove one OS from a triple boot system that shows incongruent boot lists

I'm new to Linux (about 6 weeks) and have been testing multiple versions of Linux on my NUC which resulted with an SDD with three OS partitions. The sequence of installation was: 1. Windows 10 2. U...

Ask Ubuntu

Want to remove 1 OS from triple boot system that shows incongruent boot lists #dualboot #uefi

https://askubuntu.com/q/1566610/612

Want to remove 1 OS from triple boot system that shows incongruent boot lists

Starting Point I'm new to Linux (about 6 weeks) and have been testing multiple versions of Linux on my NUC which resulted with an SDD with three OS partitions. The sequence of installation was: 1.

Ask Ubuntu