Bug 28351

Summary: UEFI SB would reject unsigned kernels
Product: Sisyphus Reporter: Michael Shigorin <mike>
Component: refindAssignee: Anton Farygin <rider>
Status: CLOSED WORKSFORME QA Contact: qa-sisyphus
Severity: normal    
Priority: P3 CC: aen, boyarsh, mike, nickel, rider
Version: unstable   
Hardware: all   
OS: Linux   
URL: http://www.rodsbooks.com/refind/secureboot.html

Description Michael Shigorin 2013-01-14 21:26:25 MSK
refind-0.6.4 boots the kernel in a way that precludes an unsigned vmlinuz from being successfully booted if shim-signed is used to start refind itself and SecureBoot is not disabled; elilo-3.14 works just fine in the same environment.

Reported upstream.
Comment 1 Michael Shigorin 2013-02-25 23:28:16 MSK
Worked around by booting ELILO instead (it's even not complete nonsense since refind is a boot manager and elilo is a boot loader ;-).

http://git.altlinux.org/people/mike/packages/?p=mkimage.git;a=commitdiff;h=8a44277df8912acb7832192fb816692b2857fb18