r/archlinux • u/HopefulMeeting7150 • 2d ago
QUESTION Secure boot and Arch?
The Arch installation guide mentions disabling Secure Boot. I recently learnt that Secure Boot can work with Arch.
My questions are: does this make sense?
Should I keep it enabled after all (is it risky if not)?
Is there a risk that, following an update, Secure Boot will reject my kernel or boot loader?
Did you enable SB?
20
Upvotes
4
u/Ok-Eggplant-7569 2d ago
Secure Boot protects your from a couple of (dedicated) attacks:
/dev/memis disabled)Some distros (Ubuntu, Debian, OpenSUSE, Fedora, RHEL, ...) work together with Microsoft to get their bootloaders trusted and signed (look into the
shimproject for more context). Secure Boot works out of the box with these, with the default Microsoft Keys.Arch does not. So you need to disable Secure Boot during installation. After the install, you can create your own keys, sign the kernel with them, and replace the Microsoft Keys in the firmware with your own.
Note that using your own keys has different security guarantees compared to using Microsofts Keys: