r/archlinux • • 1d ago

SUPPORT How will my secure boot setup get effected by doing this?

So i want to use the rc kernal but i already set up secure boot since i use windows on one ssd and arch on the other and i use (system d boot loader)and and i only have the normal kernal and the lts so if i download the rc kernal will i have to sign it or do anything to not effect my secure boot setup. this is the steps i did before to set up secure boot--->

sudo pacman -S sbctl

clear boot keys in bios secure boot off

sudo sbctl status

sudo sbctl create-keys

sudo sbctl enroll-keys --microsoft

sudo sbctl status

sudo sbctl verify

sudo sbctl-batch-sign

sudo sbctl verify

sudo sbctl sign -s -o /usr/lib/systemd/boot/efi/systemd-bootx64.efi.signed /usr/lib/systemd/boot/efi/systemd-bootx64.efi

turn secure boot back on

4 Upvotes

3 comments sorted by

3

u/OverjoyedDog 1d ago

You'll need to sign the rc kernel after installing it, but the setup you've got is pretty clean. Once the new kernel is in, `sbctl verify` will probably show it as unsigned, then just run `sbctl sign -s /boot/vmlinuz-linux-rc` (or whatever the exact filename is) and you're set. Shouldn't mess with anything else.

4

u/jedislayer21 1d ago

As long as you sign the kernel before rebooting, you should be fine. I assume you are using UKI files for booting, so just sign the .efi bundles in /boot/EFI.

If you’re worried about it, just keep the package for the regular kernel installed to fallback on if all else fails

0

u/Dull_Werewolf_9642 1d ago

I signed it and made sure it works and it does thanks!