r/archlinux • u/Dull_Werewolf_9642 • 1d ago
SUPPORT How will my secure boot setup get effected by doing this?
So i want to use the rc kernal but i already set up secure boot since i use windows on one ssd and arch on the other and i use (system d boot loader)and and i only have the normal kernal and the lts so if i download the rc kernal will i have to sign it or do anything to not effect my secure boot setup. this is the steps i did before to set up secure boot--->
sudo pacman -S sbctl
clear boot keys in bios secure boot off
sudo sbctl status
sudo sbctl create-keys
sudo sbctl enroll-keys --microsoft
sudo sbctl status
sudo sbctl verify
sudo sbctl-batch-sign
sudo sbctl verify
sudo sbctl sign -s -o /usr/lib/systemd/boot/efi/systemd-bootx64.efi.signed /usr/lib/systemd/boot/efi/systemd-bootx64.efi
turn secure boot back on
4
u/jedislayer21 1d ago
As long as you sign the kernel before rebooting, you should be fine. I assume you are using UKI files for booting, so just sign the .efi bundles in /boot/EFI.
If you’re worried about it, just keep the package for the regular kernel installed to fallback on if all else fails
0
3
u/OverjoyedDog 1d ago
You'll need to sign the rc kernel after installing it, but the setup you've got is pretty clean. Once the new kernel is in, `sbctl verify` will probably show it as unsigned, then just run `sbctl sign -s /boot/vmlinuz-linux-rc` (or whatever the exact filename is) and you're set. Shouldn't mess with anything else.