You are not logged in.

#1 Yesterday 21:39:37

cabaz
Member
Registered: 2019-03-28
Posts: 3

sbctl database files for secure boot were deleted.

I'm on a fresh (by a few days) installation of Arch.  I used sbctl to enroll keys to allow for secure boot.  Everything worked.  I followed
https://wiki.archlinux.org/title/Unifie … with_sbctl.

I use grub. and dual boot with Windows 11.

I reset my keys in the bios (trying to turn off a function).  A Dell Inspiron 3910.  I turned off the Custom mode of Secure Boot.  Turning it on allows for deleting the Platform Key.  Anyway I turned it off.  I re-enrolled the keys running "sbctl create-keys" and "sbctl enroll-keys -m -f".

I became worried that sbctl wouldn't remember the files that had been signed so I ran "sudo sbctl verify | sed 's/✓ /sudo sbctl remove-file /e'" thinking to unsign the efi files. and then resign and add them again to the database.

Anyway, Arch boots with Secure Boot enabled but the database seems to be empty.

[donald@donald-Inspiron-3910 ~]$ sbctl list-files
[donald@donald-Inspiron-3910 ~]$

There are lots of files that are signed.

[donald@donald-Inspiron-3910 ~]$ sudo sbctl verify
[sudo] password for donald: 
Verifying file database and EFI images in /boot...
✓ /boot/Boot/Resources/bootres.dll is signed
✓ /boot/Boot/Resources/cs-CZ/bootres.dll.mui is signed
✓ /boot/Boot/Resources/da-DK/bootres.dll.mui is signed
✓ /boot/Boot/Resources/de-DE/bootres.dll.mui is signed
✓ /boot/Boot/Resources/el-GR/bootres.dll.mui is signed
✓ /boot/Boot/Resources/en-US/bootres.dll.mui is signed
✓ /boot/Boot/Resources/es-ES/bootres.dll.mui is signed
✓ /boot/Boot/Resources/fi-FI/bootres.dll.mui is signed
✓ /boot/Boot/Resources/fr-FR/bootres.dll.mui is signed
✓ /boot/Boot/Resources/hu-HU/bootres.dll.mui is signed
✓ /boot/Boot/Resources/it-IT/bootres.dll.mui is signed
✓ /boot/Boot/Resources/nb-NO/bootres.dll.mui is signed
✓ /boot/Boot/Resources/nl-NL/bootres.dll.mui is signed
✓ /boot/Boot/Resources/pl-PL/bootres.dll.mui is signed
✓ /boot/Boot/Resources/pt-BR/bootres.dll.mui is signed
✓ /boot/Boot/Resources/pt-PT/bootres.dll.mui is signed
✓ /boot/Boot/Resources/ru-RU/bootres.dll.mui is signed
✓ /boot/Boot/Resources/sv-SE/bootres.dll.mui is signed
✓ /boot/Boot/Resources/tr-TR/bootres.dll.mui is signed
✓ /boot/Boot/bg-BG/bootmgr.exe.mui is signed
✓ /boot/Boot/bootuwf.dll is signed
✓ /boot/Boot/bootvhd.dll is signed
✓ /boot/Boot/cs-CZ/bootmgr.exe.mui is signed
✓ /boot/Boot/cs-CZ/memtest.exe.mui is signed
✓ /boot/Boot/da-DK/bootmgr.exe.mui is signed
✓ /boot/Boot/da-DK/memtest.exe.mui is signed
✓ /boot/Boot/de-DE/bootmgr.exe.mui is signed
✓ /boot/Boot/de-DE/memtest.exe.mui is signed
✓ /boot/Boot/el-GR/bootmgr.exe.mui is signed
✓ /boot/Boot/el-GR/memtest.exe.mui is signed
✓ /boot/Boot/en-GB/bootmgr.exe.mui is signed
✓ /boot/Boot/en-US/bootmgr.exe.mui is signed
✓ /boot/Boot/en-US/memtest.exe.mui is signed
✓ /boot/Boot/es-ES/bootmgr.exe.mui is signed
✓ /boot/Boot/es-ES/memtest.exe.mui is signed
✓ /boot/Boot/es-MX/bootmgr.exe.mui is signed
✓ /boot/Boot/et-EE/bootmgr.exe.mui is signed
✓ /boot/Boot/fi-FI/bootmgr.exe.mui is signed
✓ /boot/Boot/fi-FI/memtest.exe.mui is signed
✓ /boot/Boot/fr-CA/bootmgr.exe.mui is signed
✓ /boot/Boot/fr-FR/bootmgr.exe.mui is signed
✓ /boot/Boot/fr-FR/memtest.exe.mui is signed
✓ /boot/Boot/hr-HR/bootmgr.exe.mui is signed
✓ /boot/Boot/hu-HU/bootmgr.exe.mui is signed
✓ /boot/Boot/hu-HU/memtest.exe.mui is signed
✓ /boot/Boot/it-IT/bootmgr.exe.mui is signed
✓ /boot/Boot/it-IT/memtest.exe.mui is signed
✓ /boot/Boot/ja-JP/bootmgr.exe.mui is signed
✓ /boot/Boot/ja-JP/memtest.exe.mui is signed
✓ /boot/Boot/ko-KR/bootmgr.exe.mui is signed
✓ /boot/Boot/ko-KR/memtest.exe.mui is signed
✓ /boot/Boot/lt-LT/bootmgr.exe.mui is signed
✓ /boot/Boot/lv-LV/bootmgr.exe.mui is signed
✓ /boot/Boot/nb-NO/bootmgr.exe.mui is signed
✓ /boot/Boot/nb-NO/memtest.exe.mui is signed
✓ /boot/Boot/nl-NL/bootmgr.exe.mui is signed
✓ /boot/Boot/nl-NL/memtest.exe.mui is signed
✓ /boot/Boot/pl-PL/bootmgr.exe.mui is signed
✓ /boot/Boot/pl-PL/memtest.exe.mui is signed
✓ /boot/Boot/pt-BR/bootmgr.exe.mui is signed
✓ /boot/Boot/pt-BR/memtest.exe.mui is signed
✓ /boot/Boot/pt-PT/bootmgr.exe.mui is signed
✓ /boot/Boot/pt-PT/memtest.exe.mui is signed
✓ /boot/Boot/qps-ploc/bootmgr.exe.mui is signed
✓ /boot/Boot/qps-ploc/memtest.exe.mui is signed
✓ /boot/Boot/qps-plocm/bootmgr.exe.mui is signed
✓ /boot/Boot/qps-plocm/memtest.exe.mui is signed
✓ /boot/Boot/ro-RO/bootmgr.exe.mui is signed
✓ /boot/Boot/ru-RU/bootmgr.exe.mui is signed
✓ /boot/Boot/ru-RU/memtest.exe.mui is signed
✓ /boot/Boot/sk-SK/bootmgr.exe.mui is signed
✓ /boot/Boot/sl-SI/bootmgr.exe.mui is signed
✓ /boot/Boot/sr-Latn-RS/bootmgr.exe.mui is signed
✓ /boot/Boot/sv-SE/bootmgr.exe.mui is signed
✓ /boot/Boot/sv-SE/memtest.exe.mui is signed
✓ /boot/Boot/tr-TR/bootmgr.exe.mui is signed
✓ /boot/Boot/tr-TR/memtest.exe.mui is signed
✓ /boot/Boot/uk-UA/bootmgr.exe.mui is signed
✓ /boot/Boot/zh-CN/bootmgr.exe.mui is signed
✓ /boot/Boot/zh-CN/memtest.exe.mui is signed
✓ /boot/Boot/zh-TW/bootmgr.exe.mui is signed
✓ /boot/Boot/zh-TW/memtest.exe.mui is signed
✓ /boot/EFI/Boot/bootx64.efi is signed
✓ /boot/EFI/Boot/fbx64.efi is signed
✓ /boot/EFI/Boot/mmx64.efi is signed
✓ /boot/EFI/Dell/SOS/bootmgfw.efi is signed
✓ /boot/EFI/Dell/SOS/bootx64.efi is signed
✓ /boot/EFI/GRUB/grubx64.efi is signed
✓ /boot/EFI/Microsoft/Boot/Resources/bootres.dll is signed
✓ /boot/EFI/Microsoft/Boot/Resources/cs-CZ/bootres.dll.mui is signed
✓ /boot/EFI/Microsoft/Boot/Resources/da-DK/bootres.dll.mui is signed
✓ /boot/EFI/Microsoft/Boot/Resources/de-DE/bootres.dll.mui is signed
✓ /boot/EFI/Microsoft/Boot/Resources/el-GR/bootres.dll.mui is signed
✓ /boot/EFI/Microsoft/Boot/Resources/en-US/bootres.dll.mui is signed
✓ /boot/EFI/Microsoft/Boot/Resources/es-ES/bootres.dll.mui is signed
✓ /boot/EFI/Microsoft/Boot/Resources/fi-FI/bootres.dll.mui is signed
✓ /boot/EFI/Microsoft/Boot/Resources/fr-FR/bootres.dll.mui is signed
✓ /boot/EFI/Microsoft/Boot/Resources/hu-HU/bootres.dll.mui is signed
✓ /boot/EFI/Microsoft/Boot/Resources/it-IT/bootres.dll.mui is signed
✓ /boot/EFI/Microsoft/Boot/Resources/nb-NO/bootres.dll.mui is signed
✓ /boot/EFI/Microsoft/Boot/Resources/nl-NL/bootres.dll.mui is signed
✓ /boot/EFI/Microsoft/Boot/Resources/pl-PL/bootres.dll.mui is signed
✓ /boot/EFI/Microsoft/Boot/Resources/pt-BR/bootres.dll.mui is signed
✓ /boot/EFI/Microsoft/Boot/Resources/pt-PT/bootres.dll.mui is signed
✓ /boot/EFI/Microsoft/Boot/Resources/ru-RU/bootres.dll.mui is signed
✓ /boot/EFI/Microsoft/Boot/Resources/sv-SE/bootres.dll.mui is signed
✓ /boot/EFI/Microsoft/Boot/Resources/tr-TR/bootres.dll.mui is signed
✓ /boot/EFI/Microsoft/Boot/SecureBootRecovery.efi is signed
✓ /boot/EFI/Microsoft/Boot/bg-BG/bootmgfw.efi.mui is signed
✓ /boot/EFI/Microsoft/Boot/bg-BG/bootmgr.efi.mui is signed
✓ /boot/EFI/Microsoft/Boot/bootmgfw.efi is signed
✓ /boot/EFI/Microsoft/Boot/bootmgr.efi is signed
✓ /boot/EFI/Microsoft/Boot/cs-CZ/bootmgfw.efi.mui is signed
✓ /boot/EFI/Microsoft/Boot/cs-CZ/bootmgr.efi.mui is signed
✓ /boot/EFI/Microsoft/Boot/cs-CZ/memtest.efi.mui is signed
✓ /boot/EFI/Microsoft/Boot/da-DK/bootmgfw.efi.mui is signed
✓ /boot/EFI/Microsoft/Boot/da-DK/bootmgr.efi.mui is signed
✓ /boot/EFI/Microsoft/Boot/da-DK/memtest.efi.mui is signed
✓ /boot/EFI/Microsoft/Boot/de-DE/bootmgfw.efi.mui is signed
✓ /boot/EFI/Microsoft/Boot/de-DE/bootmgr.efi.mui is signed
✓ /boot/EFI/Microsoft/Boot/de-DE/memtest.efi.mui is signed
✓ /boot/EFI/Microsoft/Boot/el-GR/bootmgfw.efi.mui is signed
✓ /boot/EFI/Microsoft/Boot/el-GR/bootmgr.efi.mui is signed
✓ /boot/EFI/Microsoft/Boot/el-GR/memtest.efi.mui is signed
✓ /boot/EFI/Microsoft/Boot/en-GB/bootmgfw.efi.mui is signed
✓ /boot/EFI/Microsoft/Boot/en-GB/bootmgr.efi.mui is signed
✓ /boot/EFI/Microsoft/Boot/en-US/bootmgfw.efi.mui is signed
✓ /boot/EFI/Microsoft/Boot/en-US/bootmgr.efi.mui is signed
✓ /boot/EFI/Microsoft/Boot/en-US/memtest.efi.mui is signed
✓ /boot/EFI/Microsoft/Boot/es-ES/bootmgfw.efi.mui is signed
✓ /boot/EFI/Microsoft/Boot/es-ES/bootmgr.efi.mui is signed
✓ /boot/EFI/Microsoft/Boot/es-ES/memtest.efi.mui is signed
✓ /boot/EFI/Microsoft/Boot/es-MX/bootmgfw.efi.mui is signed
✓ /boot/EFI/Microsoft/Boot/es-MX/bootmgr.efi.mui is signed
✓ /boot/EFI/Microsoft/Boot/et-EE/bootmgfw.efi.mui is signed
✓ /boot/EFI/Microsoft/Boot/et-EE/bootmgr.efi.mui is signed
✓ /boot/EFI/Microsoft/Boot/fi-FI/bootmgfw.efi.mui is signed
✓ /boot/EFI/Microsoft/Boot/fi-FI/bootmgr.efi.mui is signed
✓ /boot/EFI/Microsoft/Boot/fi-FI/memtest.efi.mui is signed
✓ /boot/EFI/Microsoft/Boot/fr-CA/bootmgfw.efi.mui is signed
✓ /boot/EFI/Microsoft/Boot/fr-CA/bootmgr.efi.mui is signed
✓ /boot/EFI/Microsoft/Boot/fr-FR/bootmgfw.efi.mui is signed
✓ /boot/EFI/Microsoft/Boot/fr-FR/bootmgr.efi.mui is signed
✓ /boot/EFI/Microsoft/Boot/fr-FR/memtest.efi.mui is signed
✓ /boot/EFI/Microsoft/Boot/hr-HR/bootmgfw.efi.mui is signed
✓ /boot/EFI/Microsoft/Boot/hr-HR/bootmgr.efi.mui is signed
✓ /boot/EFI/Microsoft/Boot/hu-HU/bootmgfw.efi.mui is signed
✓ /boot/EFI/Microsoft/Boot/hu-HU/bootmgr.efi.mui is signed
✓ /boot/EFI/Microsoft/Boot/hu-HU/memtest.efi.mui is signed
✓ /boot/EFI/Microsoft/Boot/it-IT/bootmgfw.efi.mui is signed
✓ /boot/EFI/Microsoft/Boot/it-IT/bootmgr.efi.mui is signed
✓ /boot/EFI/Microsoft/Boot/it-IT/memtest.efi.mui is signed
✓ /boot/EFI/Microsoft/Boot/ja-JP/bootmgfw.efi.mui is signed
✓ /boot/EFI/Microsoft/Boot/ja-JP/bootmgr.efi.mui is signed
✓ /boot/EFI/Microsoft/Boot/ja-JP/memtest.efi.mui is signed
✓ /boot/EFI/Microsoft/Boot/kd_02_10df.dll is signed
✓ /boot/EFI/Microsoft/Boot/kd_02_10ec.dll is signed
✓ /boot/EFI/Microsoft/Boot/kd_02_1137.dll is signed
✓ /boot/EFI/Microsoft/Boot/kd_02_1414.dll is signed
✓ /boot/EFI/Microsoft/Boot/kd_02_14e4.dll is signed
✓ /boot/EFI/Microsoft/Boot/kd_02_15ad.dll is signed
✓ /boot/EFI/Microsoft/Boot/kd_02_15b3.dll is signed
✓ /boot/EFI/Microsoft/Boot/kd_02_1969.dll is signed
✓ /boot/EFI/Microsoft/Boot/kd_02_19a2.dll is signed
✓ /boot/EFI/Microsoft/Boot/kd_02_1af4.dll is signed
✓ /boot/EFI/Microsoft/Boot/kd_02_1d0f.dll is signed
✓ /boot/EFI/Microsoft/Boot/kd_02_8086.dll is signed
✓ /boot/EFI/Microsoft/Boot/kd_07_1415.dll is signed
✓ /boot/EFI/Microsoft/Boot/kd_0C_8086.dll is signed
✓ /boot/EFI/Microsoft/Boot/kdnet_uart16550.dll is signed
✓ /boot/EFI/Microsoft/Boot/kdstub.dll is signed
✓ /boot/EFI/Microsoft/Boot/ko-KR/bootmgfw.efi.mui is signed
✓ /boot/EFI/Microsoft/Boot/ko-KR/bootmgr.efi.mui is signed
✓ /boot/EFI/Microsoft/Boot/ko-KR/memtest.efi.mui is signed
✓ /boot/EFI/Microsoft/Boot/lt-LT/bootmgfw.efi.mui is signed
✓ /boot/EFI/Microsoft/Boot/lt-LT/bootmgr.efi.mui is signed
✓ /boot/EFI/Microsoft/Boot/lv-LV/bootmgfw.efi.mui is signed
✓ /boot/EFI/Microsoft/Boot/lv-LV/bootmgr.efi.mui is signed
✓ /boot/EFI/Microsoft/Boot/memtest.efi is signed
✓ /boot/EFI/Microsoft/Boot/nb-NO/bootmgfw.efi.mui is signed
✓ /boot/EFI/Microsoft/Boot/nb-NO/bootmgr.efi.mui is signed
✓ /boot/EFI/Microsoft/Boot/nb-NO/memtest.efi.mui is signed
✓ /boot/EFI/Microsoft/Boot/nl-NL/bootmgfw.efi.mui is signed
✓ /boot/EFI/Microsoft/Boot/nl-NL/bootmgr.efi.mui is signed
✓ /boot/EFI/Microsoft/Boot/nl-NL/memtest.efi.mui is signed
✓ /boot/EFI/Microsoft/Boot/pl-PL/bootmgfw.efi.mui is signed
✓ /boot/EFI/Microsoft/Boot/pl-PL/bootmgr.efi.mui is signed
✓ /boot/EFI/Microsoft/Boot/pl-PL/memtest.efi.mui is signed
✓ /boot/EFI/Microsoft/Boot/pt-BR/bootmgfw.efi.mui is signed
✓ /boot/EFI/Microsoft/Boot/pt-BR/bootmgr.efi.mui is signed
✓ /boot/EFI/Microsoft/Boot/pt-BR/memtest.efi.mui is signed
✓ /boot/EFI/Microsoft/Boot/pt-PT/bootmgfw.efi.mui is signed
✓ /boot/EFI/Microsoft/Boot/pt-PT/bootmgr.efi.mui is signed
✓ /boot/EFI/Microsoft/Boot/pt-PT/memtest.efi.mui is signed
✓ /boot/EFI/Microsoft/Boot/qps-ploc/memtest.efi.mui is signed
✓ /boot/EFI/Microsoft/Boot/qps-plocm/memtest.efi.mui is signed
✓ /boot/EFI/Microsoft/Boot/ro-RO/bootmgfw.efi.mui is signed
✓ /boot/EFI/Microsoft/Boot/ro-RO/bootmgr.efi.mui is signed
✓ /boot/EFI/Microsoft/Boot/ru-RU/bootmgfw.efi.mui is signed
✓ /boot/EFI/Microsoft/Boot/ru-RU/bootmgr.efi.mui is signed
✓ /boot/EFI/Microsoft/Boot/ru-RU/memtest.efi.mui is signed
✓ /boot/EFI/Microsoft/Boot/sk-SK/bootmgfw.efi.mui is signed
✓ /boot/EFI/Microsoft/Boot/sk-SK/bootmgr.efi.mui is signed
✓ /boot/EFI/Microsoft/Boot/sl-SI/bootmgfw.efi.mui is signed
✓ /boot/EFI/Microsoft/Boot/sl-SI/bootmgr.efi.mui is signed
✓ /boot/EFI/Microsoft/Boot/sr-Latn-RS/bootmgfw.efi.mui is signed
✓ /boot/EFI/Microsoft/Boot/sr-Latn-RS/bootmgr.efi.mui is signed
✓ /boot/EFI/Microsoft/Boot/sv-SE/bootmgfw.efi.mui is signed
✓ /boot/EFI/Microsoft/Boot/sv-SE/bootmgr.efi.mui is signed
✓ /boot/EFI/Microsoft/Boot/sv-SE/memtest.efi.mui is signed
✓ /boot/EFI/Microsoft/Boot/tr-TR/bootmgfw.efi.mui is signed
✓ /boot/EFI/Microsoft/Boot/tr-TR/bootmgr.efi.mui is signed
✓ /boot/EFI/Microsoft/Boot/tr-TR/memtest.efi.mui is signed
✓ /boot/EFI/Microsoft/Boot/uk-UA/bootmgfw.efi.mui is signed
✓ /boot/EFI/Microsoft/Boot/uk-UA/bootmgr.efi.mui is signed
✓ /boot/EFI/Microsoft/Boot/zh-CN/bootmgfw.efi.mui is signed
✓ /boot/EFI/Microsoft/Boot/zh-CN/bootmgr.efi.mui is signed
✓ /boot/EFI/Microsoft/Boot/zh-CN/memtest.efi.mui is signed
✓ /boot/EFI/Microsoft/Boot/zh-TW/bootmgfw.efi.mui is signed
✓ /boot/EFI/Microsoft/Boot/zh-TW/bootmgr.efi.mui is signed
✓ /boot/EFI/Microsoft/Boot/zh-TW/memtest.efi.mui is signed
✓ /boot/EFI/debian/fbx64.efi is signed
✓ /boot/EFI/debian/grubx64.efi is signed
✓ /boot/EFI/debian/mmx64.efi is signed
✓ /boot/EFI/debian/shimx64.efi is signed
✓ /boot/EFI/ubuntu/grubx64.efi is signed
✓ /boot/EFI/ubuntu/mmx64.efi is signed
✓ /boot/EFI/ubuntu/shimx64.efi is signed
✓ /boot/grub/x86_64-efi/core.efi is signed
✓ /boot/grub/x86_64-efi/grub.efi is signed
✓ /boot/vmlinuz-linux is signed
✓ /boot/vmlinuz-linux-lts is signed
[donald@donald-Inspiron-3910 ~]$ 

I ran

[donald@donald-Inspiron-3910 ~]$ sudo sbctl verify | sed 's/✓ /sudo sbctl sign -s /e'
[sudo] password for donald: 
Verifying file database and EFI images in /boot...
File has already been signed /boot/Boot/Resources/bootres.dll
File has already been signed /boot/Boot/Resources/cs-CZ/bootres.dll.mui
File has already been signed /boot/Boot/Resources/da-DK/bootres.dll.mui
File has already been signed /boot/Boot/Resources/de-DE/bootres.dll.mui
File has already been signed /boot/Boot/Resources/el-GR/bootres.dll.mui
File has already been signed /boot/Boot/Resources/en-US/bootres.dll.mui
File has already been signed /boot/Boot/Resources/es-ES/bootres.dll.mui
File has already been signed /boot/Boot/Resources/fi-FI/bootres.dll.mui
File has already been signed /boot/Boot/Resources/fr-FR/bootres.dll.mui
File has already been signed /boot/Boot/Resources/hu-HU/bootres.dll.mui
File has already been signed /boot/Boot/Resources/it-IT/bootres.dll.mui
File has already been signed /boot/Boot/Resources/nb-NO/bootres.dll.mui
File has already been signed /boot/Boot/Resources/nl-NL/bootres.dll.mui
File has already been signed /boot/Boot/Resources/pl-PL/bootres.dll.mui
File has already been signed /boot/Boot/Resources/pt-BR/bootres.dll.mui
File has already been signed /boot/Boot/Resources/pt-PT/bootres.dll.mui
File has already been signed /boot/Boot/Resources/ru-RU/bootres.dll.mui
File has already been signed /boot/Boot/Resources/sv-SE/bootres.dll.mui
File has already been signed /boot/Boot/Resources/tr-TR/bootres.dll.mui
File has already been signed /boot/Boot/bg-BG/bootmgr.exe.mui
File has already been signed /boot/Boot/bootuwf.dll
File has already been signed /boot/Boot/bootvhd.dll
File has already been signed /boot/Boot/cs-CZ/bootmgr.exe.mui
File has already been signed /boot/Boot/cs-CZ/memtest.exe.mui
File has already been signed /boot/Boot/da-DK/bootmgr.exe.mui
File has already been signed /boot/Boot/da-DK/memtest.exe.mui
File has already been signed /boot/Boot/de-DE/bootmgr.exe.mui
File has already been signed /boot/Boot/de-DE/memtest.exe.mui
File has already been signed /boot/Boot/el-GR/bootmgr.exe.mui
File has already been signed /boot/Boot/el-GR/memtest.exe.mui
File has already been signed /boot/Boot/en-GB/bootmgr.exe.mui
File has already been signed /boot/Boot/en-US/bootmgr.exe.mui
File has already been signed /boot/Boot/en-US/memtest.exe.mui
File has already been signed /boot/Boot/es-ES/bootmgr.exe.mui
File has already been signed /boot/Boot/es-ES/memtest.exe.mui
File has already been signed /boot/Boot/es-MX/bootmgr.exe.mui
File has already been signed /boot/Boot/et-EE/bootmgr.exe.mui
File has already been signed /boot/Boot/fi-FI/bootmgr.exe.mui
File has already been signed /boot/Boot/fi-FI/memtest.exe.mui
File has already been signed /boot/Boot/fr-CA/bootmgr.exe.mui
File has already been signed /boot/Boot/fr-FR/bootmgr.exe.mui
File has already been signed /boot/Boot/fr-FR/memtest.exe.mui
File has already been signed /boot/Boot/hr-HR/bootmgr.exe.mui
File has already been signed /boot/Boot/hu-HU/bootmgr.exe.mui
File has already been signed /boot/Boot/hu-HU/memtest.exe.mui
File has already been signed /boot/Boot/it-IT/bootmgr.exe.mui
File has already been signed /boot/Boot/it-IT/memtest.exe.mui
File has already been signed /boot/Boot/ja-JP/bootmgr.exe.mui
File has already been signed /boot/Boot/ja-JP/memtest.exe.mui
File has already been signed /boot/Boot/ko-KR/bootmgr.exe.mui
File has already been signed /boot/Boot/ko-KR/memtest.exe.mui
File has already been signed /boot/Boot/lt-LT/bootmgr.exe.mui
File has already been signed /boot/Boot/lv-LV/bootmgr.exe.mui
File has already been signed /boot/Boot/nb-NO/bootmgr.exe.mui
File has already been signed /boot/Boot/nb-NO/memtest.exe.mui
File has already been signed /boot/Boot/nl-NL/bootmgr.exe.mui
File has already been signed /boot/Boot/nl-NL/memtest.exe.mui
File has already been signed /boot/Boot/pl-PL/bootmgr.exe.mui
File has already been signed /boot/Boot/pl-PL/memtest.exe.mui
File has already been signed /boot/Boot/pt-BR/bootmgr.exe.mui
File has already been signed /boot/Boot/pt-BR/memtest.exe.mui
File has already been signed /boot/Boot/pt-PT/bootmgr.exe.mui
File has already been signed /boot/Boot/pt-PT/memtest.exe.mui
File has already been signed /boot/Boot/qps-ploc/bootmgr.exe.mui
File has already been signed /boot/Boot/qps-ploc/memtest.exe.mui
File has already been signed /boot/Boot/qps-plocm/bootmgr.exe.mui
File has already been signed /boot/Boot/qps-plocm/memtest.exe.mui
File has already been signed /boot/Boot/ro-RO/bootmgr.exe.mui
File has already been signed /boot/Boot/ru-RU/bootmgr.exe.mui
File has already been signed /boot/Boot/ru-RU/memtest.exe.mui
File has already been signed /boot/Boot/sk-SK/bootmgr.exe.mui
File has already been signed /boot/Boot/sl-SI/bootmgr.exe.mui
File has already been signed /boot/Boot/sr-Latn-RS/bootmgr.exe.mui
File has already been signed /boot/Boot/sv-SE/bootmgr.exe.mui
File has already been signed /boot/Boot/sv-SE/memtest.exe.mui
File has already been signed /boot/Boot/tr-TR/bootmgr.exe.mui
File has already been signed /boot/Boot/tr-TR/memtest.exe.mui
File has already been signed /boot/Boot/uk-UA/bootmgr.exe.mui
File has already been signed /boot/Boot/zh-CN/bootmgr.exe.mui
File has already been signed /boot/Boot/zh-CN/memtest.exe.mui
File has already been signed /boot/Boot/zh-TW/bootmgr.exe.mui
File has already been signed /boot/Boot/zh-TW/memtest.exe.mui
File has already been signed /boot/EFI/Boot/bootx64.efi
File has already been signed /boot/EFI/Boot/fbx64.efi
File has already been signed /boot/EFI/Boot/mmx64.efi
File has already been signed /boot/EFI/Dell/SOS/bootmgfw.efi
File has already been signed /boot/EFI/Dell/SOS/bootx64.efi
File has already been signed /boot/EFI/GRUB/grubx64.efi
File has already been signed /boot/EFI/Microsoft/Boot/Resources/bootres.dll
File has already been signed /boot/EFI/Microsoft/Boot/Resources/cs-CZ/bootres.dll.mui
File has already been signed /boot/EFI/Microsoft/Boot/Resources/da-DK/bootres.dll.mui
File has already been signed /boot/EFI/Microsoft/Boot/Resources/de-DE/bootres.dll.mui
File has already been signed /boot/EFI/Microsoft/Boot/Resources/el-GR/bootres.dll.mui
File has already been signed /boot/EFI/Microsoft/Boot/Resources/en-US/bootres.dll.mui
File has already been signed /boot/EFI/Microsoft/Boot/Resources/es-ES/bootres.dll.mui
File has already been signed /boot/EFI/Microsoft/Boot/Resources/fi-FI/bootres.dll.mui
File has already been signed /boot/EFI/Microsoft/Boot/Resources/fr-FR/bootres.dll.mui
File has already been signed /boot/EFI/Microsoft/Boot/Resources/hu-HU/bootres.dll.mui
File has already been signed /boot/EFI/Microsoft/Boot/Resources/it-IT/bootres.dll.mui
File has already been signed /boot/EFI/Microsoft/Boot/Resources/nb-NO/bootres.dll.mui
File has already been signed /boot/EFI/Microsoft/Boot/Resources/nl-NL/bootres.dll.mui
File has already been signed /boot/EFI/Microsoft/Boot/Resources/pl-PL/bootres.dll.mui
File has already been signed /boot/EFI/Microsoft/Boot/Resources/pt-BR/bootres.dll.mui
File has already been signed /boot/EFI/Microsoft/Boot/Resources/pt-PT/bootres.dll.mui
File has already been signed /boot/EFI/Microsoft/Boot/Resources/ru-RU/bootres.dll.mui
File has already been signed /boot/EFI/Microsoft/Boot/Resources/sv-SE/bootres.dll.mui
File has already been signed /boot/EFI/Microsoft/Boot/Resources/tr-TR/bootres.dll.mui
File has already been signed /boot/EFI/Microsoft/Boot/SecureBootRecovery.efi
File has already been signed /boot/EFI/Microsoft/Boot/bg-BG/bootmgfw.efi.mui
File has already been signed /boot/EFI/Microsoft/Boot/bg-BG/bootmgr.efi.mui
File has already been signed /boot/EFI/Microsoft/Boot/bootmgfw.efi
File has already been signed /boot/EFI/Microsoft/Boot/bootmgr.efi
File has already been signed /boot/EFI/Microsoft/Boot/cs-CZ/bootmgfw.efi.mui
File has already been signed /boot/EFI/Microsoft/Boot/cs-CZ/bootmgr.efi.mui
File has already been signed /boot/EFI/Microsoft/Boot/cs-CZ/memtest.efi.mui
File has already been signed /boot/EFI/Microsoft/Boot/da-DK/bootmgfw.efi.mui
File has already been signed /boot/EFI/Microsoft/Boot/da-DK/bootmgr.efi.mui
File has already been signed /boot/EFI/Microsoft/Boot/da-DK/memtest.efi.mui
File has already been signed /boot/EFI/Microsoft/Boot/de-DE/bootmgfw.efi.mui
File has already been signed /boot/EFI/Microsoft/Boot/de-DE/bootmgr.efi.mui
File has already been signed /boot/EFI/Microsoft/Boot/de-DE/memtest.efi.mui
File has already been signed /boot/EFI/Microsoft/Boot/el-GR/bootmgfw.efi.mui
File has already been signed /boot/EFI/Microsoft/Boot/el-GR/bootmgr.efi.mui
File has already been signed /boot/EFI/Microsoft/Boot/el-GR/memtest.efi.mui
File has already been signed /boot/EFI/Microsoft/Boot/en-GB/bootmgfw.efi.mui
File has already been signed /boot/EFI/Microsoft/Boot/en-GB/bootmgr.efi.mui
File has already been signed /boot/EFI/Microsoft/Boot/en-US/bootmgfw.efi.mui
File has already been signed /boot/EFI/Microsoft/Boot/en-US/bootmgr.efi.mui
File has already been signed /boot/EFI/Microsoft/Boot/en-US/memtest.efi.mui
File has already been signed /boot/EFI/Microsoft/Boot/es-ES/bootmgfw.efi.mui
File has already been signed /boot/EFI/Microsoft/Boot/es-ES/bootmgr.efi.mui
File has already been signed /boot/EFI/Microsoft/Boot/es-ES/memtest.efi.mui
File has already been signed /boot/EFI/Microsoft/Boot/es-MX/bootmgfw.efi.mui
File has already been signed /boot/EFI/Microsoft/Boot/es-MX/bootmgr.efi.mui
File has already been signed /boot/EFI/Microsoft/Boot/et-EE/bootmgfw.efi.mui
File has already been signed /boot/EFI/Microsoft/Boot/et-EE/bootmgr.efi.mui
File has already been signed /boot/EFI/Microsoft/Boot/fi-FI/bootmgfw.efi.mui
File has already been signed /boot/EFI/Microsoft/Boot/fi-FI/bootmgr.efi.mui
File has already been signed /boot/EFI/Microsoft/Boot/fi-FI/memtest.efi.mui
File has already been signed /boot/EFI/Microsoft/Boot/fr-CA/bootmgfw.efi.mui
File has already been signed /boot/EFI/Microsoft/Boot/fr-CA/bootmgr.efi.mui
File has already been signed /boot/EFI/Microsoft/Boot/fr-FR/bootmgfw.efi.mui
File has already been signed /boot/EFI/Microsoft/Boot/fr-FR/bootmgr.efi.mui
File has already been signed /boot/EFI/Microsoft/Boot/fr-FR/memtest.efi.mui
File has already been signed /boot/EFI/Microsoft/Boot/hr-HR/bootmgfw.efi.mui
File has already been signed /boot/EFI/Microsoft/Boot/hr-HR/bootmgr.efi.mui
File has already been signed /boot/EFI/Microsoft/Boot/hu-HU/bootmgfw.efi.mui
File has already been signed /boot/EFI/Microsoft/Boot/hu-HU/bootmgr.efi.mui
File has already been signed /boot/EFI/Microsoft/Boot/hu-HU/memtest.efi.mui
File has already been signed /boot/EFI/Microsoft/Boot/it-IT/bootmgfw.efi.mui
File has already been signed /boot/EFI/Microsoft/Boot/it-IT/bootmgr.efi.mui
File has already been signed /boot/EFI/Microsoft/Boot/it-IT/memtest.efi.mui
File has already been signed /boot/EFI/Microsoft/Boot/ja-JP/bootmgfw.efi.mui
File has already been signed /boot/EFI/Microsoft/Boot/ja-JP/bootmgr.efi.mui
File has already been signed /boot/EFI/Microsoft/Boot/ja-JP/memtest.efi.mui
File has already been signed /boot/EFI/Microsoft/Boot/kd_02_10df.dll
File has already been signed /boot/EFI/Microsoft/Boot/kd_02_10ec.dll
File has already been signed /boot/EFI/Microsoft/Boot/kd_02_1137.dll
File has already been signed /boot/EFI/Microsoft/Boot/kd_02_1414.dll
File has already been signed /boot/EFI/Microsoft/Boot/kd_02_14e4.dll
File has already been signed /boot/EFI/Microsoft/Boot/kd_02_15ad.dll
File has already been signed /boot/EFI/Microsoft/Boot/kd_02_15b3.dll
File has already been signed /boot/EFI/Microsoft/Boot/kd_02_1969.dll
File has already been signed /boot/EFI/Microsoft/Boot/kd_02_19a2.dll
File has already been signed /boot/EFI/Microsoft/Boot/kd_02_1af4.dll
File has already been signed /boot/EFI/Microsoft/Boot/kd_02_1d0f.dll
File has already been signed /boot/EFI/Microsoft/Boot/kd_02_8086.dll
File has already been signed /boot/EFI/Microsoft/Boot/kd_07_1415.dll
File has already been signed /boot/EFI/Microsoft/Boot/kd_0C_8086.dll
File has already been signed /boot/EFI/Microsoft/Boot/kdnet_uart16550.dll
File has already been signed /boot/EFI/Microsoft/Boot/kdstub.dll
File has already been signed /boot/EFI/Microsoft/Boot/ko-KR/bootmgfw.efi.mui
File has already been signed /boot/EFI/Microsoft/Boot/ko-KR/bootmgr.efi.mui
File has already been signed /boot/EFI/Microsoft/Boot/ko-KR/memtest.efi.mui
File has already been signed /boot/EFI/Microsoft/Boot/lt-LT/bootmgfw.efi.mui
File has already been signed /boot/EFI/Microsoft/Boot/lt-LT/bootmgr.efi.mui
File has already been signed /boot/EFI/Microsoft/Boot/lv-LV/bootmgfw.efi.mui
File has already been signed /boot/EFI/Microsoft/Boot/lv-LV/bootmgr.efi.mui
File has already been signed /boot/EFI/Microsoft/Boot/memtest.efi
File has already been signed /boot/EFI/Microsoft/Boot/nb-NO/bootmgfw.efi.mui
File has already been signed /boot/EFI/Microsoft/Boot/nb-NO/bootmgr.efi.mui
File has already been signed /boot/EFI/Microsoft/Boot/nb-NO/memtest.efi.mui
File has already been signed /boot/EFI/Microsoft/Boot/nl-NL/bootmgfw.efi.mui
File has already been signed /boot/EFI/Microsoft/Boot/nl-NL/bootmgr.efi.mui
File has already been signed /boot/EFI/Microsoft/Boot/nl-NL/memtest.efi.mui
File has already been signed /boot/EFI/Microsoft/Boot/pl-PL/bootmgfw.efi.mui
File has already been signed /boot/EFI/Microsoft/Boot/pl-PL/bootmgr.efi.mui
File has already been signed /boot/EFI/Microsoft/Boot/pl-PL/memtest.efi.mui
File has already been signed /boot/EFI/Microsoft/Boot/pt-BR/bootmgfw.efi.mui
File has already been signed /boot/EFI/Microsoft/Boot/pt-BR/bootmgr.efi.mui
File has already been signed /boot/EFI/Microsoft/Boot/pt-BR/memtest.efi.mui
File has already been signed /boot/EFI/Microsoft/Boot/pt-PT/bootmgfw.efi.mui
File has already been signed /boot/EFI/Microsoft/Boot/pt-PT/bootmgr.efi.mui
File has already been signed /boot/EFI/Microsoft/Boot/pt-PT/memtest.efi.mui
File has already been signed /boot/EFI/Microsoft/Boot/qps-ploc/memtest.efi.mui
File has already been signed /boot/EFI/Microsoft/Boot/qps-plocm/memtest.efi.mui
File has already been signed /boot/EFI/Microsoft/Boot/ro-RO/bootmgfw.efi.mui
File has already been signed /boot/EFI/Microsoft/Boot/ro-RO/bootmgr.efi.mui
File has already been signed /boot/EFI/Microsoft/Boot/ru-RU/bootmgfw.efi.mui
File has already been signed /boot/EFI/Microsoft/Boot/ru-RU/bootmgr.efi.mui
File has already been signed /boot/EFI/Microsoft/Boot/ru-RU/memtest.efi.mui
File has already been signed /boot/EFI/Microsoft/Boot/sk-SK/bootmgfw.efi.mui
File has already been signed /boot/EFI/Microsoft/Boot/sk-SK/bootmgr.efi.mui
File has already been signed /boot/EFI/Microsoft/Boot/sl-SI/bootmgfw.efi.mui
File has already been signed /boot/EFI/Microsoft/Boot/sl-SI/bootmgr.efi.mui
File has already been signed /boot/EFI/Microsoft/Boot/sr-Latn-RS/bootmgfw.efi.mui
File has already been signed /boot/EFI/Microsoft/Boot/sr-Latn-RS/bootmgr.efi.mui
File has already been signed /boot/EFI/Microsoft/Boot/sv-SE/bootmgfw.efi.mui
File has already been signed /boot/EFI/Microsoft/Boot/sv-SE/bootmgr.efi.mui
File has already been signed /boot/EFI/Microsoft/Boot/sv-SE/memtest.efi.mui
File has already been signed /boot/EFI/Microsoft/Boot/tr-TR/bootmgfw.efi.mui
File has already been signed /boot/EFI/Microsoft/Boot/tr-TR/bootmgr.efi.mui
File has already been signed /boot/EFI/Microsoft/Boot/tr-TR/memtest.efi.mui
File has already been signed /boot/EFI/Microsoft/Boot/uk-UA/bootmgfw.efi.mui
File has already been signed /boot/EFI/Microsoft/Boot/uk-UA/bootmgr.efi.mui
File has already been signed /boot/EFI/Microsoft/Boot/zh-CN/bootmgfw.efi.mui
File has already been signed /boot/EFI/Microsoft/Boot/zh-CN/bootmgr.efi.mui
File has already been signed /boot/EFI/Microsoft/Boot/zh-CN/memtest.efi.mui
File has already been signed /boot/EFI/Microsoft/Boot/zh-TW/bootmgfw.efi.mui
File has already been signed /boot/EFI/Microsoft/Boot/zh-TW/bootmgr.efi.mui
File has already been signed /boot/EFI/Microsoft/Boot/zh-TW/memtest.efi.mui
File has already been signed /boot/EFI/debian/fbx64.efi
File has already been signed /boot/EFI/debian/grubx64.efi
File has already been signed /boot/EFI/debian/mmx64.efi
File has already been signed /boot/EFI/debian/shimx64.efi
File has already been signed /boot/EFI/ubuntu/grubx64.efi
File has already been signed /boot/EFI/ubuntu/mmx64.efi
File has already been signed /boot/EFI/ubuntu/shimx64.efi
File has already been signed /boot/grub/x86_64-efi/core.efi
File has already been signed /boot/grub/x86_64-efi/grub.efi
File has already been signed /boot/vmlinuz-linux
File has already been signed /boot/vmlinuz-linux-lts
[donald@donald-Inspiron-3910 ~]$

but still

[donald@donald-Inspiron-3910 ~]$ sbctl list-files
[donald@donald-Inspiron-3910 ~]$

How can I repopulate the database?  I suppose I could reinstall linux and grub.  That would allow me to resign the files and then presumably they would be added to the database again.  But what about the Windows files?  I have suggestions from AI on how to remove the signature but can't find any supporting links in my searches so I haven't tried these.  If I could remove the "signed" signature from these files then I coud run the original command  from the Arch Wiki again "sudo sbctl verify | sed 's/✗ /sbctl sign -s /e'" and presumably it would sign them and add them to the database.

Thanks in advance!

Last edited by cabaz (Today 01:12:17)

Offline

#2 Today 00:08:22

cabaz
Member
Registered: 2019-03-28
Posts: 3

Re: sbctl database files for secure boot were deleted.

I got this command from AI (although I checked out the parts).

[donald@donald-Inspiron-3910 ~]$ sudo sbctl verify | grep '✓' | awk '{print $2}' | xargs -I {} sudo sbattach --remove "{}"
[sudo] password for donald: 
warning: data remaining[833080 vs 959152]: gaps between PE/COFF sections?
warning: data remaining[74296 vs 88520]: gaps between PE/COFF sections?
warning: data remaining[738360 vs 856456]: gaps between PE/COFF sections?
warning: data remaining[74296 vs 88520]: gaps between PE/COFF sections?
warning: data remaining[732728 vs 850808]: gaps between PE/COFF sections?
warning: data remaining[823352 vs 949472]: gaps between PE/COFF sections?
warning: data remaining[738360 vs 856456]: gaps between PE/COFF sections?
warning: data remaining[833080 vs 959152]: gaps between PE/COFF sections?
[donald@donald-Inspiron-3910 ~]$

Not sure what to say about the gaps.  But it seems to have unsigned everything.

[donald@donald-Inspiron-3910 ~]$ sudo sbctl verify
Verifying file database and EFI images in /boot...
✗ /boot/Boot/Resources/bootres.dll is not signed
✗ /boot/Boot/Resources/cs-CZ/bootres.dll.mui is not signed
✗ /boot/Boot/Resources/da-DK/bootres.dll.mui is not signed
✗ /boot/Boot/Resources/de-DE/bootres.dll.mui is not signed
✗ /boot/Boot/Resources/el-GR/bootres.dll.mui is not signed
✗ /boot/Boot/Resources/en-US/bootres.dll.mui is not signed
✗ /boot/Boot/Resources/es-ES/bootres.dll.mui is not signed
✗ /boot/Boot/Resources/fi-FI/bootres.dll.mui is not signed
✗ /boot/Boot/Resources/fr-FR/bootres.dll.mui is not signed
✗ /boot/Boot/Resources/hu-HU/bootres.dll.mui is not signed
✗ /boot/Boot/Resources/it-IT/bootres.dll.mui is not signed
✗ /boot/Boot/Resources/nb-NO/bootres.dll.mui is not signed
✗ /boot/Boot/Resources/nl-NL/bootres.dll.mui is not signed
✗ /boot/Boot/Resources/pl-PL/bootres.dll.mui is not signed
✗ /boot/Boot/Resources/pt-BR/bootres.dll.mui is not signed
✗ /boot/Boot/Resources/pt-PT/bootres.dll.mui is not signed
✗ /boot/Boot/Resources/ru-RU/bootres.dll.mui is not signed
✗ /boot/Boot/Resources/sv-SE/bootres.dll.mui is not signed
✗ /boot/Boot/Resources/tr-TR/bootres.dll.mui is not signed
✗ /boot/Boot/bg-BG/bootmgr.exe.mui is not signed
✗ /boot/Boot/bootuwf.dll is not signed
✗ /boot/Boot/bootvhd.dll is not signed
✗ /boot/Boot/cs-CZ/bootmgr.exe.mui is not signed
✗ /boot/Boot/cs-CZ/memtest.exe.mui is not signed
✗ /boot/Boot/da-DK/bootmgr.exe.mui is not signed
✗ /boot/Boot/da-DK/memtest.exe.mui is not signed
✗ /boot/Boot/de-DE/bootmgr.exe.mui is not signed
✗ /boot/Boot/de-DE/memtest.exe.mui is not signed
✗ /boot/Boot/el-GR/bootmgr.exe.mui is not signed
✗ /boot/Boot/el-GR/memtest.exe.mui is not signed
✗ /boot/Boot/en-GB/bootmgr.exe.mui is not signed
✗ /boot/Boot/en-US/bootmgr.exe.mui is not signed
✗ /boot/Boot/en-US/memtest.exe.mui is not signed
✗ /boot/Boot/es-ES/bootmgr.exe.mui is not signed
✗ /boot/Boot/es-ES/memtest.exe.mui is not signed
✗ /boot/Boot/es-MX/bootmgr.exe.mui is not signed
✗ /boot/Boot/et-EE/bootmgr.exe.mui is not signed
✗ /boot/Boot/fi-FI/bootmgr.exe.mui is not signed
✗ /boot/Boot/fi-FI/memtest.exe.mui is not signed
✗ /boot/Boot/fr-CA/bootmgr.exe.mui is not signed
✗ /boot/Boot/fr-FR/bootmgr.exe.mui is not signed
✗ /boot/Boot/fr-FR/memtest.exe.mui is not signed
✗ /boot/Boot/hr-HR/bootmgr.exe.mui is not signed
✗ /boot/Boot/hu-HU/bootmgr.exe.mui is not signed
✗ /boot/Boot/hu-HU/memtest.exe.mui is not signed
✗ /boot/Boot/it-IT/bootmgr.exe.mui is not signed
✗ /boot/Boot/it-IT/memtest.exe.mui is not signed
✗ /boot/Boot/ja-JP/bootmgr.exe.mui is not signed
✗ /boot/Boot/ja-JP/memtest.exe.mui is not signed
✗ /boot/Boot/ko-KR/bootmgr.exe.mui is not signed
✗ /boot/Boot/ko-KR/memtest.exe.mui is not signed
✗ /boot/Boot/lt-LT/bootmgr.exe.mui is not signed
✗ /boot/Boot/lv-LV/bootmgr.exe.mui is not signed
✗ /boot/Boot/nb-NO/bootmgr.exe.mui is not signed
✗ /boot/Boot/nb-NO/memtest.exe.mui is not signed
✗ /boot/Boot/nl-NL/bootmgr.exe.mui is not signed
✗ /boot/Boot/nl-NL/memtest.exe.mui is not signed
✗ /boot/Boot/pl-PL/bootmgr.exe.mui is not signed
✗ /boot/Boot/pl-PL/memtest.exe.mui is not signed
✗ /boot/Boot/pt-BR/bootmgr.exe.mui is not signed
✗ /boot/Boot/pt-BR/memtest.exe.mui is not signed
✗ /boot/Boot/pt-PT/bootmgr.exe.mui is not signed
✗ /boot/Boot/pt-PT/memtest.exe.mui is not signed
✗ /boot/Boot/qps-ploc/bootmgr.exe.mui is not signed
✗ /boot/Boot/qps-ploc/memtest.exe.mui is not signed
✗ /boot/Boot/qps-plocm/bootmgr.exe.mui is not signed
✗ /boot/Boot/qps-plocm/memtest.exe.mui is not signed
✗ /boot/Boot/ro-RO/bootmgr.exe.mui is not signed
✗ /boot/Boot/ru-RU/bootmgr.exe.mui is not signed
✗ /boot/Boot/ru-RU/memtest.exe.mui is not signed
✗ /boot/Boot/sk-SK/bootmgr.exe.mui is not signed
✗ /boot/Boot/sl-SI/bootmgr.exe.mui is not signed
✗ /boot/Boot/sr-Latn-RS/bootmgr.exe.mui is not signed
✗ /boot/Boot/sv-SE/bootmgr.exe.mui is not signed
✗ /boot/Boot/sv-SE/memtest.exe.mui is not signed
✗ /boot/Boot/tr-TR/bootmgr.exe.mui is not signed
✗ /boot/Boot/tr-TR/memtest.exe.mui is not signed
✗ /boot/Boot/uk-UA/bootmgr.exe.mui is not signed
✗ /boot/Boot/zh-CN/bootmgr.exe.mui is not signed
✗ /boot/Boot/zh-CN/memtest.exe.mui is not signed
✗ /boot/Boot/zh-TW/bootmgr.exe.mui is not signed
✗ /boot/Boot/zh-TW/memtest.exe.mui is not signed
✗ /boot/EFI/Boot/bootx64.efi is not signed
✗ /boot/EFI/Boot/fbx64.efi is not signed
✗ /boot/EFI/Boot/mmx64.efi is not signed
✗ /boot/EFI/Dell/SOS/bootmgfw.efi is not signed
✗ /boot/EFI/Dell/SOS/bootx64.efi is not signed
✗ /boot/EFI/GRUB/grubx64.efi is not signed
✗ /boot/EFI/Microsoft/Boot/Resources/bootres.dll is not signed
✗ /boot/EFI/Microsoft/Boot/Resources/cs-CZ/bootres.dll.mui is not signed
✗ /boot/EFI/Microsoft/Boot/Resources/da-DK/bootres.dll.mui is not signed
✗ /boot/EFI/Microsoft/Boot/Resources/de-DE/bootres.dll.mui is not signed
✗ /boot/EFI/Microsoft/Boot/Resources/el-GR/bootres.dll.mui is not signed
✗ /boot/EFI/Microsoft/Boot/Resources/en-US/bootres.dll.mui is not signed
✗ /boot/EFI/Microsoft/Boot/Resources/es-ES/bootres.dll.mui is not signed
✗ /boot/EFI/Microsoft/Boot/Resources/fi-FI/bootres.dll.mui is not signed
✗ /boot/EFI/Microsoft/Boot/Resources/fr-FR/bootres.dll.mui is not signed
✗ /boot/EFI/Microsoft/Boot/Resources/hu-HU/bootres.dll.mui is not signed
✗ /boot/EFI/Microsoft/Boot/Resources/it-IT/bootres.dll.mui is not signed
✗ /boot/EFI/Microsoft/Boot/Resources/nb-NO/bootres.dll.mui is not signed
✗ /boot/EFI/Microsoft/Boot/Resources/nl-NL/bootres.dll.mui is not signed
✗ /boot/EFI/Microsoft/Boot/Resources/pl-PL/bootres.dll.mui is not signed
✗ /boot/EFI/Microsoft/Boot/Resources/pt-BR/bootres.dll.mui is not signed
✗ /boot/EFI/Microsoft/Boot/Resources/pt-PT/bootres.dll.mui is not signed
✗ /boot/EFI/Microsoft/Boot/Resources/ru-RU/bootres.dll.mui is not signed
✗ /boot/EFI/Microsoft/Boot/Resources/sv-SE/bootres.dll.mui is not signed
✗ /boot/EFI/Microsoft/Boot/Resources/tr-TR/bootres.dll.mui is not signed
✗ /boot/EFI/Microsoft/Boot/SecureBootRecovery.efi is not signed
✗ /boot/EFI/Microsoft/Boot/bg-BG/bootmgfw.efi.mui is not signed
✗ /boot/EFI/Microsoft/Boot/bg-BG/bootmgr.efi.mui is not signed
✗ /boot/EFI/Microsoft/Boot/bootmgfw.efi is not signed
✗ /boot/EFI/Microsoft/Boot/bootmgr.efi is not signed
✗ /boot/EFI/Microsoft/Boot/cs-CZ/bootmgfw.efi.mui is not signed
✗ /boot/EFI/Microsoft/Boot/cs-CZ/bootmgr.efi.mui is not signed
✗ /boot/EFI/Microsoft/Boot/cs-CZ/memtest.efi.mui is not signed
✗ /boot/EFI/Microsoft/Boot/da-DK/bootmgfw.efi.mui is not signed
✗ /boot/EFI/Microsoft/Boot/da-DK/bootmgr.efi.mui is not signed
✗ /boot/EFI/Microsoft/Boot/da-DK/memtest.efi.mui is not signed
✗ /boot/EFI/Microsoft/Boot/de-DE/bootmgfw.efi.mui is not signed
✗ /boot/EFI/Microsoft/Boot/de-DE/bootmgr.efi.mui is not signed
✗ /boot/EFI/Microsoft/Boot/de-DE/memtest.efi.mui is not signed
✗ /boot/EFI/Microsoft/Boot/el-GR/bootmgfw.efi.mui is not signed
✗ /boot/EFI/Microsoft/Boot/el-GR/bootmgr.efi.mui is not signed
✗ /boot/EFI/Microsoft/Boot/el-GR/memtest.efi.mui is not signed
✗ /boot/EFI/Microsoft/Boot/en-GB/bootmgfw.efi.mui is not signed
✗ /boot/EFI/Microsoft/Boot/en-GB/bootmgr.efi.mui is not signed
✗ /boot/EFI/Microsoft/Boot/en-US/bootmgfw.efi.mui is not signed
✗ /boot/EFI/Microsoft/Boot/en-US/bootmgr.efi.mui is not signed
✗ /boot/EFI/Microsoft/Boot/en-US/memtest.efi.mui is not signed
✗ /boot/EFI/Microsoft/Boot/es-ES/bootmgfw.efi.mui is not signed
✗ /boot/EFI/Microsoft/Boot/es-ES/bootmgr.efi.mui is not signed
✗ /boot/EFI/Microsoft/Boot/es-ES/memtest.efi.mui is not signed
✗ /boot/EFI/Microsoft/Boot/es-MX/bootmgfw.efi.mui is not signed
✗ /boot/EFI/Microsoft/Boot/es-MX/bootmgr.efi.mui is not signed
✗ /boot/EFI/Microsoft/Boot/et-EE/bootmgfw.efi.mui is not signed
✗ /boot/EFI/Microsoft/Boot/et-EE/bootmgr.efi.mui is not signed
✗ /boot/EFI/Microsoft/Boot/fi-FI/bootmgfw.efi.mui is not signed
✗ /boot/EFI/Microsoft/Boot/fi-FI/bootmgr.efi.mui is not signed
✗ /boot/EFI/Microsoft/Boot/fi-FI/memtest.efi.mui is not signed
✗ /boot/EFI/Microsoft/Boot/fr-CA/bootmgfw.efi.mui is not signed
✗ /boot/EFI/Microsoft/Boot/fr-CA/bootmgr.efi.mui is not signed
✗ /boot/EFI/Microsoft/Boot/fr-FR/bootmgfw.efi.mui is not signed
✗ /boot/EFI/Microsoft/Boot/fr-FR/bootmgr.efi.mui is not signed
✗ /boot/EFI/Microsoft/Boot/fr-FR/memtest.efi.mui is not signed
✗ /boot/EFI/Microsoft/Boot/hr-HR/bootmgfw.efi.mui is not signed
✗ /boot/EFI/Microsoft/Boot/hr-HR/bootmgr.efi.mui is not signed
✗ /boot/EFI/Microsoft/Boot/hu-HU/bootmgfw.efi.mui is not signed
✗ /boot/EFI/Microsoft/Boot/hu-HU/bootmgr.efi.mui is not signed
✗ /boot/EFI/Microsoft/Boot/hu-HU/memtest.efi.mui is not signed
✗ /boot/EFI/Microsoft/Boot/it-IT/bootmgfw.efi.mui is not signed
✗ /boot/EFI/Microsoft/Boot/it-IT/bootmgr.efi.mui is not signed
✗ /boot/EFI/Microsoft/Boot/it-IT/memtest.efi.mui is not signed
✗ /boot/EFI/Microsoft/Boot/ja-JP/bootmgfw.efi.mui is not signed
✗ /boot/EFI/Microsoft/Boot/ja-JP/bootmgr.efi.mui is not signed
✗ /boot/EFI/Microsoft/Boot/ja-JP/memtest.efi.mui is not signed
✗ /boot/EFI/Microsoft/Boot/kd_02_10df.dll is not signed
✗ /boot/EFI/Microsoft/Boot/kd_02_10ec.dll is not signed
✗ /boot/EFI/Microsoft/Boot/kd_02_1137.dll is not signed
✗ /boot/EFI/Microsoft/Boot/kd_02_1414.dll is not signed
✗ /boot/EFI/Microsoft/Boot/kd_02_14e4.dll is not signed
✗ /boot/EFI/Microsoft/Boot/kd_02_15ad.dll is not signed
✗ /boot/EFI/Microsoft/Boot/kd_02_15b3.dll is not signed
✗ /boot/EFI/Microsoft/Boot/kd_02_1969.dll is not signed
✗ /boot/EFI/Microsoft/Boot/kd_02_19a2.dll is not signed
✗ /boot/EFI/Microsoft/Boot/kd_02_1af4.dll is not signed
✗ /boot/EFI/Microsoft/Boot/kd_02_1d0f.dll is not signed
✗ /boot/EFI/Microsoft/Boot/kd_02_8086.dll is not signed
✗ /boot/EFI/Microsoft/Boot/kd_07_1415.dll is not signed
✗ /boot/EFI/Microsoft/Boot/kd_0C_8086.dll is not signed
✗ /boot/EFI/Microsoft/Boot/kdnet_uart16550.dll is not signed
✗ /boot/EFI/Microsoft/Boot/kdstub.dll is not signed
✗ /boot/EFI/Microsoft/Boot/ko-KR/bootmgfw.efi.mui is not signed
✗ /boot/EFI/Microsoft/Boot/ko-KR/bootmgr.efi.mui is not signed
✗ /boot/EFI/Microsoft/Boot/ko-KR/memtest.efi.mui is not signed
✗ /boot/EFI/Microsoft/Boot/lt-LT/bootmgfw.efi.mui is not signed
✗ /boot/EFI/Microsoft/Boot/lt-LT/bootmgr.efi.mui is not signed
✗ /boot/EFI/Microsoft/Boot/lv-LV/bootmgfw.efi.mui is not signed
✗ /boot/EFI/Microsoft/Boot/lv-LV/bootmgr.efi.mui is not signed
✗ /boot/EFI/Microsoft/Boot/memtest.efi is not signed
✗ /boot/EFI/Microsoft/Boot/nb-NO/bootmgfw.efi.mui is not signed
✗ /boot/EFI/Microsoft/Boot/nb-NO/bootmgr.efi.mui is not signed
✗ /boot/EFI/Microsoft/Boot/nb-NO/memtest.efi.mui is not signed
✗ /boot/EFI/Microsoft/Boot/nl-NL/bootmgfw.efi.mui is not signed
✗ /boot/EFI/Microsoft/Boot/nl-NL/bootmgr.efi.mui is not signed
✗ /boot/EFI/Microsoft/Boot/nl-NL/memtest.efi.mui is not signed
✗ /boot/EFI/Microsoft/Boot/pl-PL/bootmgfw.efi.mui is not signed
✗ /boot/EFI/Microsoft/Boot/pl-PL/bootmgr.efi.mui is not signed
✗ /boot/EFI/Microsoft/Boot/pl-PL/memtest.efi.mui is not signed
✗ /boot/EFI/Microsoft/Boot/pt-BR/bootmgfw.efi.mui is not signed
✗ /boot/EFI/Microsoft/Boot/pt-BR/bootmgr.efi.mui is not signed
✗ /boot/EFI/Microsoft/Boot/pt-BR/memtest.efi.mui is not signed
✗ /boot/EFI/Microsoft/Boot/pt-PT/bootmgfw.efi.mui is not signed
✗ /boot/EFI/Microsoft/Boot/pt-PT/bootmgr.efi.mui is not signed
✗ /boot/EFI/Microsoft/Boot/pt-PT/memtest.efi.mui is not signed
✗ /boot/EFI/Microsoft/Boot/qps-ploc/memtest.efi.mui is not signed
✗ /boot/EFI/Microsoft/Boot/qps-plocm/memtest.efi.mui is not signed
✗ /boot/EFI/Microsoft/Boot/ro-RO/bootmgfw.efi.mui is not signed
✗ /boot/EFI/Microsoft/Boot/ro-RO/bootmgr.efi.mui is not signed
✗ /boot/EFI/Microsoft/Boot/ru-RU/bootmgfw.efi.mui is not signed
✗ /boot/EFI/Microsoft/Boot/ru-RU/bootmgr.efi.mui is not signed
✗ /boot/EFI/Microsoft/Boot/ru-RU/memtest.efi.mui is not signed
✗ /boot/EFI/Microsoft/Boot/sk-SK/bootmgfw.efi.mui is not signed
✗ /boot/EFI/Microsoft/Boot/sk-SK/bootmgr.efi.mui is not signed
✗ /boot/EFI/Microsoft/Boot/sl-SI/bootmgfw.efi.mui is not signed
✗ /boot/EFI/Microsoft/Boot/sl-SI/bootmgr.efi.mui is not signed
✗ /boot/EFI/Microsoft/Boot/sr-Latn-RS/bootmgfw.efi.mui is not signed
✗ /boot/EFI/Microsoft/Boot/sr-Latn-RS/bootmgr.efi.mui is not signed
✗ /boot/EFI/Microsoft/Boot/sv-SE/bootmgfw.efi.mui is not signed
✗ /boot/EFI/Microsoft/Boot/sv-SE/bootmgr.efi.mui is not signed
✗ /boot/EFI/Microsoft/Boot/sv-SE/memtest.efi.mui is not signed
✗ /boot/EFI/Microsoft/Boot/tr-TR/bootmgfw.efi.mui is not signed
✗ /boot/EFI/Microsoft/Boot/tr-TR/bootmgr.efi.mui is not signed
✗ /boot/EFI/Microsoft/Boot/tr-TR/memtest.efi.mui is not signed
✗ /boot/EFI/Microsoft/Boot/uk-UA/bootmgfw.efi.mui is not signed
✗ /boot/EFI/Microsoft/Boot/uk-UA/bootmgr.efi.mui is not signed
✗ /boot/EFI/Microsoft/Boot/zh-CN/bootmgfw.efi.mui is not signed
✗ /boot/EFI/Microsoft/Boot/zh-CN/bootmgr.efi.mui is not signed
✗ /boot/EFI/Microsoft/Boot/zh-CN/memtest.efi.mui is not signed
✗ /boot/EFI/Microsoft/Boot/zh-TW/bootmgfw.efi.mui is not signed
✗ /boot/EFI/Microsoft/Boot/zh-TW/bootmgr.efi.mui is not signed
✗ /boot/EFI/Microsoft/Boot/zh-TW/memtest.efi.mui is not signed
✗ /boot/EFI/debian/fbx64.efi is not signed
✗ /boot/EFI/debian/grubx64.efi is not signed
✗ /boot/EFI/debian/mmx64.efi is not signed
✗ /boot/EFI/debian/shimx64.efi is not signed
✗ /boot/EFI/ubuntu/grubx64.efi is not signed
✗ /boot/EFI/ubuntu/mmx64.efi is not signed
✗ /boot/EFI/ubuntu/shimx64.efi is not signed
✗ /boot/grub/x86_64-efi/core.efi is not signed
✗ /boot/grub/x86_64-efi/grub.efi is not signed
✗ /boot/vmlinuz-linux is not signed
✗ /boot/vmlinuz-linux-lts is not signed
[donald@donald-Inspiron-3910 ~]$

Last edited by cabaz (Today 00:10:10)

Offline

#3 Today 00:16:57

cabaz
Member
Registered: 2019-03-28
Posts: 3

Re: sbctl database files for secure boot were deleted.

And that did it.  I ran

sudo sbctl verify | sed 's/✗ /sudo sbctl sign -s /e'

again which signed the efi files again.  Then "sbctl list-files" gives all the signed efi binaries.

Marking as solved. smile

Spoke too soon.  Now I can't boot into Windows.

Last edited by cabaz (Today 01:12:51)

Offline

Board footer

Powered by FluxBB