r/archlinux • • 4h ago

QUESTION Secure boot and Arch?

The Arch installation guide mentions disabling Secure Boot. I recently learnt that Secure Boot can work with Arch.

My questions are: does this make sense?

Should I keep it enabled after all (is it risky if not)?

Is there a risk that, following an update, Secure Boot will reject my kernel or boot loader?

Did you enable SB?

7 Upvotes

20 comments sorted by

8

u/Illustrious-Gur8335 4h ago

does this make sense?

Perfectly makes sense, the Arch install ISO does not support secureboot that is why install guide asked you to disable it first then reenable it once system reboots.

Should I keep it enabled after all (is it risky if not)?

Certain games and Windows with Bitlocker - if you dual-boot - will require secure boot.

Is there a risk that, following an update, Secure Boot will reject my kernel or boot loader?

Nope, at most the certificate signing your kernel and bootloader expires, and you sign them again.

Did you enable SB?

Yes, lazy to deviate from my BIOS "optimised settings".

3

u/Exotic-Screen-9204 4h ago edited 2h ago

Linux is able to be installed with or without an active Secure Boot.

But having an active Secure Boot requires additional installation details be properly managed.

Often, the easiest first installation is done with Secure Boot turned off. BIOS/UEFI firmware menu interface varies from brand to brand. Some make a Linux UEFI Secure Boot easy, others can be confusing. HP and Dell seem to me to be easier.

3

u/kansetsupanikku 4h ago

The sane order of things is to disable it, install, set up the requirements, and enable it when ready. I would consider it worth it.

3

u/WildCard65 3h ago

If you do secureboot and go the route of setting up your own keys, make sure to install the Microsoft keys also.

My graphics card required the Microsoft keys.

•

u/noobjaish 34m ago

Why both?

2

u/AppointmentNearby161 4h ago

The installer ISO does not work with secureboot since it does not use the shim signed by Microsoft. You can enable secureboot after you install the base system. As to whether you should, that depends on your threat model. Assuming you don't have a buggy bios, if secureboot rejects your bootloader after an update, you just disable it and reboot.

2

u/circuskid 3h ago

Arch is fine with secureboot. I've been running Limine with secure boot with sbctl without issues for.. awhile.

  • Updates won't brick. sbctl installs a pacman hook that re-signs on every update. Don't even have to think about it.
  • Cert expiration doesn't really apply. UEFI firmware doesn't usually check expiry dates and your own keys are good for years. The MS CA rollover affects the shim and MS signed stuff, not your own keys.
  • Enroll the MS keys along with yours - This keeps GPU option ROMs, and Windows if you dual boot, happy.
  • Enrolling keys goes through setup mode which wipes the dbx, sbctl doesn't put it back. Or at least didn't for me.
  • Just disable SB if it breaks" isn't always an escape hatch. On Limine with config verification turned on, a bad config hash fails whether SB is on or off. Keep a backup of your config.

1

u/dthrdr 2h ago

Arch is the only distro where the installer needs it disabled that I’m aware of. Easy enough to disable it but also easy enough for Arch to fix it. 

1

u/Illustrious-Gur8335 2h ago

Huh. Only debian and Fedora installers support secure boot using their own signed shims

1

u/das_menschy 1h ago

You forgot Ubuntu. And LinuxMint uses the one from Ubuntu. 

3

u/dthrdr 1h ago

And forgot, Rocky/Alma, Alpine and so on. Like I said Arch is one of the few “big” distros not supporting it on the installer iso.

•

u/agowa338 34m ago

Tl;Dr:

Yes it does make sense.

No it's not a beginner thing to do. On Arch you'll have to setup all of the signing keys and the hooks to sign any new kernel after pacman installed an update manually. It isn't a turnkey solution there as it is e.g. on Bazzite.

Yes it does work on Arch.

Yes I've had it fully configured back then when I still used arch.

It avoids tampering with your bootloader and kernel. Esp. relevant when you want to avoid evil maid attacks by your friends trying to troll you...

•

u/Appropriate_Town3242 3m ago

I mean this is ignoring the existence of sbctl which does turn it into a very beginner friendly option, sbctl works great for like 99% of use cases I find.

•

u/agowa338 0m ago

I still wouldn't hand a beginner sbctl.

Except they're familiar with Linux and are "just" an ArchLinux beginner.

1

u/ModernUS3R 4h ago edited 4h ago

You can set it up better if you use systemdboot and UKI. I used this guide here to configure all my machines. Following setup, every time the systemd or kernel updates it will re-sign itself after the mkinitcpio process. I have dual boot and both windows and arch load properly.

One thing I noticed with a dell laptop is that some of the extra bios utility won't load. I believe this is because setup mode cleared keys related to those but the main bios and everything else is fine.

0

u/WoodyXP 4h ago

I use secure boot. It protects against bootkits, bootloader/kernal tampering and a host of other things. You can screw up your computer if you don't configure it properly, so make sure you follow the instructions should you choose to set it up.

2

u/Moist_Professional64 4h ago

You don’t screw anything up. If secrue boot fails just disable it and reset it in uefi

-1

u/HopefulMeeting7150 4h ago

I wonder if sync and update packages may block my arch (generally updating kernal, bootloader etc)...?

Have yoy ever had it?

2

u/SuikaNek0 1h ago

like he said, if u WOULD brick anything you can just disable secure boot and fix it, that said sbctl for example which is used for secure boot has pacman hook which resigns kernel every update so generally u don’t have to worry about it