Secure boot Auto enable

Today I got a weird situation.

Yesterday evening I attempted to do the system update, but 5 min in I have changed my mind, cancel the update terminal and wend out.

Today in the morning I booted in to:
Secure boot fail error.

The fix was to disable Secure boot in the Bios.

I can’t remember ever enable Secure Boot

Can someone maybe explain what might have happened?

Depending at which point you interrupted the update, the potential for system damage remains. In these cases we might usually refer you to a tutorial such as this one:


You are no doubt aware that Manjaro does not support Microsoft’s implementation of Secure Boot, and disabling it is the best resolve.

As to your error, my best guess is: :man_shrugging:

Manjaro has no capability of enabling or disabling Secure Boot; some Windows versions apparently do.

If you’re multi-booting, I might give Windows (11?) the evil eye. Otherwise, cosmic rays, maybe?!

Regards.


1 Like

Nope.

For security reasons - enabling or disabling secure boot - must be done by a human.

While it is possible to utilise Secure Boot with Manjaro LInux - for the aforementioned reason - it will never be an automated task.

[root tip] [How To] Manjaro and Windows - Secure Boot - using repo only

1 Like

Maybe Secure Boot is enabled by default in the factory-default UEFI settings and your CMOS battery died or shorted out, causing the UEFI to resort to factory-default settings. :man_shrugging:

Another possibility is that you are dual-booting with Microsoft Windows and that you have (knowingly or unknowingly) applied a Windows update in the meantime, causing Secure Boot to become enabled.

Without any proper information regarding your system, our guess is only as good as yours. :man_shrugging:

1 Like

Possibly a BIOS/UEFI update…?

From some research done today - it appears that changing the firmware’s secure boot status can be done from CLI given the vendor supports it and certain conditions exist - at least on Windows it can be done.

I need to research more - if it turns out to be valid - it could provide a path to enable Secure Boot at Calamares installation level - but again only for a subset of systems.

2 Likes

Well thank you everyone for does information.

Shorted out, that could pretty much be it. I have just testing resetting the BIOS settings to default, and that is enable Secure Boot by default.
I’m just glad the Supervisor Password setting is not also just got resetting…

But also hwclock seems fine:

sudo hwclock -r
2025-03-27 12:43:25.574960+01:00
cat /proc/driver/rtc | grep batt
batt_status     : okay

Yes, I still have the Original Windows for nostalgic reason, but at day one I tested if it works then reduce it to 86 GB and have never touched it since.

lsblk
❯ lsblk -o NAME,MAJ:MIN,FSTYPE,LABEL,SIZE,MOUNTPOINT

NAME                       MAJ:MIN FSTYPE      LABEL      SIZE MOUNTPOINT
nvme1n1                    259:0                          1.8T 
├─nvme1n1p1                259:1   vfat                   280M /boot/efi
├─nvme1n1p2                259:2   crypto_LUKS            1.3T 
│ └─luks-2bdc0baf-74dd-45e0-b603-74c8191f9a64
│                          254:0   ext4                   1.3T /
└─nvme1n1p3                259:3   ext4        backup   502.9G /media/backup
nvme0n1                    259:4                        953.9G 
├─nvme0n1p3                259:5   ntfs        Acer      86.8G 
├─nvme0n1p4                259:6   ntfs        Recovery     1G 
└─nvme0n1p5                259:7   crypto_LUKS          865.5G 

inxi info
System:
  Kernel: 6.12.19-1-MANJARO arch: x86_64 bits: 64
  Desktop: Xfce v: 4.20.1 Distro: Manjaro Linux
Machine:
  Type: Laptop System: Acer product: Nitro ANV15-51 v: V1.08
    serial: <superuser required>
  Mobo: RPL model: Sportage_RTH v: V1.08 serial: <superuser required>
    UEFI: INSYDE v: 1.08 date: 10/31/2023
Battery:
  ID-1: BAT1 charge: 50.2 Wh (100.0%) condition: 50.2/58.8 Wh (85.4%)
CPU:
  Info: 10-core (6-mt/4-st) model: 13th Gen Intel Core i7-13620H bits: 64
    type: MST AMCP cache: L2: 9.5 MiB
  Speed (MHz): avg: 3119 min/max: 400/4700:4900:3600 cores: 1: 3119 2: 3119
    3: 3119 4: 3119 5: 3119 6: 3119 7: 3119 8: 3119 9: 3119 10: 3119 11: 3119
    12: 3119 13: 3119 14: 3119 15: 3119 16: 3119
Graphics:
  Device-1: Intel Raptor Lake-P [UHD Graphics] driver: i915 v: kernel
  Device-2: NVIDIA AD107M [GeForce RTX 4050 Max-Q / Mobile] driver: nvidia
    v: 550.144.03
  Device-3: Quanta ACER HD User Facing driver: uvcvideo type: USB
  Display: x11 server: X.org v: 1.21.1.16 with: Xwayland v: 24.1.6 driver: X:
    loaded: modesetting,nvidia unloaded: nouveau dri: iris gpu: i915 resolution:
    1: 1920x1080~60Hz 2: 1920x1080~60Hz 3: 1920x1080~144Hz
  API: EGL v: 1.5 drivers: kms_swrast,nvidia
    platforms: gbm,x11,surfaceless,device
  API: OpenGL v: 4.6.0 compat-v: 4.5 vendor: nvidia v: 550.144.03
    renderer: NVIDIA GeForce RTX 4050 Laptop GPU/PCIe/SSE2
  API: Vulkan v: 1.4.304 drivers: N/A surfaces: xcb,xlib
  Info: Tools: api: eglinfo, glxinfo, vulkaninfo de: xfce4-display-settings
    gpu: nvidia-settings,nvidia-smi x11: xprop,xrandr
Audio:
  Device-1: Intel Raptor Lake-P/U/H cAVS driver: sof-audio-pci-intel-tgl
  Device-2: NVIDIA AD107 High Definition Audio driver: snd_hda_intel
  Device-3: HP USB Audio driver: hid-generic,snd-usb-audio,usbhid type: USB
  API: ALSA v: k6.12.19-1-MANJARO status: kernel-api
  Server-1: PipeWire v: 1.4.1 status: active
Network:
  Device-1: Intel Raptor Lake PCH CNVi WiFi driver: iwlwifi
  IF: wlp0s20f3 state: up mac: <filter>
  Device-2: Realtek RTL8111/8168/8211/8411 PCI Express Gigabit Ethernet
    driver: r8169
  IF: enp62s0 state: down mac: <filter>
  Device-3: Realtek RTL8153 Gigabit Ethernet Adapter driver: r8152 type: USB
  IF: enp0s13f0u1u4 state: down mac: <filter>
  IF-ID-1: docker0 state: down mac: <filter>
  IF-ID-2: virbr1 state: down mac: <filter>
Bluetooth:
  Device-1: Intel AX201 Bluetooth driver: btusb type: USB
  Report: btmgmt ID: hci0 state: up address: <filter> bt-v: 5.2
RAID:
  Hardware-1: Intel Volume Management Device NVMe RAID Controller Intel
    driver: vmd
Drives:
  Local Storage: total: 2.75 TiB used: 693.77 GiB (24.6%)
  ID-1: /dev/nvme0n1 vendor: Western Digital model: WD PC SN740
    SDDQNQD-1T00-1014 size: 953.87 GiB
  ID-2: /dev/nvme1n1 vendor: Samsung model: SSD 970 EVO Plus 2TB
    size: 1.82 TiB
Partition:
  ID-1: / size: 1.31 TiB used: 594.67 GiB (44.5%) fs: ext4 dev: /dev/dm-0
  ID-2: /boot/efi size: 279.4 MiB used: 448 KiB (0.2%) fs: vfat
    dev: /dev/nvme1n1p1
Swap:
  ID-1: swap-1 type: file size: 43.4 GiB used: 0 KiB (0.0%) file: /swapfile
Sensors:
  System Temperatures: cpu: 44.8 C mobo: N/A
  Fan Speeds (rpm): N/A
Info:
  Memory: total: 32 GiB note: est. available: 31.05 GiB used: 11.41 GiB (36.7%)
  Processes: 483 Uptime: 13m Shell: Zsh inxi: 3.3.37