Linux Mint 17.2, 17.3 Secure Boot Issues

Status
Not open for further replies.
Joined
Dec 5, 2009
Messages
28,044
Location
Regina, Saskatchewan, Canada
Guys doing any updating with yesterday's updates, or trying 17.3, be cautious if you have secure boot. I knew something didn't look right, but I let it do it anyway, much to my chagrin. Note:

Upgrade: grub-efi-amd64-bin:amd64 (2.02~beta2-9ubuntu1.4, 2.02~beta2-9ubuntu1.5), grub-efi-amd64:amd64 (2.02~beta2-9ubuntu1.4, 2.02~beta2-9ubuntu1.5), coreutils:amd64 (8.21-1ubuntu5.1, 8.21-1ubuntu5.3), python-apt:amd64 (0.9.3.5ubuntu1, 0.9.3.5ubuntu2), grub-common:amd64 (2.02~beta2-9ubuntu1.4, 2.02~beta2-9ubuntu1.5), grub2-common:amd64 (2.02~beta2-9ubuntu1.4, 2.02~beta2-9ubuntu1.5), ntp:amd64 (4.2.6.p5+dfsg-3ubuntu2.14.04.5, 4.2.6.p5+dfsg-3ubuntu2.14.04.6), python3-apt:amd64 (0.9.3.5ubuntu1, 0.9.3.5ubuntu2), gnome-desktop3-data:amd64 (3.8.4-0ubuntu3.1, 3.8.4-0ubuntu3.2), ntp-doc:amd64 (4.2.6.p5+dfsg-3ubuntu2.14.04.5, 4.2.6.p5+dfsg-3ubuntu2.14.04.6), python-apt-common:amd64 (0.9.3.5ubuntu1, 0.9.3.5ubuntu2), unattended-upgrades:amd64 (0.82.1ubuntu2.3, 0.82.1ubuntu2.4), ntpdate:amd64 (4.2.6.p5+dfsg-3ubuntu2.14.04.5, 4.2.6.p5+dfsg-3ubuntu2.14.04.6)

Remove: grub-efi-amd64-signed:amd64 (1.34.5+2.02~beta2-9ubuntu1.4)


Something is broken with their EFI updates, and perhaps the automatically removed last package had something to do with it. In any event, it wouldn't let me back into Mint until I went into the BIOS and disabled secure boot. Considering this is a step backwards, I'm not impressed. I haven't devised a more robust workaround yet. I don't know if I should file a bug report now or wait until I devise a fix, rather than waiting for them, and file it all at once.

In any case, just letting you guys know. Apparently, this issue has been known with 17.3, and now they decided to foist it upon 17.2 users. I see Linus needs to go on another expletive laden rant to smarten someone up.
 
I wonder if there is something going askew regarding the "signing" given that the package is an Ubuntu package - grub-efi-amd64-signed:amd64 (1.34.5+2.02~beta2-9ubuntu1.4) - and you are not using Ubuntu? Mint has not licensed themselves in this regard so they're going to have to figure out how to be indistinguishable from Ubuntu at boot-time, maybe?

I have also failed as of this writing to see any benefit to using Secure Boot unless you're Microsoft and are trying to prevent anyone from installing a non-Windows OS on a system they purchased.
 
That last package is what caught my eye. I'm wondering, too, if that thing being removed caused the issue. Did Canonical give them a hard time? Did Canonical just yank that package? Did it not play nice with something else? Did someone just screw up that package or one of the other components?

I agree it's not terribly useful for me to be using Secure Boot, even for the nominal reasons it's useful. No one is going to be trying to remotely install a rootkit on my computer. It's also not a public computer where I would worry about someone inept trying something with an unlicensed Live DVD.

My concern with this issue isn't for me, it's for much more casual users, particularly with newer machines where Secure Boot is enabled by default. Mint is used by all kinds of people, including people with a lot of expertise, down to those who just want to check email and read the news. Diagnosing and fixing this problem isn't exactly trivial for them. Sure, I know what a Secure Boot failure looks like and how to go into the BIOS and switch to legacy settings. Lots of people, however, are going to be flummoxed by this.
 
This is from the 17.2 release notes:

Quote:
UEFI is fully supported.

Note: Linux Mint does not use digital signatures and does not register to be certified by Microsoft as being a "secure" OS. As such, it will not boot with SecureBoot. If your system is using secureBoot, turn it off.

Note: Linux Mint places its boot files in /boot/efi/EFI/ubuntu to work around this bug. This does not prevent the installation of multiple releases or distributions, or dual-boots between Ubuntu and Linux Mint, as they can all be bootable from the same grub menu.


That does not sound well for those less experienced users who have systems with Secure Boot on by default!

Canonical, if I recall, *is* certified by Microsoft as secure (I have never typed a more ironic statement before): https://help.ubuntu.com/community/UEFI#SecureBoot
 
Originally Posted By: uc50ic4more
I have also failed as of this writing to see any benefit to using Secure Boot unless you're Microsoft and are trying to prevent anyone from installing a non-Windows OS on a system they purchased.


Did anyone ever imagine there was another reason for 'Secure Boot'?

It exists so Microsoft can control what you do with the PC you buy. It's also why my next laptop will probably be one built for Linux, rather than a Windows cheapie that I wipe and overwrite.
 
Originally Posted By: uc50ic4more
That does not sound well for those less experienced users who have systems with Secure Boot on by default!

And it flies right in the face of my experience with 17.2. The Live DVD and the actual install both work fine with secure boot. So, they must have been riding on Canonical's coattails, and probably inadvertently. Most new systems I would assume would have Secure Boot on by default, and if you want to make your product accessible to the masses, you can't make them fumble around with something like this.

That's the one thing that irks me with Mint - these little kludges. The HP printing setup didn't work as smoothly as it did in my last Ubuntu version. In fairness, that might be the same with the current Ubuntu and an hplip fault. In any case, I had to delete the auto-detected printer and capture it as a USB printer as if it were not detected, and all was fine. Then, some buffoon decided to make the GPG temporary working directory within home a root only folder (this was at least two versions of Mint previous), and the GUI tools don't give squat for an error message. Playing with the command line showed a permission denied error. Yeesh. They have all the multimedia stuff well taken care of, but doing silly things with ownership like that, well, I don't have a lot of patience for that. I filed a bug report and the fix for that, but never checked back and haven't tried with this version.

As for your link, "The PC will reboot and you will be able to enter the BIOS (if not press the necessary key)." What's the necessary key?
wink.gif
Actually, I struggled with that when I first put Mint on here, since HP inexplicably uses ESC. Philosophically, I think that's ideal, but it was certainly not my first choice, and was playing a bunch of key roulette to get where I wanted until I stumbled across it. I think it was my fourth choice. And yes, we must be at end times if Microsoft is allowed to certify anyone or anything as "secure."

emg: I would say that Secure Boot could do well to protect someone from their own foolishness, at least in certain situations. But, making it difficult for someone to use a more secure operating system in the first place is kind of idiotic. Yes, trying to run a compromised USB OS or something silly from a CD or DVD would require a user to jump through a few hoops. But, there are clearly hoops for some to jump through when there shouldn't have been any, such as in my case.
 
Status
Not open for further replies.
Back
Top Bottom