https://bugzilla.suse.com/show_bug.cgi?id=1185441 https://bugzilla.suse.com/show_bug.cgi?id=1185441#c20
--- Comment #20 from Gary Ching-Pang Lin glin@suse.com --- (In reply to Michiel Janssens from comment #19)
Hi, since upgrading to shim 15.4 I had the same issue with Secureboot enabled in BIOS on Tumbleweed, so with message "system is compromised". To be able to boot I disabled Secureboot in BIOS. Today I upgraded TW to snapshot 20210520, with shim-15.4-3.1.x86_64, still the same issue when enabling Secureboot in BIOS, so disabled it again.
So I followed some of the steps in this report, didn't downgrade shim package.
- mokutil --enable-validation (not disable)
- reboot
- Press Down and Enter in shim menu to *Change secure boot state*
- Enter three password characters.
- Press y and Enter
- Press any key to reboot system (reboot)
- system boots, Secureboot still disabled in BIOS.
- Boot to Bios and enabled Secureboot again
- System boots, without error
mokutil --sb-state gives SecureBoot enabled, so I guess it's fixed.
Thanks for verifying MokSBState and provide the workaround!