Repository navigation
Replies: 4 comments 2 replies
|
For those interested, I've automated the (re)signing process: https://github.com/ykzird/ykzird-secure-boot |
|
I found this at an insanely good time, thank you very much, I can confirm it works with the following setup (including the automation): Since MSI in general has an apparently very interesting implementation for Secure Boot, I also had to do the following (from another Linux install I had before this one, but it still applies):
|
|
Thank you for the complete manual! I did it step by step and at the end when enabling the secure boot when I select omarchy in the limine... the computer restarts. |
|
I couldn't get it to successfully boot from a USB4 external SSD attached to a Gen12 Lenovo Carbon X1. Figured it out with the help of Claude and had it write a summary, but it's pretty long and I didn't want to dump it in here without asking if this is OK? In brief, the fix is a small custom mkinitcpio hook (thunderbolt-auth) that actively polls /sys/bus/thunderbolt/devices/*/authorized, writes 1 to anything unauthorized, and waits for the tunnel and NVMe probe to complete, inserted immediately before block in the HOOKS array, since appending it runs it after the hooks that needed the disk have already given up. |
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Omarchy Secure Boot + Dual Boot — Definitive Community Guide
This guide was written after a full hands-on troubleshooting session getting Secure Boot working on Omarchy with Limine 11.2.0. It supersedes Discussion #2296 and incorporates all hard-won lessons. If something in an older guide contradicts this one, trust this one. But as always, your mileage may vary. I honestly do NOT recommend this, as it's not worth the headache; even if you automate the maintenance part of this, it would still be better to have two separate systems for both Linux and Omarchy. Sadly that's not always possible, so I decided to use #2296 as a reference and spin up Claude to see if I could get it working and document as much as I can. Hopefully this will help those wanting to run this!
What This Guide Achieves
Critical Things to Understand Before You Start
These are the lessons that took hours to learn; read them first:
Only sign the Limine EFI binary. Do NOT sign kernels, initramfs, or any other EFI files. Limine verifies those via its own BLAKE2B hash mechanism embedded in
limine.conf. Signing them externally corrupts that verification and causes silent blank screen boot failures.Do NOT run the signing one-liner from Discussion Omarchy Dual-Boot Secure Boot Setup (Custom Keys Guide) #2296. The command
sudo sbctl verify | sed -nE 's|^✗ (/.+) is not signed$|sbctl sign -s "\1"|p' | sudo shwill sign files Limine needs to verify itself. This breaks booting.The config checksum must be enrolled BEFORE signing. Running
limine enroll-configmodifies the binary; any signature applied before this step becomes invalid./boot/EFI/BOOT/BOOTX64.EFIis the fallback loader, not Limine. The actual Limine binary is at/boot/EFI/limine/limine_x64.efi.sbctl remove-filedoes not strip the physical signature from the binary. It only removes it from sbctl's database. Usebsdtarto extract a clean binary from the package cache instead.Limine 11.2.0 enforces config checksum strictly. If the checksum is not enrolled, Limine panics with
SECURE BOOT IS ACTIVE BUT NO CONFIG CHECKSUM IS ENROLLEDregardless of whether your EFI files are signed correctly.hash_mismatch_panic: nohides errors. Set it toyesduring troubleshooting so you get visible panic messages instead of silent blank screens.Plymouth (
splash) breaks booting with Secure Boot enabled. Removesplashfrom your kernel cmdline before enabling Secure Boot.Additional notes:
Prerequisites
Required tools (will be installed during setup)
sbctl— Secure Boot key managementpesign— PE signature inspectionbsdtar— package extraction (usually pre-installed)Phase 1 — Preparation
Step 1: Disable Secure Boot in BIOS
Boot into BIOS (usually F2, F12, or Delete on startup). Disable Secure Boot if not already disabled. Save and exit.
Step 2: Install required tools
Step 3: Configure dual-boot (if not already done)
Step 4: Remove
splashfrom kernel cmdlineThis is essential. Plymouth's graphical splash screen fails silently under Secure Boot, causing a blank screen.
Edit the Limine config:
Find the line:
Change it to:
Save and rebuild the UKI:
Step 5: Comment out the EFI fallback entry in limine.conf
Chainloading an unsigned EFI binary will cause a panic with Secure Boot active.
Find the section at the bottom and comment it out:
Step 6: Enable hash mismatch panics for troubleshooting
In
/boot/limine.conf, ensure this is set:This gives you visible error messages instead of silent blank screens if anything goes wrong.
Phase 2 — Secure Boot Key Management
Step 7: Clear existing Secure Boot keys in BIOS
Reboot into BIOS and navigate to Secure Boot settings. Clear all existing keys. Look for "Delete all Secure Boot Variables", "Reset to Setup Mode", or similar. Set Secure Boot Mode to Custom. Do not re-enable Secure Boot yet. Save and exit, boot back into Omarchy.
Step 8: Verify Setup Mode
Should show:
An ✗ next to Setup Mode is normal; don't worry about it.
Step 9: Create custom keys
Step 10: Enroll keys
The
-mflag includes Microsoft's keys, which is essential for Windows to keep booting. Either of these output formats is fine; proceed regardless:Step 11: Verify key enrollment
If Setup Mode still shows Enabled after this step, don't panic; several users reported this and still ended up with working Secure Boot after completing all steps.
Phase 3 — Update Kernel Hash in limine.conf
Since you rebuilt the UKI in Step 4, the hash in
limine.confis now stale and must be updated.Step 12: Generate new kernel EFI hash
Copy only the hash string; not the filename that
b2sumappends.Step 13: Update limine.conf
Find the main Linux entry path line. It will look like:
Replace the hash after
#with the new one from Step 12. Leave everything else untouched.Phase 4 — Enroll Config Checksum and Sign Limine
This is the most critical phase. The order of operations is strict; do not deviate.
Step 14: Extract a clean Limine binary from package cache
This ensures no stale signatures interfere with the process.
Verify it is clean (should return nothing):
Step 15: Generate config checksum
Copy only the hash string; not the filename.
Step 16: Enroll checksum into the Limine binary
This embeds the checksum into the binary. The binary is now modified.
Step 17: Sign the Limine binary
The
-sflag saves it to sbctl's database for tracking.Step 18: Verify
pesign -Sshould show "Database Key" (your custom key).sbctl verifyshould show ✓ forlimine_x64.efi. All other files showing ✗ is expected and correct; do not sign them.Phase 5 — Enable Secure Boot
Step 19: Reboot into BIOS
In BIOS:
Step 20: Fix boot order if needed
If you land in an emergency shell, go back into BIOS and set the boot order to:
Step 21: Verify Secure Boot is active
Expected output:
In Windows: Start →
msinfo32→ confirmSecure Boot State: On.Ongoing Maintenance
After any change to limine.conf or kernel updates
The config checksum and Limine signature must be refreshed every time
limine.confchanges (including after kernel updates which update the kernel hash in the config automatically).Full re-sign sequence:
Editing Limine boot entries
Edit
/boot/limine.confdirectly. Each entry is a self-contained block; delete the block to remove an entry. Remember to run the full re-sign sequence above after any edit.BitLocker
If Windows prompts for a BitLocker recovery key after enabling Secure Boot, this is normal; the TPM PCR values shifted when you enrolled custom keys. Enter the recovery key once and it will re-seal to the new state. Subsequent boots will not prompt again.
Troubleshooting
"SECURE BOOT IS ACTIVE BUT NO CONFIG CHECKSUM IS ENROLLED"
The config checksum was not enrolled into the Limine binary, or was enrolled into the wrong binary. Ensure you are targeting
/boot/EFI/limine/limine_x64.efiand not/boot/EFI/BOOT/BOOTX64.EFI(that is the fallback loader, not Limine).Blank screen after selecting Linux in Limine
Two possible causes:
hash_mismatch_panic: yesinlimine.confto get a visible error, then re-enroll the config and re-sign.splashfromKERNEL_CMDLINEin/etc/default/limineand rebuild withsudo limine-mkinitcpio."incorrect digest" error when signing
The binary has a stale physical signature embedded. Extract a clean binary from the package cache:
Then proceed with enroll-config and sign.
pesign shows certificate after extracting from package cache
The binary is not clean. Try removing any embedded PE signature:
"File doesn't exist in database" from sbctl remove-file
The file was never tracked by sbctl. Skip
remove-fileand proceed directly tolimine enroll-configandsbctl sign -s.Windows no longer boots
Ensure you used the
-mflag when enrolling keys (sbctl enroll-keys -m). Without it, Microsoft's keys are not included and Windows Boot Manager will be rejected by the firmware.BitLocker recovery key prompt on every Windows boot
Disable BitLocker on the Windows partition, or enter the recovery key once; it should re-seal after that and not prompt again.
Emergency shell on boot
Check your BIOS boot order. Limine must be first. Go to BIOS and set:
Setup Mode still shows Enabled after key enrollment
This is cosmetic on some firmware implementations. Continue with the guide; Secure Boot will still work correctly after reboot.
"Corrupted file detected" for snapshot kernel EFIs
Limine's BLAKE2B hash for a snapshot kernel EFI no longer matches. Regenerate the hash for that specific file and update its path entry in
limine.conf:Then update the hash after
#in the correspondinglimine.confpath entry, and run the full re-sign sequence.MSI Specific (as per #5306 (comment))
When you reset to setup mode, the keys get reset, but, if you do not disable the setting "Factory Key Provisioni" beforehand, it will automatically add the factory keys (i.e. Microsoft, ...) back on reboot (which disables setup mode again before you are booted into Linux, yes :))
Reference: Correct Signing Order
Always follow this exact order. Deviating causes "incorrect digest" errors:
Useful Commands
Wishlist:
Guide version: 1.1 — April 2026
Tested on: Omarchy with Limine 11.2.0, ASRock X870 PRO RS
Based on: Discussion #2296 + extensive hands-on troubleshooting
Author: @ykzird
All reactions