diff options
| author | Craig Jennings <c@cjennings.net> | 2026-09-13 07:00:06 -0500 |
|---|---|---|
| committer | Craig Jennings <c@cjennings.net> | 2026-09-13 07:00:06 -0500 |
| commit | 3bab9f1ff287c61e85504ad5ab0c5a0d69bf0a61 (patch) | |
| tree | 51ce3214db7164ff309b8e3bfad6ab56600153e4 /scripts/test-configs/zfs-mirror-encrypt.conf | |
| parent | 6ed8697ae38e30bd7990553d26ea6bb4ef4d3e46 (diff) | |
| download | archangel-3bab9f1ff287c61e85504ad5ab0c5a0d69bf0a61.tar.gz archangel-3bab9f1ff287c61e85504ad5ab0c5a0d69bf0a61.zip | |
docs: check Secure Boot before blaming a lost EFI boot entry
A firmware update can re-enable Secure Boot without clearing NVRAM. The firmware then rejects the unsigned ZFSBootMenu or GRUB loader as "no bootable drive" rather than a security violation, which looks like a missing boot entry. A Framework BIOS update did this to an installed machine this week. I put a check-Secure-Boot-first bullet at the top of the troubleshooting section, with shim's MOK screen on the Ventoy stick as the tell and the firmware fix.
Diffstat (limited to 'scripts/test-configs/zfs-mirror-encrypt.conf')
0 files changed, 0 insertions, 0 deletions
