Update to this post. Please read it before commenting!

So I ended up following instructions I found online and disabled secure boot in my BIOS and then tried to boot Linux Mint (version 21.2, Cinnamon Edition) with UEFI OS. However, as soon as I did that, i got a “Perform MOK management” screen that said the following:

Continue boot Enroll MOK Enroll key from disk Enroll hash from disk

Can anyone tell me what this means and what I should do? Do keep in mind I’m a total newbie when it comes to Linux. Thanks in advance!

  • Leaflet
    link
    English
    82 months ago

    For Secure Boot, the kernel is “signed” with a key. During boot up, Secure Boot checks to make sure that key is valid. Most kernels are signed with Microsoft’s key that is preloaded on basically every system. However, not all kernels can be signed with Microsoft’s key; if you install a proprietary driver (which you likely selected to during the setup), to continue using secure boot you need to sign the kernel using your own key.

    That’s what MOK management is for. You are adding your own key to your system to use for Secure Boot.

    Personally, I just disable Secure Boot. While it does have some security benefits, it’s not worth the headache IMO.

      • Leaflet
        link
        English
        22 months ago

        You can still do MOK management when Secure Boot is off.

        • @[email protected]OP
          link
          fedilink
          12 months ago

          Thank you for your response! So I can select Continue boot, install Mint and then reenable Secure Boot after I’m done installing?

          • Leaflet
            link
            English
            12 months ago

            If you continue without adding the keys, you may have issues if you rely on out of tree drivers like Nvidia. Personally, I would hit continue then leave secure boot off.