Stream9 Bad Shim Signature

I updated to 5.14.0-176.e19.x86_64 Stream 9 from I updated to 5.14.0-168.e19.x86_64 Stream 9. On load I get the error(s):

error: …/…/grub-core/kern/efi/sb.c:183:bad shim signature
error: …/…/grub-core/loader/i386/efi/linux.c:259:you need to load the kernal first

I can still boot into 5.14.0-168.e19.x86_64 Stream 9 without disabling secure boot. I do not want to disable secure boot. What has changed to affect this and/or is there a fix for this?

I too am having the same issue. Update downloaded both 176 and 171. Neither will boot. Had to regress to 163.

Is there any resolution to this? I ma having the same issue with a VM.

The last kernel I can boot is 168.

https://bugzilla.redhat.com/show_bug.cgi?id=2138019

From the bug report, this looks to be resolved as of kernel-5.14.0-183.el9, which I can see published in the repos already.

I installed kernel-5.14.0-183.el9 and now it hangs on startup - I get the “circle of death.” Essentially before the login screen it just hangs ‘forever’ – at least it is a slight improvement, but without any error messages I cannot debug or share more info than this.

I updated to kernel-5.14.0-191.el9 and it hangs on startup — same as above.

Hi Brian, I assume that you have LVM configured. I had the same problem.

Try to delete (its safe to delete or put it aside) following file and boot again with the newer kernel.

/etc/lvm/devices/system.devices

The cause seems to be a regression / updated code that handle that content …

1 Like

Leon,

Your solution did indeed work. I deleted /etc/lvm/devices/system.devices using 168 and then successfully booted into 191.

Thanks!!!

This solution did not work for me. However, I did get further with kernel 202. See boot log below:

Thanks, Roy

[ OK ] Finished Create Static Device Nodes in /dev.
Starting Rule-based Manager for Device Events and Files…
[ OK ] Started Rule-based Manager for Device Events and Files.
Starting Load Kernel Module configfs…
Starting Load Kernel Module fuse…
[ OK ] Finished Load Kernel Module configfs.
[ OK ] Finished Load Kernel Module fuse.
[ OK ] Finished Coldplug All udev Devices.
Starting Wait for udev To Complete Device Initialization…
[ OK ] Created slice Slice /system/systemd-backlight.
Starting Load/Save Screen Backlight Brightness of backlight:intel_backlight…
[ OK ] Finished Load/Save Screen Backlight Brightness of backlight:intel_backlight.
[ OK ] Reached target Smart Card.
[ OK ] Listening on Load/Save RF Kill Switch Status /dev/rfkill Watch.
Starting Load/Save RF Kill Switch Status…
Starting Load/Save Screen Backlight Brightness of leds:dell::kbd_backlight…
[ OK ] Finished Load/Save Screen Backlight Brightness of leds:dell::kbd_backlight.
[ OK ] Started Load/Save RF Kill Switch Status.
[ OK ] Finished Wait for udev To Complete Device Initialization.
[ OK ] Reached target Preparation for Local File Systems.
Mounting /boot…
Starting File System Check on /dev/disk/by-uuid/9A69-CC42…
[ OK ] Finished File System Check on /dev/disk/by-uuid/9A69-CC42.
[ OK ] Mounted /boot.
Mounting /boot/efi…
[ OK ] Mounted /boot/efi.

[DEPEND] Dependency failed for /home.
[DEPEND] Dependency failed for Local File Systems.
[DEPEND] Dependency failed for Mark the need to relabel after reboot.
[ OK ] Stopped Forward Password Requests to Wall Directory Watch.
[ OK ] Reached target Timer Units.
[ OK ] Reached target Sound Card.
[ OK ] Reached target Bluetooth Support.
[ OK ] Reached target Preparation for Network.
[ OK ] Reached target Network.
[ OK ] Reached target Network is Online.
[ OK ] Reached target Preparation for Remote File Systems.
[ OK ] Reached target Remote File Systems.
[ OK ] Reached target User and Group Name Lookups.
[ OK ] Reached target Path Units.
[ OK ] Reached target Socket Units.
[ OK ] Started Emergency Shell.
[ OK ] Reached target Emergency Mode.
Starting Crash recovery kernel arming…
Starting Tell Plymouth To Write Out Runtime Data…
Starting Create Volatile Files and Directories…
[ OK ] Finished Tell Plymouth To Write Out Runtime Data.
[ OK ] Finished Create Volatile Files and Directories.
Starting Security Auditing Service…
[ OK ] Started Security Auditing Service.
Starting Record System Boot/Shutdown in UTMP…
[ OK ] Finished Record System Boot/Shutdown in UTMP.
Starting Record Runlevel Change in UTMP…
[ OK ] Finished Record Runlevel Change in UTMP.
[ OK ] Finished Crash recovery kernel arming.