Secure Boot (Limine): sbctl still signs kernels; 11.2.0 note outdated
Nobody has claimed this yet.
Assessment
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Newbie friendliness
- 78/100
- Issue type
- Documentation
- Clarity
- Clearly specified
- Activity status
- Active
- Tech stack
- arch-linux
- Domain
- documentation, operating-systems
Research direction
Start with src/content/docs/configuration/secure_boot_setup.mdx and review the linked sbctl, mkinitcpio, limine-mkinitcpio-hook, and Limine sources. Update the Limine guidance with the kernel-signing note and revise the Limine version caution to reflect 12.0 behavior. Done means both suggested explanations and version references are accurate.
Written by the indexing model from the issue text.
Description
1. Kernels still get signed, although the page says it isn't necessary
The page correctly says signing kernels "isn't necessary on Limine", because Limine checks them by BLAKE2B hash. But once sbctl is set up, the kernel gets signed anyway: every time mkinitcpio generates an initramfs, sbctl's post hook (/usr/lib/initcpio/post/sbctl) signs the kernel in place (/usr/lib/modules/<version>/vmlinuz), and limine-mkinitcpio-hook then copies that signed kernel to the ESP:
$ sudo sbverify --cert /var/lib/sbctl/keys/db/db.pem /boot/<machine-id>/linux-cachyos/vmlinuz
Signature verification OK
The kernel is built with the EFI stub, so the firmware can start it directly; because it carries a db signature, Secure Boot should accept it, bypassing Limine's config checksum and hash checks.
Suggested note for the Limine tab:
sbctl's mkinitcpio post hook signs every kernel, even though Limine doesn't need it. To keep kernels unsigned:
- Create a non-executable file
/etc/initcpio/post/sbctl. mkinitcpio runs each hook name once,/etcfirst, and skips non-executable files.- Reinstall the kernel package to replace the already-signed copy.
Only do this in the default (non-UKI) mode. UKIs are chainloaded (
protocol: efi), which relies on the firmware checking their signature, and limine-mkinitcpio-hook leaves UKI signing to this hook.
2. The "Limine >= 11.2.0" caution describes behaviour only 11.2.0 had
The caution says Limine panics with SECURE BOOT IS ACTIVE BUT NO CONFIG CHECKSUM IS ENROLLED when no checksum is enrolled. Limine's ChangeLog shows this changed:
11.2.0: enforcement introduced, 11.2.1: enforcement reverted, 12.0.0: enforcement re-introduced as opt-in.
Since 12.0.0, without an enrolled checksum, "Limine treats Secure Boot as inactive" (USAGE.md). In that case the config isn't verified, file hashes aren't required, and the editor isn't force-disabled (init_config in common/lib/config.c). A signed but unenrolled binary still boots under Secure Boot, just without these protections.
Suggested wording for the caution:
Always enroll the config checksum (
limine-enroll-config). Since Limine 12.0, an unenrolled binary doesn't panic; it silently runs as if Secure Boot were off.
Versions checked: Limine 12.9.0, limine-mkinitcpio-hook 1.39.0, mkinitcpio 42, sbctl 0.18.
[!NOTE]
AI disclosure: I researched and drafted this with an AI assistant (Claude). I reviewed it, and every claim is checked against the linked sources. What I ran on my own machine: the sbverify result, the signed kernel on the ESP being identical to the one in /usr/lib/modules, and the package versions listed. What I did not test on hardware: the firmware starting a signed kernel directly, booting an unenrolled Limine binary, and the /etc/initcpio/post/sbctl override. Those statements come from reading the source code and documentation.
- Dominant language
- MDX
- Stars
- 152
- Forks
- 236
- Avg merge
- 18h 42m
- Merged PRs (30d)
- 3
Getting set up
This project ships no dev container, Dockerfile or contributing guide, so setting up is up to you: start from its README, and see our first-contribution guide for the general steps.
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from CachyOS/wiki
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
-
EGL HeadlessOpen
Difficulty 1/5 Under an hour Newbie friendliness 82/100
-
Difficulty 2/5 Half a day Newbie friendliness 74/100
-
Difficulty 1/5 1-3 hours Newbie friendliness 88/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
Similar issues
-
sync-en
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
Maintainers usually reply within 1 day
-
community-request
Difficulty 1/5 Under an hour Newbie friendliness 95/100
NVIDIA-NeMo/Curator#2464 · 1 comment ·
Maintainers usually reply within 1 day
-
good first issue hacktoberfest
Difficulty 2/5 1-3 hours Newbie friendliness 87/100
elnachto/laya-triage#5 ·
-
Difficulty 1/5 Under an hour Newbie friendliness 88/100
Maintainers usually reply within 1 day
-
external
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
langchain-ai/docs#6328 · 1 comment ·
Maintainers usually reply within 1 day