devsetup1-4 Exercise 2: DKMS, Secure Boot and the Machine Owner Key ===================================================================== WHY DEBIAN CANNOT SIGN A DKMS MODULE ------------------------------------ With Secure Boot on, the firmware only lets code run if it carries a signature from a key it trusts. Debian signs its own kernel and its own prebuilt modules with Debian's key. A DKMS module is different: DKMS takes the driver's SOURCE and compiles it on YOUR machine, against YOUR kernel. The resulting file did not exist when Debian built and signed its packages, so Debian has nothing to sign. Without a signature the firmware refuses to load it. WHAT A MACHINE OWNER KEY (MOK) IS --------------------------------- A key pair belonging to the owner of this machine: - The private key (/var/lib/dkms/mok.key) stays on the machine and is used by DKMS to sign each module it builds. - The public key (/var/lib/dkms/mok.pub) is what you ask the firmware to trust. DKMS generates the pair automatically the first time it builds a module. Once the public key is enrolled, every module DKMS signs with the private key is accepted, including rebuilds after kernel updates, so you only enrol once. WHY ENROLMENT NEEDS YOU AT THE KEYBOARD --------------------------------------- Enrolling a key changes what the machine trusts, so it must not be possible for software running inside Debian to do it silently. The request is queued with "mokutil --import", but the change can only be confirmed by a person at the console during boot, in the firmware's MOK Manager screen, using the one-time password you set. Malware running in Debian cannot reach that screen, so it cannot approve its own key. RECOVERY IF YOU SKIPPED THE BLUE SCREEN --------------------------------------- Symptom: the NVIDIA module will not load; the desktop may run without acceleration or show a black screen. 1. If the desktop is black, switch to a text console: Ctrl+Alt+F3, and log in. 2. Confirm the key is not enrolled: sudo mokutil --list-enrolled and check whether an import is still pending: sudo mokutil --list-new 3. Queue the key again (you will be asked for a one-time password): sudo mokutil --import /var/lib/dkms/mok.pub 4. Reboot: sudo reboot 5. When the blue MOK Manager screen appears, follow its instructions and enter the one-time password to enrol the key. Do not let it time out. 6. After the desktop starts, verify: sudo mokutil --list-enrolled dkms status nvidia-smi FALLBACK -------- If you cannot get it to work, either turn Secure Boot off in the firmware settings (which avoids the need for the key, at the cost of that protection), or remove the proprietary driver (sudo apt purge nvidia-kernel-dkms nvidia-driver nvidia-smi; sudo apt autoremove) and return to nouveau. WHY THIS WORKS AS AN ANSWER --------------------------- It explains the reasoning (who can sign what, and why a person must be present) rather than just listing commands, and the recovery steps are ordered so each one can be checked before moving on.