On Sat, Feb 26, 2022, 20:26 Tobias Powalowski via arch-general < arch-general@xxxxxxxxxxxxxxxxxxx> wrote: > Hi > > --sbat=/usr/share/grub/sbat.csv --modules="all_video boot btrfs cat > configfile cryptodisk echo efi_gop efi_uga efifwsetup efinet ext2 f2fs > fat font gcry_rijndael gcry_rsa gcry_serpent gcry_sha256 gcry_twofish > gcry_whirlpool gfxmenu gfxterm gzio halt hfsplus http iso9660 loadenv > loopback linux lvm lsefi lsefimmap luks luks2 mdraid09 mdraid1x > minicmd net normal part_apple part_msdos part_gpt password_pbkdf2 pgp > png reboot regexp search search_fs_uuid search_fs_file search_label > serial sleep syslinuxcfg test tftp video xfs zstd backtrace chain tpm > usb usbserial_common usbserial_pl2303 usbserial_ftdi > usbserial_usbdebug keylayouts at_keyboard" > > These options are used for SB and if you want to use Secure Boot you > need to use standalone grub, cause it is not allowed to load modules > in Secure Boot mode. > greetings > tpowa > > -- > Tobias Powalowski > Arch Linux Developer & Package Maintainer (tpowa) > https://www.archlinux.org > tpowa@xxxxxxxxxxxxx > > St. Martin-Apotheke > Herzog-Georg-Str. 25 > 89415 Lauingen > https://www.st-martin-apo.de > info@xxxxxxxxxxxxxxxx Hey Tobias, Thanks for the input! Do I need to load all of those modules to make Grub happy? Also, do I need anything else than the correct `grub-install` command? I noticed in the UEFI SB ArchWiki it's mentioned to sign also the kernel. Bests, Giovanni