Re-verified trusty since the previous trusty comment was imprecise:
dkms 2.2.0.3-1.1ubuntu5.14.04.10
Upgrading kernel and headers follows with a loadable, properly signed module using the MOK generated previously.
ubuntu@ubuntu:~$ dpkg -l shim-signed dkms | cat Desired=Unknown/Install/Remove/Purge/Hold | Status=Not/Inst/Conf-files/Unpacked/halF-conf/Half-inst/trig-aWait/Trig-pend |/ Err?=(none)/Reinst-required (Status,Err: uppercase=bad) ||/ Name Version Architecture Description +++-=====================================-====================================================-============-=============================================================================== ii dkms 2.2.0.3-1.1ubuntu5.14.04.10 all Dynamic Kernel Module Support Framework ii shim-signed 1.33.1~14.04.4+13-0ubuntu2 amd64 Secure Boot chain-loading bootloader (Microsoft-signed binary)
[...]
Unpacking linux-headers-4.4.0-142-generic (4.4.0-142.168~14.04.1) ... Setting up linux-headers-4.4.0-142 (4.4.0-142.168~14.04.1) ... Setting up linux-headers-4.4.0-142-generic (4.4.0-142.168~14.04.1) ... Examining /etc/kernel/header_postinst.d. run-parts: executing /etc/kernel/header_postinst.d/dkms 4.4.0-142-generic /boot/vmlinuz-4.4.0-142-generic Nothing to do. Nothing to do. ubuntu@ubuntu:/lib/modules/4.4.0-142-generic$ cat /proc/version_signature Ubuntu 4.4.0-142.168~14.04.1-generic 4.4.167 ubuntu@ubuntu:/lib/modules/4.4.0-142-generic$ sudo modprobe bbswitch modprobe: ERROR: could not insert 'bbswitch': No such device ubuntu@ubuntu:/lib/modules/4.4.0-142-generic$ dmesg | tail [ 15.036233] audit: type=1400 audit(1550095748.630:15): apparmor="STATUS" operation="profile_replace" profile="unconfined" name="/usr/lib/connman/scripts/dhclient-script" pid=1004 comm="apparmor_parser" [ 15.036504] audit: type=1400 audit(1550095748.630:16): apparmor="STATUS" operation="profile_replace" profile="unconfined" name="/usr/lib/connman/scripts/dhclient-script" pid=1004 comm="apparmor_parser" [ 15.118903] audit: type=1400 audit(1550095748.714:17): apparmor="STATUS" operation="profile_load" profile="unconfined" name="/usr/sbin/tcpdump" pid=1006 comm="apparmor_parser" [ 15.273612] init: plymouth-upstart-bridge main process ended, respawning [ 16.272167] random: nonblocking pool is initialized [ 219.644638] bbswitch: loading out-of-tree module taints kernel. [ 219.644704] bbswitch: module verification failed: signature and/or required key missing - tainting kernel [ 219.645133] bbswitch: version 0.7 [ 219.645146] bbswitch: Found integrated VGA device 0000:00:02.0: \_SB_.PCI0.VID_ [ 219.645159] bbswitch: No discrete VGA device found
Re-verified trusty since the previous trusty comment was imprecise:
dkms 2.2.0.3- 1.1ubuntu5. 14.04.10
Upgrading kernel and headers follows with a loadable, properly signed module using the MOK generated previously.
ubuntu@ubuntu:~$ dpkg -l shim-signed dkms | cat Unknown/ Install/ Remove/ Purge/Hold Not/Inst/ Conf-files/ Unpacked/ halF-conf/ Half-inst/ trig-aWait/ Trig-pend /Reinst- required (Status,Err: uppercase=bad) ======= ======= ======= ======= ======- ======= ======= ======= ======= ======= ======= ======= ===-=== ======= ==-==== ======= ======= ======= ======= ======= ======= ======= ======= ======= ======= ===== 1.1ubuntu5. 14.04.10 all Dynamic Kernel Module Support Framework 14.04.4+ 13-0ubuntu2 amd64 Secure Boot chain-loading bootloader (Microsoft-signed binary)
Desired=
| Status=
|/ Err?=(none)
||/ Name Version Architecture Description
+++-===
ii dkms 2.2.0.3-
ii shim-signed 1.33.1~
[...]
Unpacking linux-headers- 4.4.0-142- generic (4.4.0- 142.168~ 14.04.1) ... 4.4.0-142 (4.4.0- 142.168~ 14.04.1) ... 4.4.0-142- generic (4.4.0- 142.168~ 14.04.1) ... header_ postinst. d. header_ postinst. d/dkms 4.4.0-142-generic /boot/vmlinuz- 4.4.0-142- generic ubuntu: /lib/modules/ 4.4.0-142- generic$ cat /proc/version_ signature 168~14. 04.1-generic 4.4.167 ubuntu: /lib/modules/ 4.4.0-142- generic$ sudo modprobe bbswitch ubuntu: /lib/modules/ 4.4.0-142- generic$ dmesg | tail 8.630:15) : apparmor="STATUS" operation= "profile_ replace" profile= "unconfined" name="/ usr/lib/ connman/ scripts/ dhclient- script" pid=1004 comm="apparmor_ parser" 8.630:16) : apparmor="STATUS" operation= "profile_ replace" profile= "unconfined" name="/ usr/lib/ connman/ scripts/ dhclient- script" pid=1004 comm="apparmor_ parser" 8.714:17) : apparmor="STATUS" operation= "profile_ load" profile= "unconfined" name="/ usr/sbin/ tcpdump" pid=1006 comm="apparmor_ parser" upstart- bridge main process ended, respawning
Setting up linux-headers-
Setting up linux-headers-
Examining /etc/kernel/
run-parts: executing /etc/kernel/
Nothing to do.
Nothing to do.
ubuntu@
Ubuntu 4.4.0-142.
ubuntu@
modprobe: ERROR: could not insert 'bbswitch': No such device
ubuntu@
[ 15.036233] audit: type=1400 audit(155009574
[ 15.036504] audit: type=1400 audit(155009574
[ 15.118903] audit: type=1400 audit(155009574
[ 15.273612] init: plymouth-
[ 16.272167] random: nonblocking pool is initialized
[ 219.644638] bbswitch: loading out-of-tree module taints kernel.
[ 219.644704] bbswitch: module verification failed: signature and/or required key missing - tainting kernel
[ 219.645133] bbswitch: version 0.7
[ 219.645146] bbswitch: Found integrated VGA device 0000:00:02.0: \_SB_.PCI0.VID_
[ 219.645159] bbswitch: No discrete VGA device found