Secureboot lockdown testing successful:
ubuntu@mantic-opt:~$ uname -a Linux mantic-opt 6.5.0-1003-intel-opt #3-Ubuntu SMP Thu Oct 19 20:43:29 UTC 2023 x86_64 x86_64 x86_64 GNU/Linux ubuntu@mantic-opt:~$ cat /sys/kernel/security/lockdown none [integrity] confidentiality ubuntu@mantic-opt:~$ sudo dmesg|grep lockdown [ 0.000000] Kernel is locked down from EFI Secure Boot mode; see man kernel_lockdown.7 [ 0.367595] LSM: initializing lsm=lockdown,capability,landlock,yama,apparmor,integrity [ 1.968857] Lockdown: swapper/0: hibernation is restricted; see man kernel_lockdown.7 ubuntu@mantic-opt:~$ sudo dmesg|grep secureboot [ 0.000000] secureboot: Secure boot enabled [ 0.022929] secureboot: Secure boot enabled
Secureboot lockdown testing successful:
ubuntu@ mantic- opt:~$ uname -a intel-opt #3-Ubuntu SMP Thu Oct 19 20:43:29 UTC 2023 x86_64 x86_64 x86_64 GNU/Linux mantic- opt:~$ cat /sys/kernel/ security/ lockdown mantic- opt:~$ sudo dmesg|grep lockdown capability, landlock, yama,apparmor, integrity mantic- opt:~$ sudo dmesg|grep secureboot
Linux mantic-opt 6.5.0-1003-
ubuntu@
none [integrity] confidentiality
ubuntu@
[ 0.000000] Kernel is locked down from EFI Secure Boot mode; see man kernel_lockdown.7
[ 0.367595] LSM: initializing lsm=lockdown,
[ 1.968857] Lockdown: swapper/0: hibernation is restricted; see man kernel_lockdown.7
ubuntu@
[ 0.000000] secureboot: Secure boot enabled
[ 0.022929] secureboot: Secure boot enabled