Skip to main content
Close Search
Nitrux — #DisruptiveByDesign — Official WebsiteNitrux — #DisruptiveByDesign — Official Website
search
Menu
  • x-twitter bluesky facebook youtube github instagram telegram mastodon threads email
  • search
  • Menu
Nitrux — #DisruptiveByDesign — Official Website
  • Nitrux Core Concepts 9
    • Distribution Philosophy
    • System Architecture
      • Immutable Architecture
      • Rootless App Model
      • Aesthetic FHS
      • Init System
      • Language Stratification
      • Workspace Environment
    • Workspace Architecture
      • Workspace Compartmentalization
      • Nitrux Workspace Session Manager
  • Getting Started 20
    • System Requirements
      • Hardware Compatibility Validation Layer
      • Minimum Requirements
      • Recommended Requirements
    • Installation Guide
      • Download the ISO
        • ISO for AMD and Intel Hardware
        • ISO for NVIDIA Hardware
      • Validate the ISO
        • ISO Integrity Validation
        • ISO Authenticity Validation
      • Flashing the ISO
        • USB Flash Preflight
        • Rufus (Windows)
        • Ventoy (Windows/Linux)
        • dd (*nix)
      • Installing Nitrux
        • Nitrux Installation Process Information
        • Using Secure Boot with Nitrux
        • Automated Partitioning Options
        • Non-automated Partitioning Options
        • Full-disk Encryption in Nitrux
        • Single-booting Nitrux
        • Dual-booting Nitrux with Windows or other Linux distributions
        • Triple-booting Nitrux, Windows, and other Linux distributions
        • Report Installation Bugs
  • Workspace and UX 10
    • Workspace Applications
      • Default Software Selection
      • Workspace Settings
    • Workspace Defaults
      • greetd + QMLGreet
      • Hyprland
      • Valenz
      • Marina
      • Vicinae
      • QMLogout
      • NudgeOSD
      • Workspace Daemons
        • Default Session Daemons
  • Software Management 4
    • Graphical Software Manager (AppFinder)
    • User Application Delivery
      • NX AppHub and AppBoxes
      • Flatpak
    • Development Environments
      • Distrobox
  • Security and Privacy 6
    • Security Features
      • System Security Features
    • Security Policies
      • Identity and Access Management
      • Kernel and Memory Hardening
      • Network Security and Privacy
      • Session Hardening
      • Bluetooth Security
  • System Performance 4
    • Filesystem Optimizations
      • XFS Features in Nitrux
      • F2FS Features in Nitrux
    • System Optimizations
      • Advanced Memory Management
      • Performance and I/O
  • System Management 5
    • System Administration
      • Nitrux Update Tool System
      • NX Overlayroot
      • Nitrux GRUB Modes
    • System Configuration
      • SB Manager
      • Kernel Boot
  • Troubleshooting 21
    • FAQ
      • Is Nitrux right for me?
      • Is Nitrux eating my RAM?
      • NVIDIA Driver Information
      • Virtualizing Nitrux
      • Support for Other Desktop Environments
      • Flatpak Information
      • Energy Saving Information
      • Virtual Consoles (TTY) Information
      • GRUB Menu Information
      • KDE Wallet Information
      • NetworkManager Information
      • Backups Information
      • General Gaming Information
      • AppImage Information
      • MauiKit UI Framework Information
    • Installation Issues
      • ISO doesn’t boot or System installs, but there's no GUI
      • Can't install due to the MBR partition limit
      • Can't install due to mounted Swap partitions
      • Failure to install due to an issue with rsync error code 11
      • Failure to install GRUB on a computer with multiple storage devices or using the MBR partition table
      • Installation is successful, but user data isn't persistent
  • Resources 2
    • Tutorials
    • Get Involved

Using Secure Boot with Nitrux

1 min read

33 views

When Secure Boot is enabled, we strongly recommend using Ventoy to boot the ISO. Ventoy provides documentation on enrolling its key in the computer’s MOKManager. After enrolling Ventoy’s key and rebooting, select our ISO and use GRUB 2 Boot mode. However, enrolling Ventoy’s key only authorizes Ventoy; it does not authorize the bootloader installed on the system.

As of Nitrux 7.0.0, the Nitrux GRUB packages currently contain unsigned UEFI binaries, and the default Nitrux kernel is also unsigned. Therefore, an installed system may fail to boot before the kernel loads if Secure Boot remains enabled.

To boot the installed system with Secure Boot enabled, the installed bootloader must first be trusted—through a signed shim and compatible GRUB, or a locally trusted GRUB—and the kernel must also be signed.

Important Notes

If Secure Boot is enabled and the kernel is unsigned, booting will fail with an error such as “Secure Boot Violation”, “Secure Boot Fail”, and other variants. Some distributions, like Ubuntu, have their bootloaders (shims) signed by Microsoft’s UEFI CA, allowing them to trust their kernels without manual enrollment. Given our past interactions with Microsoft and its partners, we’re unwilling to pay Microsoft for its signing service.

Users can freely generate and enroll their Machine Owner Keys (MOKs) to sign the bootloader and kernel locally.

Updated on 4 October, 2026
Previous - Installing NitruxNitrux Installation Process InformationNext - Installing NitruxAutomated Partitioning Options
Close Menu
  • Documentation
  • Bug Tracker
  • Blog
    • Tutorial
    • News
    • Other
    • Blog Archive
      • News and Tutorial Archive
      • Maui Archive
      • ZNX Archive
      • VMetal Archive
      • PNX Archive
  • x-twitter
  • bluesky
  • facebook
  • youtube
  • github
  • instagram
  • telegram
  • mastodon
  • threads
  • email

© 2017-2026 Some Rights Reserved. Made with ♥ by Nitrux Latinoamericana S.C.