Skip to main content
Close Search
Nitrux — #DisruptiveByDesign — Official WebsiteNitrux — #DisruptiveByDesign — Official Website
search
Menu
  • x-twitter bluesky facebook youtube github instagram telegram mastodon threads email
  • search
  • Menu
Nitrux — #DisruptiveByDesign — Official Website
  • Nitrux Core Concepts 9
    • Distribution Philosophy
    • System Architecture
      • Immutable Architecture
      • Rootless App Model
      • Aesthetic FHS
      • Init System
      • Language Stratification
      • Workspace Environment
    • Workspace Architecture
      • Workspace Compartmentalization
      • Nitrux Workspace Session Manager
  • Getting Started 20
    • System Requirements
      • Hardware Compatibility Validation Layer
      • Minimum Requirements
      • Recommended Requirements
    • Installation Guide
      • Download the ISO
        • ISO for AMD and Intel Hardware
        • ISO for NVIDIA Hardware
      • Validate the ISO
        • ISO Integrity Validation
        • ISO Authenticity Validation
      • Flashing the ISO
        • USB Flash Preflight
        • Rufus (Windows)
        • Ventoy (Windows/Linux)
        • dd (*nix)
      • Installing Nitrux
        • Nitrux Installation Process Information
        • Using Secure Boot with Nitrux
        • Automated Partitioning Options
        • Non-automated Partitioning Options
        • Full-disk Encryption in Nitrux
        • Single-booting Nitrux
        • Dual-booting Nitrux with Windows or other Linux distributions
        • Triple-booting Nitrux, Windows, and other Linux distributions
        • Report Installation Bugs
  • Workspace and UX 10
    • Workspace Applications
      • Default Software Selection
      • Workspace Settings
    • Workspace Defaults
      • greetd + QMLGreet
      • Hyprland
      • Valenz
      • Marina
      • Vicinae
      • QMLogout
      • NudgeOSD
      • Workspace Daemons
        • Default Session Daemons
  • Software Management 4
    • Graphical Software Manager (AppFinder)
    • User Application Delivery
      • NX AppHub and AppBoxes
      • Flatpak
    • Development Environments
      • Distrobox
  • Security and Privacy 6
    • Security Features
      • System Security Features
    • Security Policies
      • Identity and Access Management
      • Kernel and Memory Hardening
      • Network Security and Privacy
      • Session Hardening
      • Bluetooth Security
  • System Performance 4
    • Filesystem Optimizations
      • XFS Features in Nitrux
      • F2FS Features in Nitrux
    • System Optimizations
      • Advanced Memory Management
      • Performance and I/O
  • System Management 5
    • System Administration
      • Nitrux Update Tool System
      • NX Overlayroot
      • Nitrux GRUB Modes
    • System Configuration
      • SB Manager
      • Kernel Boot
  • Troubleshooting 21
    • FAQ
      • Is Nitrux right for me?
      • Is Nitrux eating my RAM?
      • NVIDIA Driver Information
      • Virtualizing Nitrux
      • Support for Other Desktop Environments
      • Flatpak Information
      • Energy Saving Information
      • Virtual Consoles (TTY) Information
      • GRUB Menu Information
      • KDE Wallet Information
      • NetworkManager Information
      • Backups Information
      • General Gaming Information
      • AppImage Information
      • MauiKit UI Framework Information
    • Installation Issues
      • ISO doesn’t boot or System installs, but there's no GUI
      • Can't install due to the MBR partition limit
      • Can't install due to mounted Swap partitions
      • Failure to install due to an issue with rsync error code 11
      • Failure to install GRUB on a computer with multiple storage devices or using the MBR partition table
      • Installation is successful, but user data isn't persistent
  • Resources 2
    • Tutorials
    • Get Involved

SB Manager

< 1 min read

16 views

SB Manager is a utility for managing Secure Boot on Nitrux. It generates Machine Owner Keys (MOK), signs kernels, and enrolls keys into the UEFI firmware.

How it works

SB Manager performs three steps:

  1. Generates Secure Boot keys (MOK).
  2. Signs the kernel for Secure Boot.
  3. Enrolls keys into the UEFI firmware.

The utility is highly automated. It prompts for permission before taking action and requests the OpenSSL certificate and MOK password.

What is Secure Boot?

Secure Boot is a UEFI security standard that verifies the digital signature of boot software before execution. Only software signed with a trusted key can run, preventing unauthorized code from loading during startup.

What is a Machine Owner Key (MOK)?

An MOK is a cryptographic key pair that allows users to sign custom kernels or modules for use with Secure Boot. Instead of disabling Secure Boot entirely, users can create their own keys, sign their software, and enroll the keys in the firmware.

Usage

Run from the terminal:

sb-manager

The utility requires pkexec elevated privileges. There are no configuration parameters or additional options.

Updated on 5 October, 2026
Previous - System AdministrationNitrux GRUB ModesNext - System ConfigurationKernel Boot
Close Menu
  • Documentation
  • Bug Tracker
  • Blog
    • Tutorial
    • News
    • Other
    • Blog Archive
      • News and Tutorial Archive
      • Maui Archive
      • ZNX Archive
      • VMetal Archive
      • PNX Archive
  • x-twitter
  • bluesky
  • facebook
  • youtube
  • github
  • instagram
  • telegram
  • mastodon
  • threads
  • email

© 2017-2026 Some Rights Reserved. Made with ♥ by Nitrux Latinoamericana S.C.