| name | secure-boot |
| description | Enroll the Bluefin Secure Boot key to enable signed kernel modules (NVIDIA, custom kmods). |
| domain | sysadmin |
Secure Boot Key Enrollment
Bluefin supports Secure Boot. For out-of-tree kernel modules (NVIDIA drivers, VirtualBox,
custom kmods), the Bluefin signing key must be enrolled in the MOK (Machine Owner Key)
database. This is a one-time post-install step required on NVIDIA variants and any
system using custom kmods.
Load with: point your agent at this file.
When to Use
- First boot after installing a Bluefin NVIDIA variant
- After rebasing to an image with custom kernel modules
- When the system refuses to load a kmod due to Secure Boot signature verification failure
- Verifying whether the Bluefin key is already enrolled
When NOT to Use
- Disabling Secure Boot entirely — enrolling the key is better than disabling Secure Boot
- Systems where Secure Boot is already working and kmods load correctly
Check Secure Boot Status
mokutil --sb-state
mokutil --list-enrolled
Bluefin Enrollment Flow (Recommended)
Use the ujust recipe — it handles key location and enrollment automatically:
ujust enroll-secure-boot-key
When prompted for a password during the MOK enrollment UI at reboot, enter: