Standalone backup agents for Linux, Mac, AIX & Solaris workloads on-premises or in the public cloud
Post Reply
mdiver
Veeam Legend
Posts: 239
Liked: 39 times
Joined: Nov 04, 2009 2:08 pm
Contact:

Bad shim signature while booting custom Linux recovery ISO

Post by mdiver »

For a SLES system with a HANA workload on top, we need a custom recovery ISO to do bare metal recoveries as we have NICs not included in the generic ISO.
We could generate the custom ISO as described in https://helpcenter.veeam.com/docs/agent ... tml?ver=60.

The ISO starts to boot as expected but then shows the following error:
bad shim signature - load kernel first
I could relate that to secure boot already:
https://forums.linuxmint.com/viewtopic.php?t=393337

We already have the appropriate certificates in the UEFI bios to allow for agent backups according to:
https://helpcenter.veeam.com/docs/agent ... tml?ver=60

The backup of the system runs flawlessly using blksnap.

Does another certificate have to be enrolled to use the ISO?

Thanks
Mike
rovshan.pashayev
Veeam Software
Posts: 571
Liked: 113 times
Joined: Jul 03, 2023 12:44 pm
Full Name: Rovshan Pashayev
Location: Czechia
Contact:

Re: Bad shim signature while booting custom Linux recovery ISO

Post by rovshan.pashayev »

Hello Mike,

In order to boot Veeam Recovery Media (VRM) with SecureBoot enabled, you need to use the original, unpatched ISO.
But, to boot VRM with an ISO patched on SLES, SecureBoot needs to be disabled.
Rovshan Pashayev
Analyst
Veeam Agent for Linux, Mac, AIX & Solaris
Post Reply

Who is online

Users browsing this forum: mdiver and 13 guests