Standalone backup agents for Linux, Mac, AIX & Solaris workloads on-premises or in the public cloud
Post Reply
mdiver
Veeam Legend
Posts: 241
Liked: 39 times
Joined: Nov 04, 2009 2:08 pm
Contact:

Bad shim signature while booting custom Linux recovery ISO

Post by mdiver »

For a SLES system with a HANA workload on top, we need a custom recovery ISO to do bare metal recoveries as we have NICs not included in the generic ISO.
We could generate the custom ISO as described in https://helpcenter.veeam.com/docs/agent ... tml?ver=60.

The ISO starts to boot as expected but then shows the following error:
bad shim signature - load kernel first
I could relate that to secure boot already:
https://forums.linuxmint.com/viewtopic.php?t=393337

We already have the appropriate certificates in the UEFI bios to allow for agent backups according to:
https://helpcenter.veeam.com/docs/agent ... tml?ver=60

The backup of the system runs flawlessly using blksnap.

Does another certificate have to be enrolled to use the ISO?

Thanks
Mike
rovshan.pashayev
Veeam Software
Posts: 572
Liked: 113 times
Joined: Jul 03, 2023 12:44 pm
Full Name: Rovshan Pashayev
Location: Czechia
Contact:

Re: Bad shim signature while booting custom Linux recovery ISO

Post by rovshan.pashayev »

Hello Mike,

In order to boot Veeam Recovery Media (VRM) with SecureBoot enabled, you need to use the original, unpatched ISO.
But, to boot VRM with an ISO patched on SLES, SecureBoot needs to be disabled.
Rovshan Pashayev
Analyst
Veeam Agent for Linux, Mac, AIX & Solaris
mdiver
Veeam Legend
Posts: 241
Liked: 39 times
Joined: Nov 04, 2009 2:08 pm
Contact:

Re: Bad shim signature while booting custom Linux recovery ISO

Post by mdiver »

Hello Rovshan.

Thanks for your reply.

With the unpatched ISO, we unfortunately do not see all necessary drivers as they are not in generic LX-VRM. We have to bundle NIC drivers and NIC firmwares to bring the system into the LAN. We've also set --efi to create an efi aware ISO (BTW: why that switch if the patched ISO does never work?).

As you recommended, we recovered now with secure boot disabled, but the system does not boot after recovery.
It just jumps into grub after having shown some EFI errors.
I guess VRM during bare-metal recovery without secure boot did not correctly set the necessary entry points for GRUB with EFI.

What is the recommended way to recover with secure boot and be able to boot afterwards?
rovshan.pashayev
Veeam Software
Posts: 572
Liked: 113 times
Joined: Jul 03, 2023 12:44 pm
Full Name: Rovshan Pashayev
Location: Czechia
Contact:

Re: Bad shim signature while booting custom Linux recovery ISO

Post by rovshan.pashayev »

Hello Mike,

After recovery, remember to enable Secure Boot again.
If you continue to experience issues, please submit a Support Case and share the case number here for reference.

Thank you
Rovshan Pashayev
Analyst
Veeam Agent for Linux, Mac, AIX & Solaris
mdiver
Veeam Legend
Posts: 241
Liked: 39 times
Joined: Nov 04, 2009 2:08 pm
Contact:

Re: Bad shim signature while booting custom Linux recovery ISO

Post by mdiver »

We did re-enable secure boot.
We'll file a case. Hope they'll help as this leans more into SLES and GRUB.
We see secure boot most of the time now with physical agents.
Post Reply

Who is online

Users browsing this forum: No registered users and 14 guests