Fedora Account System
Red Hat Associate
Red Hat Customer
Booting the official RHEL8.8 DVD in UEFI mode in QEMU/KVM fails with "Verify error:self signed certificate in certificate chain" when Shim verifies the signature of the Kernel, hence once selecting the kernel in Grub. This occurs since upgrading from Fedora 41 to Fedora 42. I verified that all was fine with Fedora 41. The RHEL8.10 DVD works fine. Packages (latest): qemu-kvm-9.2.3-1.fc42.x86_64 edk2-ovmf-20250221-8.fc42.noarch Reproducible: Always Steps to Reproduce: 1. Create a QEMU/KVM using virt-manager in UEFI Secure Boot mode 2. Boot the RHEL8.8 DVD 3. Select an entry to boot the kernel Actual Results: Automatic reboot after selecting the kernel Expected Results: Kernel boots fine
Created attachment 2091200 [details] Serial console in Shim verbose mode showing the automatic reboot
Created attachment 2091201 [details] Serial console in Shim verbose mode when booting RHEL8.10 DVD (all fine)
Fedora 42 is more strict on NX, following the microsoft secure boot signing policy change in 2022, see https://fedoraproject.org/wiki/Changes/Edk2Security for details. The NX fixes have been backported to RHEL-8.10 but not RHEL-8.8 and older. Essentially it is a guest issue. I'd recommend to use RHEL-8.10. Alternatively it is also possible to use the edk2 builds without secure boot support which continue to be less strict on NX.
*** This bug has been marked as a duplicate of bug 2373761 ***