Tboot bootloader (Intel TXT) not Supported on UEFI Secure Boot Systems
This document (000019785) is provided subject to the disclaimer at the end of this document.
Environment
SUSE Linux Enterprise Server 15
Situation
"error: can't find command `multiboot`" and "error: can't find command `module`".
Resolution
The tboot bootloader would allow to run arbitrary other machine code that is unsigned and thus would break the Secure Boot concept.
To use the tboot bootloader despite of this, it is possible to disable the Secure Boot feature in the machine's UEFI configuration. In this case the grub2 bootloader will allow to load the untrusted tboot bootloader.
However, using this approach, the Secure Boot security feature will be lost.
SUSE does not recommend this approach for typical installations.
Cause
Disclaimer
This Support Knowledgebase provides a valuable tool for SUSE customers and parties interested in our products and solutions to acquire information, ideas and learn from one another. Materials are provided for informational, personal or non-commercial use within your organization and are presented "AS IS" WITHOUT WARRANTY OF ANY KIND.
- Document ID:000019785
- Creation Date: 16-Nov-2020
- Modified Date:10-Dec-2020
-
- SUSE Linux Enterprise Server
For questions or concerns with the SUSE Knowledgebase please contact: tidfeedback[at]suse.com