fix(pve-nvidia-host): refuse early on Secure Boot without an enrolled DKMS key; record nh3-pve SB=on
This commit is contained in:
@@ -90,6 +90,14 @@ not power back on by itself.
|
||||
Display = IGFX (or enable iGPU Multi-Monitor). Reaching the BIOS now needs a
|
||||
display on the RTX's mini-DP, for example the NanoKVM through a mini-DP→HDMI
|
||||
adapter. Verify with `lspci | grep 00:02.0` and `boot_vga` on `00:02.0`.
|
||||
- ⚠ **Secure Boot is ON here** (`mokutil --sb-state`, lockdown `integrity`;
|
||||
enrolled MOK = the Proxmox Secure Boot CA). esh-pve, the same model, has it
|
||||
OFF. Any DKMS-built module, the NVIDIA driver included, is refused until its
|
||||
key is enrolled through MokManager at boot or Secure Boot is turned off in the
|
||||
BIOS. Both need the console, and the console is blind (below). The 2026-09-25
|
||||
NVIDIA install failed on this and rolled itself back. What it left, all
|
||||
harmless: headers `6.8.12-11` plus the series meta, dkms and build-essential;
|
||||
nouveau blacklisted and unloaded; the `.run` staged in `/root/nvidia`.
|
||||
- **OOB decision (Prime via Miranda, 2026-09-25): HOLD. nh3-pve stays console-blind
|
||||
until the next NH3 site visit.** No BIOS change and no reboot until then. The
|
||||
accepted risk: a boot without network means a site trip. **Target end state:**
|
||||
|
||||
Reference in New Issue
Block a user