# Confirm Secure Boot Enabled

**URL:** <https://forums.suse.com/t/confirm-secure-boot-enabled/35454>\
**Category:** General Discussion\
**Created:** [January 20, 2021, 3:30am UTC](https://forums.suse.com/t/confirm-secure-boot-enabled/35454 "2021-01-20T03:30:06Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Dwayne](https://avatars.discourse-cdn.com/v4/letter/d/8c91f0/32.png) [@Dwayne](https://forums.suse.com/u/Dwayne)\
**Post date:** [January 20, 2021, 3:30am UTC](https://forums.suse.com/t/confirm-secure-boot-enabled/35454/1 "2021-01-20T03:30:06Z")

</div>

Having a problem installing a security tool and the vendor is telling me to disable secure boot. How can I check that secure boot is enabled or configured?

---

<div class="post-metadata">

**Author:** ![malcolmlewis](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/malcolmlewis/32/11375_2.png) [@malcolmlewis](https://forums.suse.com/u/malcolmlewis)\
**Post date:** [January 20, 2021, 4:13am UTC](https://forums.suse.com/t/confirm-secure-boot-enabled/35454/2 "2021-01-20T04:13:13Z")

</div>

@Dwayne Hi and welcome to the Forum 🙂  
Depends on the SLE release… Try the command (as root user) `bootctl`

---

<div class="post-metadata">

**Author:** ![Dwayne](https://avatars.discourse-cdn.com/v4/letter/d/8c91f0/32.png) [@Dwayne](https://forums.suse.com/u/Dwayne)\
**Post date:** [January 20, 2021, 6:36pm UTC](https://forums.suse.com/t/confirm-secure-boot-enabled/35454/3 "2021-01-20T18:36:32Z")

</div>

> bootctl status  
> File system " /boot" is not a FAT EFI System Partition (ESP) file system.

Not sure if tells me anything about a secure boot. Anything else I can try?

Dwayne

---

<div class="post-metadata">

**Author:** ![malcolmlewis](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/malcolmlewis/32/11375_2.png) [@malcolmlewis](https://forums.suse.com/u/malcolmlewis)\
**Post date:** [January 20, 2021, 8:51pm UTC](https://forums.suse.com/t/confirm-secure-boot-enabled/35454/4 "2021-01-20T20:51:28Z")

</div>

@Dwayne Hi, then lets see if it’s using UEFI booting with `efibootmgr -v`

---

<div class="post-metadata">

**Author:** ![Davonious](https://avatars.discourse-cdn.com/v4/letter/d/ec9cab/32.png) [@Davonious](https://forums.suse.com/u/Davonious)\
**Post date:** [January 21, 2021, 6:08pm UTC](https://forums.suse.com/t/confirm-secure-boot-enabled/35454/5 "2021-01-21T18:08:43Z")

</div>

You could also do the quick and dirty method of parsing dmesg. I.e.  
sudo dmesg | grep -i “secure boot”  
The tool ‘efivar’ also can give some information, but the parameter names… wow. =)  
There’s a lot of love for the tool ‘efitools’, which a lot of people use to validate things like this. Unfortunately I can’t find a native 15.2 repo for it. Probably more my inexperience than anything. =)

---

<div class="post-metadata">

**Author:** ![malcolmlewis](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/malcolmlewis/32/11375_2.png) [@malcolmlewis](https://forums.suse.com/u/malcolmlewis)\
**Post date:** [January 21, 2021, 9:56pm UTC](https://forums.suse.com/t/confirm-secure-boot-enabled/35454/6 "2021-01-21T21:56:01Z")

</div>

@Davonious Hi and welcome to the Forum 🙂  
Just grab the src rpm from [https://download.opensuse.org/repositories/Base:/System/openSUSE\_Factory/src/](https://download.opensuse.org/repositories/Base:/System/openSUSE_Factory/src/) and rebuild locally (as your user!) with `rpmbuild --rebuild efitools-1.9.2-1.1.src.rpm` it will create a directory in $HOME/rpmbuild down in the RPMS directory will be your binaries to install with zypper (as root user) 😉
