Problem Description:
Should I try to install Ubuntu with Secure Boot on or turn it off?
It’s an older laptop (Acer Aspire V5 571) - no good for Windows 11, so in the next week or so, installing Ubuntu and won’t be using Windows anymore.
Windows secure boot certificates expiring June2026 - does this matter? Should I try to update the certificates?
Relevant System Information:
Acer Aspire V5 571.
with secure boot turned off, boots okay into the ‘try ubuntu’ environment (from a usb).
currently only Windows 10 installed (all backed up, plan is erase disk and install Ubuntu).
While Ubuntu supports both secure boot on or off you should know that if you have secure boot on Ubuntu only supports running signed kernels no unsigned or custom kernels can be installed unless you sign them to run with secure boot on. You also can’t run mainline kernels with secure boot on at least not yet until the Ubuntu team decides to support mainline kernels with secure boot on.
Thanks William - while I like the idea of being adventurous with the kernel, not really at that level of competency.
Really more concerned about issues like - if something goes wrong, am I going to get a bricked device?
All the best.
If you’re going to make an assertion like that, please explain it clearly for everybody.
Please don’t scare people and then walk away. We just don’t do that here.
Folks are welcome to explain the complexity to a beginner (as much as that beginner wants) so they learn good questions they should ask.
The Ubuntu Install ISO will boot in a secure boot environment. The OP will always be able to retrieve their data or rescue their system, whether in a secure boot environment or not. Any blocker to un-bricking won’t be related to Secure Boot, unless the OP has done some really advanced surgery upon their system.
You gave zero technical information beyond stating something you probably read somewhere, itself probably a false claim. Please cite your sources if you’re going to make such a claim.
All seems to be working fine.
Set up with secure boot.
Can still access the UEFI menu.
Whilst Windows was still installed, the UEFI menu was a little difficult to use, but all seems fine now.
Thanks everyone - moving forward, I now have a working computer!
Please don’t use Grub Customizer. It’s been deprecated for several years now, because it can cause problems (I learned this the hard way).
It’s not available in the Ubuntu repositories (I’ve checked on 24.04).
@gregbrady — If you install with Secure Boot on, and subsequently updates cause a problem with it, you can simply turn off Secure Boot. However, it’s highly unlikely to be a problem for several years still (I’ve asked that same question about expiring certificates before).
Actually it’s still maintained and was last updated 28Apr25 though it has been removed from the Ubuntu repos for sometime now for the reason you stated and yea it’s something you use at your own risk.
If there’s no real reason for using other kernel than one supplied and maintained by Ubuntu, I would stay away from messing with them. Everyone is free to use their system as they wish, but especially when you are new to Ubuntu and/or Linux in general, there’s no need to use something else than default one, if everything works and that’s usually the case with signed and tested kernels.