{ pkgs, lib, lanzaboote, ... }: { # How to enter setup mode - msi motherboard ## 1. enter BIOS via [Del] Key ## 2. => => => ## 3. enable ## 4. set to ## 5. enter ## 6. select , and then select for ## 7. Press F10 to saving and reboot. imports = [ lanzaboote.nixosModules.lanzaboote ]; environment.systemPackages = [ # For debugging and troubleshooting Secure Boot. pkgs.sbctl ]; # Lanzaboote currently replaces the systemd-boot module. # This setting is usually set to true in configuration.nix # generated at installation time. So we force it to false # for now. boot.loader.systemd-boot.enable = lib.mkForce false; boot.lanzaboote = { enable = true; pkiBundle = "/etc/secureboot"; }; }