2

I am running Ubuntu 22.04 with the Mate desktop. Yesterday, when I returned to my desk, the laptop screen was black. I clicked the mouse, but it didn't wake up. I thought it was frozen, so I performed a hard reset by pressing the power button for five seconds. Afterward, I noticed that it was lagging and getting stuck at the BIOS logo for a while during boot. The day before, I had upgraded the kernel to:

uname -a
Linux whatnext 5.15.0-72-generic #79-Ubuntu SMP Wed Apr 19 08:22:18 UTC 2023 x86_64 x86_64 x86_64 GNU/Linux

Despite the lagging at the BIOS, the system eventually boots and runs well.

I also noticed an error in the log, but it was there for a long time, so I believe it is unrelated:

Loading X.509 certificate: UEFI:db
[    0.834706] integrity: Problem loading X.509 certificate -65
[    0.834710] fbcon: Taking over console

Would you please assist me?

EDIT:

Output of systemd-analyze:

Startup finished in 3.051s (kernel) + 9.435s (userspace) = 12.487s 
graphical.target reached after 9.208s in userspace

Output of systemd-analyze blame:

6.028s NetworkManager-wait-online.service
2.368s snapd.service
1.807s snapd.seeded.service
1.494s networkd-dispatcher.service
1.479s postfix@-.service
1.075s systemd-resolved.service
1.042s xrdp.service
 745ms ufw.service
 525ms netfilter-persistent.service
 414ms blueman-mechanism.service
 335ms dev-nvme0n1p2.device
 291ms binfmt-support.service
 265ms php8.1-fpm.service
 252ms snapd.apparmor.service
 240ms udisks2.service
 225ms tlp.service
 218ms apport-autoreport.service
 213ms upower.service
 202ms accounts-daemon.service
 195ms avahi-daemon.service
 193ms bluetooth.service
 192ms apparmor.service
 180ms lightdm.service
 180ms polkit.service
 180ms dev-loop23.device
 180ms dev-loop25.device
 179ms power-profiles-daemon.service
 178ms dev-loop24.device
 178ms dev-loop29.device
 177ms dev-loop17.device
 176ms plymouth-quit-wait.service
 175ms dev-loop28.device
 174ms dev-loop19.device
 173ms dev-loop31.device
 172ms phpsessionclean.service
 171ms dev-loop22.device
 170ms dev-loop20.device
 170ms dev-loop21.device
 168ms dev-loop30.device
 167ms dev-loop16.device
 166ms dev-loop12.device
 164ms systemd-udev-trigger.service
 164ms dev-loop15.device
 163ms dev-loop10.device
 161ms dev-loop13.device
 160ms suricata.service
 159ms switcheroo-control.service
 159ms user@1000.service
 157ms dev-loop26.device
 155ms thermald.service
 155ms dns-clean.service
 154ms systemd-logind.service
 154ms gpu-manager.service
 153ms dev-loop14.device
 153ms apport.service
 152ms wpa_supplicant.service
 149ms dev-loop5.device
 148ms snap.upnp-server.webdav.service
 146ms dev-loop6.device
 145ms dev-loop7.device
 144ms dev-loop2.device
 143ms dev-loop11.device
 143ms winbind.service
 143ms dev-loop1.device
 143ms dev-loop0.device
 140ms dev-loop8.device
 140ms secureboot-db.service
 135ms dev-loop9.device
 131ms grub-common.service
 128ms dev-loop27.device
 126ms dev-loop4.device
 125ms smartmontools.service
 118ms dev-loop18.device
 114ms dev-loop3.device
 114ms systemd-journald.service
 114ms systemd-timesyncd.service
 104ms systemd-oomd.service
 101ms virtualbox.service
  98ms mini-httpd.service
  97ms console-setup.service
  90ms systemd-tmpfiles-setup.service
  88ms apache2.service
  87ms lm-sensors.service
  80ms ModemManager.service
  79ms modprobe@chromeos_pstore.service
  78ms update-notifier-download.service
  77ms rsyslog.service
  72ms e2scrub_reap.service
  64ms proc-sys-fs-binfmt_misc.mount
  64ms systemd-udevd.service
  64ms bluez-alsa.service
  62ms snap-alfacast-44.mount
  61ms snap-android\x2dstudio-126.mount
  56ms snap-arduino-85.mount
  55ms snap-bare-5.mount
  54ms snap-chromium-2477.mount
  53ms cups.service
  53ms snap-chromium\x2dffmpeg-30.mount
  51ms networking.service
  51ms snap-code-129.mount
  50ms plymouth-read-write.service
  50ms systemd-networkd.service
  49ms snap-core-14946.mount
  48ms snap-core18-2745.mount
  47ms NetworkManager.service
  47ms snap-core20-1891.mount
  46ms keyboard-setup.service
  45ms kerneloops.service
  44ms snap-core22-634.mount
  42ms snap-cups-872.mount
  41ms netperf.service
  41ms snap-firefox-2667.mount
  41ms snap-firefox-2710.mount
  41ms systemd-journal-flush.service
  40ms snap-flutter-130.mount
  39ms snap-gnome\x2d3\x2d28\x2d1804-198.mount
  38ms snap-gnome\x2d3\x2d38\x2d2004-140.mount
  37ms snap-gnome\x2d42\x2d2204-102.mount
  36ms snap-gtk2\x2dcommon\x2dthemes-13.mount
  35ms systemd-fsck@dev-disk-by\x2duuid-1AD1\x2d6070.service
  35ms snap-gtk\x2dcommon\x2dthemes-1535.mount
  34ms snap-guiscrcpy-256.mount
  33ms ssh.service
  33ms vtun.service
  32ms snap-onlyoffice\x2ddesktopeditors-147.mount
  31ms snap-p7zip\x2ddesktop-220.mount
  30ms nscd.service
  29ms snap-pycharm\x2dcommunity-332.mount
  28ms snap-qt515\x2dcore20-28.mount
  27ms snap-scrcpy-399.mount
  27ms nvmf-autoconnect.service
  26ms snap-snapd-19122.mount
  25ms systemd-modules-load.service
  24ms openvpn.service
  24ms snap-snapd\x2ddesktop\x2dintegration-83.mount
  23ms boot-efi.mount
  23ms snap-spotify-67.mount
  22ms plymouth-start.service
  22ms conky-refresh.service
  21ms snap-sublime\x2dtext-118.mount
  20ms snap-upnp\x2dserver-1.mount
  19ms dev-hugepages.mount
  19ms dev-mqueue.mount
  19ms snap-whatsie-146.mount
  18ms sys-kernel-debug.mount
  18ms grub-initrd-fallback.service
  18ms sys-kernel-tracing.mount
  18ms tmp.mount
  17ms atd.service
  15ms var-snap-firefox-common-host\x2dhunspell.mount
  15ms kmod-static-nodes.service
  15ms systemd-sysusers.service
  14ms modprobe@configfs.service
  13ms modprobe@drm.service
  12ms xrdp-sesman.service
  12ms modprobe@fuse.service
  11ms systemd-tmpfiles-setup-dev.service
  10ms setvtrgb.service
  10ms alsa-restore.service
  10ms systemd-user-sessions.service
   9ms systemd-random-seed.service
   8ms systemd-sysctl.service
   8ms systemd-update-utmp.service
   7ms user-runtime-dir@1000.service
   7ms systemd-network-generator.service
   6ms systemd-backlight@backlight:amdgpu_bl0.service
   6ms systemd-remount-fs.service
   5ms swapfile.swap
   5ms systemd-update-utmp-runlevel.service
   4ms systemd-networkd-wait-online.service
   4ms modprobe@efi_pstore.service
   4ms modprobe@pstore_blk.service
   3ms modprobe@pstore_zone.service
   3ms sys-fs-fuse-connections.mount
   3ms rtkit-daemon.service
   3ms ifupdown-pre.service
   2ms sys-kernel-config.mount
   2ms modprobe@ramoops.service
   1ms postfix.service
 683us snapd.socket

Output of mokutil --list-enrolled:

[key 1]
SHA1 Fingerprint: 76:a0:92:06:58:00:bf:37:69:01:c3:72:cd:55:a9:0e:1f:de:d2:e0
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            b9:41:24:a0:18:2c:92:67
        Signature Algorithm: sha256WithRSAEncryption
        Issuer: C=GB, ST=Isle of Man, L=Douglas, O=Canonical Ltd., CN=Canonical Ltd. Master Certificate Authority
        Validity
            Not Before: Apr 12 11:12:51 2012 GMT
            Not After : Apr 11 11:12:51 2042 GMT
        Subject: C=GB, ST=Isle of Man, L=Douglas, O=Canonical Ltd., CN=Canonical Ltd. Master Certificate Authority
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (2048 bit)
                Modulus:
                    00:bf:5b:3a:16:74:ee:21:5d:ae:61:ed:9d:56:ac:
                    bd:de:de:72:f3:dd:7e:2d:4c:62:0f:ac:c0:6d:48:
                    08:11:cf:8d:8b:fb:61:1f:27:cc:11:6e:d9:55:3d:
                    39:54:eb:40:3b:b1:bb:e2:85:34:79:ca:f7:7b:bf:
                    ba:7a:c8:10:2d:19:7d:ad:59:cf:a6:d4:e9:4e:0f:
                    da:ae:52:ea:4c:9e:90:ce:c6:99:0d:4e:67:65:78:
                    5d:f9:d1:d5:38:4a:4a:7a:8f:93:9c:7f:1a:a3:85:
                    db:ce:fa:8b:f7:c2:a2:21:2d:9b:54:41:35:10:57:
                    13:8d:6c:bc:29:06:50:4a:7e:ea:99:a9:68:a7:3b:
                    c7:07:1b:32:9e:a0:19:87:0e:79:bb:68:99:2d:7e:
                    93:52:e5:f6:eb:c9:9b:f9:2b:ed:b8:68:49:bc:d9:
                    95:50:40:5b:c5:b2:71:aa:eb:5c:57:de:71:f9:40:
                    0a:dd:5b:ac:1e:84:2d:50:1a:52:d6:e1:f3:6b:6e:
                    90:64:4f:5b:b4:eb:20:e4:61:10:da:5a:f0:ea:e4:
                    42:d7:01:c4:fe:21:1f:d9:b9:c0:54:95:42:81:52:
                    72:1f:49:64:7a:c8:6c:24:f1:08:70:0b:4d:a5:a0:
                    32:d1:a0:1c:57:a8:4d:e3:af:a5:8e:05:05:3e:10:
                    43:a1
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Subject Key Identifier: 
                AD:91:99:0B:C2:2A:B1:F5:17:04:8C:23:B6:65:5A:26:8E:34:5A:63
            X509v3 Authority Key Identifier: 
                AD:91:99:0B:C2:2A:B1:F5:17:04:8C:23:B6:65:5A:26:8E:34:5A:63
            X509v3 Basic Constraints: critical
                CA:TRUE
            X509v3 Key Usage: 
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 CRL Distribution Points: 
                Full Name:
                  URI:http://www.canonical.com/secure-boot-master-ca.crl
    Signature Algorithm: sha256WithRSAEncryption
    Signature Value:
        3f:7d:f6:76:a5:b3:83:b4:2b:7a:d0:6d:52:1a:03:83:c4:12:
        a7:50:9c:47:92:cc:c0:94:77:82:d2:ae:57:b3:99:04:f5:32:
        3a:c6:55:1d:07:db:12:a9:56:fa:d8:d4:76:20:eb:e4:c3:51:
        db:9a:5c:9c:92:3f:18:73:da:94:6a:a1:99:38:8c:a4:88:6d:
        c1:fc:39:71:d0:74:76:16:03:3e:56:23:35:d5:55:47:5b:1a:
        1d:41:c2:d3:12:4c:dc:ff:ae:0a:92:9c:62:0a:17:01:9c:73:
        e0:5e:b1:fd:bc:d6:b5:19:11:7a:7e:cd:3e:03:7e:66:db:5b:
        a8:c9:39:48:51:ff:53:e1:9c:31:53:91:1b:3b:10:75:03:17:
        ba:e6:81:02:80:94:70:4c:46:b7:94:b0:3d:15:cd:1f:8e:02:
        e0:68:02:8f:fb:f9:47:1d:7d:a2:01:c6:07:51:c4:9a:cc:ed:
        dd:cf:a3:5d:ed:92:bb:be:d1:fd:e6:ec:1f:33:51:73:04:be:
        3c:72:b0:7d:08:f8:01:ff:98:7d:cb:9c:e0:69:39:77:25:47:
        71:88:b1:8d:27:a5:2e:a8:f7:3f:5f:80:69:97:3e:a9:f4:99:
        14:db:ce:03:0e:0b:66:c4:1c:6d:bd:b8:27:77:c1:42:94:bd:
        fc:6a:0a:bc

[key 2] SHA1 Fingerprint: ed:b0:b4:c8:15:c7:cd:09:1d:ea:c6:62:02:29:2f:e8:49:3c:08:80 Certificate: Data: Version: 3 (0x2) Serial Number: 02:8a:4d:05:27:66:63:cc:be:3a:cd:fd:5f:b3:9d:98:23:23:7a:a9 Signature Algorithm: sha256WithRSAEncryption Issuer: CN=kenn-IdeaPad-3-15ALC6 Secure Boot Module Signature key Validity Not Before: Sep 5 09:44:05 2022 GMT Not After : Aug 12 09:44:05 2122 GMT Subject: CN=kenn-IdeaPad-3-15ALC6 Secure Boot Module Signature key Subject Public Key Info: Public Key Algorithm: rsaEncryption Public-Key: (2048 bit) Modulus: 00:be:c5:2f:36:3f:bf:c9:93:9a:26:2b:c2:fa:04: 5a:f3:e3:57:12:dd:65:a3:ba:43:12:c4:bb:ff:f6: 31:d1:10:15:22:88:27:64:7d:03:dc:3d:8b:d4:ed: 43:d2:90:1c:cf:9b:78:8f:43:f8:fe:22:e3:0a:ad: bf:c6:41:61:0d:f7:c7:d2:18:5f:01:ad:88:11:e9: f1:90:4e:ae:85:e2:4b:79:07:71:19:38:64:97:b2: 66:00:a4:c1:c2:f3:7b:16:f5:61:62:c0:ee:5f:3d: 22:1a:af:4c:1c:d1:85:f5:4d:47:b1:88:ec:7a:4f: e1:dc:36:3a:02:f1:d8:d0:31:dd:b2:01:fa:7e:3a: f7:16:54:5c:b8:9a:1d:29:39:25:2e:89:45:b4:26: 2e:67:73:90:bc:2b:87:21:c9:6c:62:56:f4:6a:ac: 4a:c3:c4:4a:d5:0d:ce:49:f2:ec:63:ac:95:9d:46: 84:db:8d:81:44:6b:df:f0:cd:3d:f9:56:3d:a7:4b: 69:39:b0:ca:00:08:0f:74:ce:d4:85:6c:74:2f:57: 6e:93:48:b2:f1:cc:00:a8:15:38:56:47:1b:f6:a1: 5e:b9:d2:4d:c9:b1:0b:c9:16:e1:97:f8:9f:92:c7: f4:be:a1:e0:73:6c:03:95:df:b0:a7:d4:a4:39:d4: fe:39 Exponent: 65537 (0x10001) X509v3 extensions: X509v3 Subject Key Identifier: 59:3A:5A:DA:59:A3:8C:EA:7F:1A:03:3B:C4:0F:FD:D9:54:7D:ED:62 X509v3 Authority Key Identifier: 59:3A:5A:DA:59:A3:8C:EA:7F:1A:03:3B:C4:0F:FD:D9:54:7D:ED:62 X509v3 Basic Constraints: critical CA:FALSE X509v3 Extended Key Usage: Code Signing, 1.3.6.1.4.1.2312.16.1.2 Netscape Comment: OpenSSL Generated Certificate Signature Algorithm: sha256WithRSAEncryption Signature Value: 02:39:87:80:9a:f7:e7:27:34:58:7a:86:18:76:6f:5f:bf:a6: 3e:3e:31:fb:80:75:47:ba:b4:2c:3d:bb:cf:29:8e:fc:32:25: 52:95:a0:2f:86:25:8d:df:bf:fd:d1:61:f4:fd:1f:99:33:19: df:c8:fd:a3:fe:b3:fe:51:07:91:c8:10:c9:39:49:2a:c8:a6: e9:82:ae:80:0b:ed:2a:77:d5:a8:7e:d0:a5:c1:ba:1d:c6:41: cc:1f:4a:b5:73:20:b1:af:42:72:d1:52:e7:e1:c3:72:fb:78: f3:e4:fa:12:1e:b9:1c:02:f6:66:22:89:53:ec:d6:d7:0c:c0: 8e:c9:d5:fa:49:1f:b8:b3:3c:74:ae:0a:fb:03:7d:4c:43:ce: b3:f7:11:35:7c:5c:a0:32:9a:61:c3:d8:6b:56:d1:75:58:39: 40:04:58:91:32:f7:8c:2a:e9:37:56:9c:3b:04:e9:f1:e9:16: 97:cd:d1:97:9c:7c:07:c7:e7:44:0b:9e:4b:4f:e6:9a:19:57: f1:d3:1c:a4:7e:4a:66:00:a5:33:e5:ce:0a:cb:ba:4f:0c:12: 7d:47:b5:aa:8f:be:f0:d2:66:d2:bf:63:a7:80:33:41:ae:6d: 25:fa:59:ec:c0:f1:27:ad:76:82:0a:fb:5d:c3:76:d1:d4:44: 56:6b:a3:df

Output of journalctl -b:

EDIT2:

Output of nvme smart-log /dev/nvme0:

Smart Log for NVME device:nvme0 namespace-id:ffffffff
critical_warning            : 0
temperature             : 40 C (313 Kelvin)
available_spare             : 100%
available_spare_threshold       : 10%
percentage_used             : 1%
endurance group critical warning summary: 0
data_units_read             : 27.013.146
data_units_written          : 11.873.862
host_read_commands          : 482.279.578
host_write_commands         : 178.036.790
controller_busy_time            : 4.854
power_cycles                : 2.022
power_on_hours              : 2.518
unsafe_shutdowns            : 12
media_errors                : 0
num_err_log_entries         : 0
Warning Temperature Time        : 0
Critical Composite Temperature Time : 0
Thermal Management T1 Trans Count   : 0
Thermal Management T2 Trans Count   : 0
Thermal Management T1 Total Time    : 0
Thermal Management T2 Total Time    : 0

EDIT3:

Output of journalctl -k -b -p err:

May 27 11:14:26 whatnext kernel: integrity: Problem loading X.509 certificate -65
May 27 11:39:19 whatnext kernel: [drm:dc_dmub_srv_wait_idle [amdgpu]] *ERROR* Error waiting for DMUB idle: status=3
May 27 12:18:25 whatnext kernel: [drm:dc_dmub_srv_wait_idle [amdgpu]] *ERROR* Error waiting for DMUB idle: status=3

EDIT4:

I disabled "Secre Boot" within BIOS but nothing's changed.

kenn
  • 5,162
  • It would be helpful to post the output of the boot process, including sudo systemd-analyze and sudo systemd-analyze blame (just any key discovers is fine). Also, I'd check the output of sudo journalctl -b, looking for any unusual warnings or errors. – richbl May 25 '23 at 18:55
  • 1
    @richbl thank you for responding. I updated my post. – kenn May 26 '23 at 15:02
  • 1
    Looks like the delay is before starting the kernel. How old is the computer (Bios Battery)? How old is the disk (smartctl) ? – Marco May 27 '23 at 10:46
  • @Marco I bought it 9 months ago. I posted output of nvme smart-log /dev/nvme0. – kenn May 27 '23 at 14:43
  • 1
    https://askubuntu.com/questions/1310107/integrity-problem-loading-x-509-certificate-65-in-ubuntu-20-04 has the integrity notice and that one had a broken hard disk. Might be worth checking the health of your disk https://askubuntu.com/questions/1218700/integrity-problem-loading-x-509-certificate-65 also broken hard disk – Rinzwind May 27 '23 at 15:22
  • 3rd one: https://askubuntu.com/questions/1284756/integrity-problem-loading-x-509-certificate-65-before-login secure boot enabled. disabling it was enough. – Rinzwind May 27 '23 at 15:24
  • @Rinzwind thank you for responding. I had checked some of the links you posted before I posted my question. I haven't tried disabling secure boot yet, because it may compromise safety of my system? – kenn May 27 '23 at 18:47
  • 1
    I would go first to kernel errors at boot, journalctl -k -b -p err. Did you try to boot with a live pendrive; tried to temporarily disable UEFI secure boot, or boot with a previous/older kernel? – Pablo Bianchi May 27 '23 at 18:54
  • 1
    @kenn no secure boot is Microsoft marketing to blame users their system got hacked and it because MS can not fix their product ;-) We Linux users don't need it. – Rinzwind May 27 '23 at 18:55
  • @Rinzwind not everyone think the same way. That being said, probably the OP don't need SB level of safety – Pablo Bianchi May 27 '23 at 19:01
  • @PabloBianchi thank you for the info and the links. They are informative. I updated my question. – kenn May 27 '23 at 20:27
  • I have the same model with Arch Linux(5.19.6 kernel I believe) installed and have the same problem. In first 2–3 months it was starting real fast but after that it got stuck at Lenovo logo for a while. It takes 5 to 10 seconds before the GRUB menu appears, after that it is only another 5 to 15 seconds until the login screen. Secure Boot was always turned off. BIOS is not laggy. systemd-analyze has an additional step for me, firmware which took 18 seconds. 'mokutilreturns nothing.journalctl -kb -p errreturns the same first line, but alsoamdgpu: Secure display: Generic Failure.` 1/2 – Emre Talha May 29 '23 at 20:11
  • And also amdgpu: SECUREDISPLAY: query securedisplay TA failed. ret 0x0. These errors look completely irrelevant for me, but maybe it means something to someone. Correction to the last comment: 5.19.6 was the first kernel that was installed on this laptop. Now I run 6.3.4 and that issue have never changed. 2/2 – Emre Talha May 29 '23 at 20:17
  • It seems strictly related to Lenovo IdeaPad 3. Did you try fwupdmgr --force refresh? – Pablo Bianchi May 30 '23 at 17:06
  • @PabloBianchi Thank you for the suggestion. I tried it, it doesn't work. – kenn May 31 '23 at 19:27

1 Answers1

0

This could be a case of a failed POST (Power On Self Test)

Try reinstalling the BIOS and reset settings to default, as there could be a corrupt configuration file causing the computer to temporarily hang.

If this doesn't work, take it to a repair shop. This isn't a normal occurrence. I'd recommend backing up any important information just in case.

You can find a BIOS update on Lenovo's website here

You can find supporting instructions on how to install the bios here

Nafiu Lawal
  • 870
  • 8
  • 10
  • Thank you for your response. I tried loading the default settings within the BIOS, but unfortunately, it doesn't seem to be working. Could you please provide any additional guidance or suggestions to help resolve this issue? – kenn May 30 '23 at 08:29
  • @kenn I would recommend booting into a Windows partition, as I don't know of any tools that Lenovo has made for Ubuntu or Linux in general. Use that Windows partition to reflash the BIOS/UEFI and reboot. If that doesn't work, take it to a repair shop. – Damian Garcia May 30 '23 at 19:38