How was this system installed? Was it installed in BIOS mode and then changed to UEFI?
Is shim-signed correctly installed on the system? Without shim-signed installed and present on the ESP partition (/boot/efi/EFI/ubuntu/bootx64.efi); as well as listed as the BootEntry to load (sudo efibootmgr -v will tell), the system will not be able to boot an image recognized as valid by the Microsoft keys that are usually on these systems. ** Changed in: grub2 (Ubuntu) Status: New => Incomplete -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1745740 Title: [Xenial] Update to kernel 4.4.0-112-generic make the system failed to boot with enabled BIOS SecureBoot mode To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/grub2/+bug/1745740/+subscriptions -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs