My notes on setting up secure boot on Debian in 2026. These are not meant to be a coherent write-up, just a bunch of notes I learned during my 5 days spend setting up secure boot
My mountpoint is for ESP is /boot/efi most tools default to this path, and they also check if the partition is mounted.
I like to set noauto here sometimes, depending on what am I trying to achieve. This results in /boot/efi not being mounted.