Score:2

Lenovo IdeaPad 3 15ALC6 BIOS screen hangs fifteen seconds on boot

in flag

I am running Ubuntu 22.04 with the Mate desktop. Yesterday, when I returned to my desk, the laptop screen was black. I clicked the mouse, but it didn't wake up. I thought it was frozen, so I performed a hard reset by pressing the power button for five seconds. Afterward, I noticed that it was lagging and getting stuck at the BIOS logo for a while during boot. The day before, I had upgraded the kernel to:

uname -a
Linux whatnext 5.15.0-72-generic #79-Ubuntu SMP Wed Apr 19 08:22:18 UTC 2023 x86_64 x86_64 x86_64 GNU/Linux

Despite the lagging at the BIOS, the system eventually boots and runs well.

I also noticed an error in the log, but it was there for a long time, so I believe it is unrelated:

Loading X.509 certificate: UEFI:db
[    0.834706] integrity: Problem loading X.509 certificate -65
[    0.834710] fbcon: Taking over console

Would you please assist me?

EDIT:

Output of systemd-analyze:

Startup finished in 3.051s (kernel) + 9.435s (userspace) = 12.487s 
graphical.target reached after 9.208s in userspace

Output of systemd-analyze blame:

6.028s NetworkManager-wait-online.service
2.368s snapd.service
1.807s snapd.seeded.service
1.494s networkd-dispatcher.service
1.479s [email protected]
1.075s systemd-resolved.service
1.042s xrdp.service
 745ms ufw.service
 525ms netfilter-persistent.service
 414ms blueman-mechanism.service
 335ms dev-nvme0n1p2.device
 291ms binfmt-support.service
 265ms php8.1-fpm.service
 252ms snapd.apparmor.service
 240ms udisks2.service
 225ms tlp.service
 218ms apport-autoreport.service
 213ms upower.service
 202ms accounts-daemon.service
 195ms avahi-daemon.service
 193ms bluetooth.service
 192ms apparmor.service
 180ms lightdm.service
 180ms polkit.service
 180ms dev-loop23.device
 180ms dev-loop25.device
 179ms power-profiles-daemon.service
 178ms dev-loop24.device
 178ms dev-loop29.device
 177ms dev-loop17.device
 176ms plymouth-quit-wait.service
 175ms dev-loop28.device
 174ms dev-loop19.device
 173ms dev-loop31.device
 172ms phpsessionclean.service
 171ms dev-loop22.device
 170ms dev-loop20.device
 170ms dev-loop21.device
 168ms dev-loop30.device
 167ms dev-loop16.device
 166ms dev-loop12.device
 164ms systemd-udev-trigger.service
 164ms dev-loop15.device
 163ms dev-loop10.device
 161ms dev-loop13.device
 160ms suricata.service
 159ms switcheroo-control.service
 159ms [email protected]
 157ms dev-loop26.device
 155ms thermald.service
 155ms dns-clean.service
 154ms systemd-logind.service
 154ms gpu-manager.service
 153ms dev-loop14.device
 153ms apport.service
 152ms wpa_supplicant.service
 149ms dev-loop5.device
 148ms snap.upnp-server.webdav.service
 146ms dev-loop6.device
 145ms dev-loop7.device
 144ms dev-loop2.device
 143ms dev-loop11.device
 143ms winbind.service
 143ms dev-loop1.device
 143ms dev-loop0.device
 140ms dev-loop8.device
 140ms secureboot-db.service
 135ms dev-loop9.device
 131ms grub-common.service
 128ms dev-loop27.device
 126ms dev-loop4.device
 125ms smartmontools.service
 118ms dev-loop18.device
 114ms dev-loop3.device
 114ms systemd-journald.service
 114ms systemd-timesyncd.service
 104ms systemd-oomd.service
 101ms virtualbox.service
  98ms mini-httpd.service
  97ms console-setup.service
  90ms systemd-tmpfiles-setup.service
  88ms apache2.service
  87ms lm-sensors.service
  80ms ModemManager.service
  79ms modprobe@chromeos_pstore.service
  78ms update-notifier-download.service
  77ms rsyslog.service
  72ms e2scrub_reap.service
  64ms proc-sys-fs-binfmt_misc.mount
  64ms systemd-udevd.service
  64ms bluez-alsa.service
  62ms snap-alfacast-44.mount
  61ms snap-android\x2dstudio-126.mount
  56ms snap-arduino-85.mount
  55ms snap-bare-5.mount
  54ms snap-chromium-2477.mount
  53ms cups.service
  53ms snap-chromium\x2dffmpeg-30.mount
  51ms networking.service
  51ms snap-code-129.mount
  50ms plymouth-read-write.service
  50ms systemd-networkd.service
  49ms snap-core-14946.mount
  48ms snap-core18-2745.mount
  47ms NetworkManager.service
  47ms snap-core20-1891.mount
  46ms keyboard-setup.service
  45ms kerneloops.service
  44ms snap-core22-634.mount
  42ms snap-cups-872.mount
  41ms netperf.service
  41ms snap-firefox-2667.mount
  41ms snap-firefox-2710.mount
  41ms systemd-journal-flush.service
  40ms snap-flutter-130.mount
  39ms snap-gnome\x2d3\x2d28\x2d1804-198.mount
  38ms snap-gnome\x2d3\x2d38\x2d2004-140.mount
  37ms snap-gnome\x2d42\x2d2204-102.mount
  36ms snap-gtk2\x2dcommon\x2dthemes-13.mount
  35ms systemd-fsck@dev-disk-by\x2duuid-1AD1\x2d6070.service
  35ms snap-gtk\x2dcommon\x2dthemes-1535.mount
  34ms snap-guiscrcpy-256.mount
  33ms ssh.service
  33ms vtun.service
  32ms snap-onlyoffice\x2ddesktopeditors-147.mount
  31ms snap-p7zip\x2ddesktop-220.mount
  30ms nscd.service
  29ms snap-pycharm\x2dcommunity-332.mount
  28ms snap-qt515\x2dcore20-28.mount
  27ms snap-scrcpy-399.mount
  27ms nvmf-autoconnect.service
  26ms snap-snapd-19122.mount
  25ms systemd-modules-load.service
  24ms openvpn.service
  24ms snap-snapd\x2ddesktop\x2dintegration-83.mount
  23ms boot-efi.mount
  23ms snap-spotify-67.mount
  22ms plymouth-start.service
  22ms conky-refresh.service
  21ms snap-sublime\x2dtext-118.mount
  20ms snap-upnp\x2dserver-1.mount
  19ms dev-hugepages.mount
  19ms dev-mqueue.mount
  19ms snap-whatsie-146.mount
  18ms sys-kernel-debug.mount
  18ms grub-initrd-fallback.service
  18ms sys-kernel-tracing.mount
  18ms tmp.mount
  17ms atd.service
  15ms var-snap-firefox-common-host\x2dhunspell.mount
  15ms kmod-static-nodes.service
  15ms systemd-sysusers.service
  14ms [email protected]
  13ms [email protected]
  12ms xrdp-sesman.service
  12ms [email protected]
  11ms systemd-tmpfiles-setup-dev.service
  10ms setvtrgb.service
  10ms alsa-restore.service
  10ms systemd-user-sessions.service
   9ms systemd-random-seed.service
   8ms systemd-sysctl.service
   8ms systemd-update-utmp.service
   7ms [email protected]
   7ms systemd-network-generator.service
   6ms systemd-backlight@backlight:amdgpu_bl0.service
   6ms systemd-remount-fs.service
   5ms swapfile.swap
   5ms systemd-update-utmp-runlevel.service
   4ms systemd-networkd-wait-online.service
   4ms modprobe@efi_pstore.service
   4ms modprobe@pstore_blk.service
   3ms modprobe@pstore_zone.service
   3ms sys-fs-fuse-connections.mount
   3ms rtkit-daemon.service
   3ms ifupdown-pre.service
   2ms sys-kernel-config.mount
   2ms [email protected]
   1ms postfix.service
 683us snapd.socket

Output of mokutil --list-enrolled:

[key 1]
SHA1 Fingerprint: 76:a0:92:06:58:00:bf:37:69:01:c3:72:cd:55:a9:0e:1f:de:d2:e0
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            b9:41:24:a0:18:2c:92:67
        Signature Algorithm: sha256WithRSAEncryption
        Issuer: C=GB, ST=Isle of Man, L=Douglas, O=Canonical Ltd., CN=Canonical Ltd. Master Certificate Authority
        Validity
            Not Before: Apr 12 11:12:51 2012 GMT
            Not After : Apr 11 11:12:51 2042 GMT
        Subject: C=GB, ST=Isle of Man, L=Douglas, O=Canonical Ltd., CN=Canonical Ltd. Master Certificate Authority
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (2048 bit)
                Modulus:
                    00:bf:5b:3a:16:74:ee:21:5d:ae:61:ed:9d:56:ac:
                    bd:de:de:72:f3:dd:7e:2d:4c:62:0f:ac:c0:6d:48:
                    08:11:cf:8d:8b:fb:61:1f:27:cc:11:6e:d9:55:3d:
                    39:54:eb:40:3b:b1:bb:e2:85:34:79:ca:f7:7b:bf:
                    ba:7a:c8:10:2d:19:7d:ad:59:cf:a6:d4:e9:4e:0f:
                    da:ae:52:ea:4c:9e:90:ce:c6:99:0d:4e:67:65:78:
                    5d:f9:d1:d5:38:4a:4a:7a:8f:93:9c:7f:1a:a3:85:
                    db:ce:fa:8b:f7:c2:a2:21:2d:9b:54:41:35:10:57:
                    13:8d:6c:bc:29:06:50:4a:7e:ea:99:a9:68:a7:3b:
                    c7:07:1b:32:9e:a0:19:87:0e:79:bb:68:99:2d:7e:
                    93:52:e5:f6:eb:c9:9b:f9:2b:ed:b8:68:49:bc:d9:
                    95:50:40:5b:c5:b2:71:aa:eb:5c:57:de:71:f9:40:
                    0a:dd:5b:ac:1e:84:2d:50:1a:52:d6:e1:f3:6b:6e:
                    90:64:4f:5b:b4:eb:20:e4:61:10:da:5a:f0:ea:e4:
                    42:d7:01:c4:fe:21:1f:d9:b9:c0:54:95:42:81:52:
                    72:1f:49:64:7a:c8:6c:24:f1:08:70:0b:4d:a5:a0:
                    32:d1:a0:1c:57:a8:4d:e3:af:a5:8e:05:05:3e:10:
                    43:a1
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Subject Key Identifier: 
                AD:91:99:0B:C2:2A:B1:F5:17:04:8C:23:B6:65:5A:26:8E:34:5A:63
            X509v3 Authority Key Identifier: 
                AD:91:99:0B:C2:2A:B1:F5:17:04:8C:23:B6:65:5A:26:8E:34:5A:63
            X509v3 Basic Constraints: critical
                CA:TRUE
            X509v3 Key Usage: 
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 CRL Distribution Points: 
                Full Name:
                  URI:http://www.canonical.com/secure-boot-master-ca.crl
    Signature Algorithm: sha256WithRSAEncryption
    Signature Value:
        3f:7d:f6:76:a5:b3:83:b4:2b:7a:d0:6d:52:1a:03:83:c4:12:
        a7:50:9c:47:92:cc:c0:94:77:82:d2:ae:57:b3:99:04:f5:32:
        3a:c6:55:1d:07:db:12:a9:56:fa:d8:d4:76:20:eb:e4:c3:51:
        db:9a:5c:9c:92:3f:18:73:da:94:6a:a1:99:38:8c:a4:88:6d:
        c1:fc:39:71:d0:74:76:16:03:3e:56:23:35:d5:55:47:5b:1a:
        1d:41:c2:d3:12:4c:dc:ff:ae:0a:92:9c:62:0a:17:01:9c:73:
        e0:5e:b1:fd:bc:d6:b5:19:11:7a:7e:cd:3e:03:7e:66:db:5b:
        a8:c9:39:48:51:ff:53:e1:9c:31:53:91:1b:3b:10:75:03:17:
        ba:e6:81:02:80:94:70:4c:46:b7:94:b0:3d:15:cd:1f:8e:02:
        e0:68:02:8f:fb:f9:47:1d:7d:a2:01:c6:07:51:c4:9a:cc:ed:
        dd:cf:a3:5d:ed:92:bb:be:d1:fd:e6:ec:1f:33:51:73:04:be:
        3c:72:b0:7d:08:f8:01:ff:98:7d:cb:9c:e0:69:39:77:25:47:
        71:88:b1:8d:27:a5:2e:a8:f7:3f:5f:80:69:97:3e:a9:f4:99:
        14:db:ce:03:0e:0b:66:c4:1c:6d:bd:b8:27:77:c1:42:94:bd:
        fc:6a:0a:bc

[key 2]
SHA1 Fingerprint: ed:b0:b4:c8:15:c7:cd:09:1d:ea:c6:62:02:29:2f:e8:49:3c:08:80
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            02:8a:4d:05:27:66:63:cc:be:3a:cd:fd:5f:b3:9d:98:23:23:7a:a9
        Signature Algorithm: sha256WithRSAEncryption
        Issuer: CN=kenn-IdeaPad-3-15ALC6 Secure Boot Module Signature key
        Validity
            Not Before: Sep  5 09:44:05 2022 GMT
            Not After : Aug 12 09:44:05 2122 GMT
        Subject: CN=kenn-IdeaPad-3-15ALC6 Secure Boot Module Signature key
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (2048 bit)
                Modulus:
                    00:be:c5:2f:36:3f:bf:c9:93:9a:26:2b:c2:fa:04:
                    5a:f3:e3:57:12:dd:65:a3:ba:43:12:c4:bb:ff:f6:
                    31:d1:10:15:22:88:27:64:7d:03:dc:3d:8b:d4:ed:
                    43:d2:90:1c:cf:9b:78:8f:43:f8:fe:22:e3:0a:ad:
                    bf:c6:41:61:0d:f7:c7:d2:18:5f:01:ad:88:11:e9:
                    f1:90:4e:ae:85:e2:4b:79:07:71:19:38:64:97:b2:
                    66:00:a4:c1:c2:f3:7b:16:f5:61:62:c0:ee:5f:3d:
                    22:1a:af:4c:1c:d1:85:f5:4d:47:b1:88:ec:7a:4f:
                    e1:dc:36:3a:02:f1:d8:d0:31:dd:b2:01:fa:7e:3a:
                    f7:16:54:5c:b8:9a:1d:29:39:25:2e:89:45:b4:26:
                    2e:67:73:90:bc:2b:87:21:c9:6c:62:56:f4:6a:ac:
                    4a:c3:c4:4a:d5:0d:ce:49:f2:ec:63:ac:95:9d:46:
                    84:db:8d:81:44:6b:df:f0:cd:3d:f9:56:3d:a7:4b:
                    69:39:b0:ca:00:08:0f:74:ce:d4:85:6c:74:2f:57:
                    6e:93:48:b2:f1:cc:00:a8:15:38:56:47:1b:f6:a1:
                    5e:b9:d2:4d:c9:b1:0b:c9:16:e1:97:f8:9f:92:c7:
                    f4:be:a1:e0:73:6c:03:95:df:b0:a7:d4:a4:39:d4:
                    fe:39
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Subject Key Identifier: 
                59:3A:5A:DA:59:A3:8C:EA:7F:1A:03:3B:C4:0F:FD:D9:54:7D:ED:62
            X509v3 Authority Key Identifier: 
                59:3A:5A:DA:59:A3:8C:EA:7F:1A:03:3B:C4:0F:FD:D9:54:7D:ED:62
            X509v3 Basic Constraints: critical
                CA:FALSE
            X509v3 Extended Key Usage: 
                Code Signing, 1.3.6.1.4.1.2312.16.1.2
            Netscape Comment: 
                OpenSSL Generated Certificate
    Signature Algorithm: sha256WithRSAEncryption
    Signature Value:
        02:39:87:80:9a:f7:e7:27:34:58:7a:86:18:76:6f:5f:bf:a6:
        3e:3e:31:fb:80:75:47:ba:b4:2c:3d:bb:cf:29:8e:fc:32:25:
        52:95:a0:2f:86:25:8d:df:bf:fd:d1:61:f4:fd:1f:99:33:19:
        df:c8:fd:a3:fe:b3:fe:51:07:91:c8:10:c9:39:49:2a:c8:a6:
        e9:82:ae:80:0b:ed:2a:77:d5:a8:7e:d0:a5:c1:ba:1d:c6:41:
        cc:1f:4a:b5:73:20:b1:af:42:72:d1:52:e7:e1:c3:72:fb:78:
        f3:e4:fa:12:1e:b9:1c:02:f6:66:22:89:53:ec:d6:d7:0c:c0:
        8e:c9:d5:fa:49:1f:b8:b3:3c:74:ae:0a:fb:03:7d:4c:43:ce:
        b3:f7:11:35:7c:5c:a0:32:9a:61:c3:d8:6b:56:d1:75:58:39:
        40:04:58:91:32:f7:8c:2a:e9:37:56:9c:3b:04:e9:f1:e9:16:
        97:cd:d1:97:9c:7c:07:c7:e7:44:0b:9e:4b:4f:e6:9a:19:57:
        f1:d3:1c:a4:7e:4a:66:00:a5:33:e5:ce:0a:cb:ba:4f:0c:12:
        7d:47:b5:aa:8f:be:f0:d2:66:d2:bf:63:a7:80:33:41:ae:6d:
        25:fa:59:ec:c0:f1:27:ad:76:82:0a:fb:5d:c3:76:d1:d4:44:
        56:6b:a3:df

Output of journalctl -b:

EDIT2:

Output of nvme smart-log /dev/nvme0:

Smart Log for NVME device:nvme0 namespace-id:ffffffff
critical_warning            : 0
temperature             : 40 C (313 Kelvin)
available_spare             : 100%
available_spare_threshold       : 10%
percentage_used             : 1%
endurance group critical warning summary: 0
data_units_read             : 27.013.146
data_units_written          : 11.873.862
host_read_commands          : 482.279.578
host_write_commands         : 178.036.790
controller_busy_time            : 4.854
power_cycles                : 2.022
power_on_hours              : 2.518
unsafe_shutdowns            : 12
media_errors                : 0
num_err_log_entries         : 0
Warning Temperature Time        : 0
Critical Composite Temperature Time : 0
Thermal Management T1 Trans Count   : 0
Thermal Management T2 Trans Count   : 0
Thermal Management T1 Total Time    : 0
Thermal Management T2 Total Time    : 0

EDIT3:

Output of journalctl -k -b -p err:

May 27 11:14:26 whatnext kernel: integrity: Problem loading X.509 certificate -65
May 27 11:39:19 whatnext kernel: [drm:dc_dmub_srv_wait_idle [amdgpu]] *ERROR* Error waiting for DMUB idle: status=3
May 27 12:18:25 whatnext kernel: [drm:dc_dmub_srv_wait_idle [amdgpu]] *ERROR* Error waiting for DMUB idle: status=3

EDIT4:

I disabled "Secre Boot" within BIOS but nothing's changed.

ec flag
It would be helpful to post the output of the boot process, including `sudo systemd-analyze` and `sudo systemd-analyze blame` (just any key discovers is fine). Also, I'd check the output of `sudo journalctl -b`, looking for any unusual warnings or errors.
in flag
@richbl thank you for responding. I updated my post.
Marco avatar
br flag
Looks like the delay is before starting the kernel. How old is the computer (Bios Battery)? How old is the disk (smartctl) ?
in flag
@Marco I bought it 9 months ago. I posted output of `nvme smart-log /dev/nvme0`.
cn flag
https://askubuntu.com/questions/1310107/integrity-problem-loading-x-509-certificate-65-in-ubuntu-20-04 has the integrity notice and that one had a broken hard disk. Might be worth checking the health of your disk https://askubuntu.com/questions/1218700/integrity-problem-loading-x-509-certificate-65 also broken hard disk
cn flag
3rd one: https://askubuntu.com/questions/1284756/integrity-problem-loading-x-509-certificate-65-before-login secure boot enabled. disabling it was enough.
in flag
@Rinzwind thank you for responding. I had checked some of the links you posted before I posted my question. I haven't tried `disabling secure boot` yet, because it may compromise safety of my system?
vn flag
I would go first to kernel errors at boot, `journalctl -k -b -p err`. Did you try to boot with a live pendrive; tried to temporarily disable UEFI secure boot, or boot with a previous/older kernel?
cn flag
@kenn no secure boot is Microsoft marketing to blame users their system got hacked and it because MS can not fix their product ;-) We Linux users don't need it.
vn flag
@Rinzwind [not everyone think the same way](https://wiki.debian.org/SecureBoot#What_is_UEFI_Secure_Boot_NOT.3F). That being said, probably the OP don't need SB level of safety
in flag
@PabloBianchi thank you for the info and the links. They are informative. I updated my question.
Emre Talha avatar
ar flag
I have the same model with Arch Linux(5.19.6 kernel I believe) installed and have the same problem. In first 2–3 months it was starting real fast but after that it got stuck at Lenovo logo for a while. It takes 5 to 10 seconds before the GRUB menu appears, after that it is only another 5 to 15 seconds until the login screen. Secure Boot was always turned off. BIOS is not laggy. `systemd-analyze` has an additional step for me, firmware which took 18 seconds. 'mokutil` returns nothing. `journalctl -kb -p err` returns the same first line, but also `amdgpu: Secure display: Generic Failure.` 1/2
Emre Talha avatar
ar flag
And also `amdgpu: SECUREDISPLAY: query securedisplay TA failed. ret 0x0`. These errors look completely irrelevant for me, but maybe it means something to someone. Correction to the last comment: 5.19.6 was the first kernel that was installed on this laptop. Now I run 6.3.4 and that issue have never changed. 2/2
vn flag
It seems strictly related to [Lenovo IdeaPad 3](https://bugs.launchpad.net/ubuntu/+source/linux/+bug/1930783/comments/13). Did you try [`fwupdmgr --force refresh`](https://askubuntu.com/a/1355708/349837)?
in flag
@PabloBianchi Thank you for the suggestion. I tried it, it doesn't work.
Score:0
kp flag

This could be a case of a failed POST (Power On Self Test)

Try reinstalling the BIOS and reset settings to default, as there could be a corrupt configuration file causing the computer to temporarily hang.

If this doesn't work, take it to a repair shop. This isn't a normal occurrence. I'd recommend backing up any important information just in case.

You can find a BIOS update on Lenovo's website here

You can find supporting instructions on how to install the bios here

in flag
Thank you for your response. I tried loading the default settings within the BIOS, but unfortunately, it doesn't seem to be working. Could you please provide any additional guidance or suggestions to help resolve this issue?
Damian Garcia avatar
kp flag
@kenn I would recommend booting into a Windows partition, as I don't know of any tools that Lenovo has made for Ubuntu or Linux in general. Use that Windows partition to reflash the BIOS/UEFI and reboot. If that doesn't work, take it to a repair shop.
I sit in a Tesla and translated this thread with Ai:

mangohost

Post an answer

Most people don’t grasp that asking a lot of questions unlocks learning and improves interpersonal bonding. In Alison’s studies, for example, though people could accurately recall how many questions had been asked in their conversations, they didn’t intuit the link between questions and liking. Across four studies, in which participants were engaged in conversations themselves or read transcripts of others’ conversations, people tended not to realize that question asking would influence—or had influenced—the level of amity between the conversationalists.