With Xen Orchestra 5.110.1, and fully patched XCP-ng 8.3 hosts in a pool, if I use V2V to import a Windows 2025 VM from vSphere 8 (VM is UEFI with secure boot enabled), the VM will only boot if I disable secure boot. Everything works perfectly after the migration with secure boot disabled, but if I enable it, I get the UEFI interactive shell. I've done "secureboot-certs install" on the pool. When the VM is powered up and at the UEFI shell screen, I have an option on the "advanced" tab to copy the pool's default UEFI certs to the VM (it disappears if the VM is powered off). Selecting this, and rebooting has no effect.
I will admin that I don't have a strong understanding of the internals of secure boot, as it "just works" in VMware, and I've never had to do any troubleshooting of it.
What am I missing? I could open a support request, but I thought maybe someone here would be able to point me in the right direction.
Thanks.
Allen B.