How to Enable Secure Boot on Omarchy (Arch Linux) with Limine and sbctl, Including Legacy BIOS/MBR to UEFI/GPT Conversion Without Reinstalling
A tested, step-by-step guide to enabling UEFI Secure Boot on Omarchy (the Arch Linux + Hyprland setup) that uses the Limine bootloader, sbctl custom keys, signed Unified Kernel Images (UKIs) and Limine config enrollment (BLAKE2B checksum), with LUKS full-disk encryption and btrfs + Snapper snapshots kept working.
It also covers a case most Secure Boot guides skip: Omarchy installed in legacy BIOS mode on an MBR (dos) disk. Secure Boot needs UEFI, so the guide first converts the install to UEFI on GPT in place, without reinstalling or losing data.
Builds on the community guide in omacom/omarchy discussion #2296, which assumes you already boot in UEFI mode.
Tested on: Acer Swift 3 SF314-52 (Insyde H2O firmware) · Omarchy · Limine 12.8 · limine-mkinitcpio-hook 1.38 · limi