"That image is definitely built with UEFI SB stuff included, I've just
double-checked. What error(s) are you seeing?"
Steve,
thanks for the quick reply.
The answer is the typical message "Verifying SBAT shim failed, etc...."
Let me add that with the very same hardware, and software (sha256sum validation, and very reliable Fedora media writer), everything works fine with two other distros Fedora, and the latest Open Suse Leap, both shim-EFI signed.
I also can normally use the very same USB thumb drive, on my other system with Secureboot disabled.
So there is definitely no doubt that there is something wrong with the way the ISO is EFI-shim signed. (debugging this is not so easy!)
I am not exactly a distro hopper, I just need Debian (I used in the past) because of some SW with Debian packages and support only (the Google Flutter Framework)
I also have used Linux since the time of LILO etc....
----
I reiterate here, I cannot disable the Secure Boot (I don't have the BIOS password).
But still use properly signed other live distros's USB etc...
----
Andre