Secure-Boot auf Leap 16.0 - wie aktivieren
Werner Franke <[email protected]> Wed, 1 Jul 2026 10:06:24 +0200
| Newsgroups | gmane.linux.suse.general.german |
|---|---|
| Organization | Privat |
| Message-ID | <[email protected]> |
Hallo zusammen,
da im Netz das Thema Secure-Boot aktuell ist, weil Zertifikate auslaufen sollen, habe ich mich etwas mit
diesem Thema beschäftigt, auch weil in der c't 2026.13 einige Artikel darüber abgedruckt sind.
Leider sind die Artikel auf Windows PCs gemünzt und wie ich da mit den Linux-Rools die
passenden Informationen bekomme, ist mir nicht so recht klar.
(Aus dem Grund sie eventuell auch einige verwendeten Befehle unten falsch bzw. fehlen)
Bei meinem neuen ASUS Laptop (Nov 2025), auf dem ich Leap 16.0 frisch installiert hatte, habe ich im UEFI-BIOS
nachgeschaut und festgestellt das dort Secure-Boot deaktiviert ist. Das war anscheinend bei Auslieferung
schon so, denn ich hatte da nicht dran geschraubt.
Nach einem Restore der Keys und aktivieren von Secure-Boot kann ich OpenSUSE nicht mehr booten.
Auch ein "fwupdmgr get-updates" und "fwupdmgr update" hat nichts gebracht.
Ich nehme an einige der Keys ist abgelaufen und muss ersetzt werden.
(abgelaufen: bald Key3 (--db) und abgelaufen Key2 (--kek) ??)
Wie aktualisieren?
Vielen dank für Tipps
Werner Franke
Folgende Infos habe ich auf dem ACER zusammengetragen:
mokutil --db
Key 1: CN=ASUSTeK Notebook SW Key Certificate 2011 bis 2031
Key 2: CN=ASUSTeK MotherBoard SW Key Certificate 2011 bis 2031
Key 3: C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2010
2011 bis 19.10.2026
Key 4: C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2010
2013 bis 2035
Key 5: C=GB, ST=Isle of Man, L=Douglas, O=Canonical Ltd., CN=Canonical Ltd. Master Certificate Authority
2012 bis 2042
mokutil --kek
Key 1: CN=ASUSTeK Notebook KEK Certificate 2011 bis 2031
Key 2: C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Corporation KEK CA 2011
2011 bis 24.06.2026
Key 3: C=US, O=Microsoft Corporation, CN=Microsoft RSA Devices Root CA 2021
2023 bis 2038
mokutil --list-enrolled
Key 1: CN=SUSE Linux Enterprise Secure Boot CA, C=DE, L=Nuremberg, O=SUSE Linux Products GmbH, OU=Build Team/[email protected]
2013 bis 2035
sbverify_--list /boot/efi/EFI/opensuse/shim.efi
signature 1
image signature issuers:
- /C=US/ST=Washington/L=Redmond/O=Microsoft Corporation/CN=Microsoft Corporation UEFI CA 2011
image signature certificates:
- subject: /C=US/ST=Washington/L=Redmond/O=Microsoft Corporation/CN=Microsoft Windows UEFI Driver Publisher
issuer: /C=US/ST=Washington/L=Redmond/O=Microsoft Corporation/CN=Microsoft Corporation UEFI CA 2011
- subject: /C=US/ST=Washington/L=Redmond/O=Microsoft Corporation/CN=Microsoft Corporation UEFI CA 2011
issuer: /C=US/ST=Washington/L=Redmond/O=Microsoft Corporation/CN=Microsoft Corporation Third Party Marketplace Root
signature 2
image signature issuers:
- /C=US/O=Microsoft Corporation/CN=Microsoft UEFI CA 2023
image signature certificates:
- subject: /C=US/ST=Washington/L=Redmond/O=Microsoft Corporation/CN=Microsoft UEFI CA 2023 signer
issuer: /C=US/O=Microsoft Corporation/CN=Microsoft UEFI CA 2023
- subject: /C=US/O=Microsoft Corporation/CN=Microsoft UEFI CA 2023
issuer: /C=US/O=Microsoft Corporation/CN=Microsoft RSA Devices Root CA 2021
signature 3
image signature issuers:
- /CN=SUSE Linux Enterprise Secure Boot CA/C=DE/L=Nuremberg/O=SUSE Linux Products GmbH/OU=Build Team/[email protected]
image signature certificates:
- subject: /CN=SUSE Linux Enterprise Secure Boot Signkey/C=DE/L=Nuremberg/O=SUSE Linux Products GmbH/OU=Build Team/[email protected]
issuer: /CN=SUSE Linux Enterprise Secure Boot CA/C=DE/L=Nuremberg/O=SUSE Linux Products GmbH/OU=Build Team/[email protected]
efi-readvar_-v KEK
Variable KEK, length 3946
KEK: List 0, type X509
Signature 0, size 852, owner 3b053091-6c9f-04cc-b1ac-e2a51e3be5f5
Subject:
CN=ASUSTeK Notebook KEK Certificate
Issuer:
CN=ASUSTeK Notebook KEK Certificate
KEK: List 1, type X509
Signature 0, size 1532, owner 77fa9abd-0359-4d32-bd60-28f4e78f784b
Subject:
C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Corporation KEK CA 2011
Issuer:
C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Corporation Third Party Marketplace Root
KEK: List 2, type X509
Signature 0, size 1478, owner 77fa9abd-0359-4d32-bd60-28f4e78f784b
Subject:
C=US, O=Microsoft Corporation, CN=Microsoft Corporation KEK 2K CA 2023
Issuer:
C=US, O=Microsoft Corporation, CN=Microsoft RSA Devices Root CA 2021