Secure-Boot auf Leap 16.0 - wie aktivieren

Werner Franke <[email protected]> Wed, 1 Jul 2026 10:06:24 +0200
Newsgroups gmane.linux.suse.general.german
Organization Privat
Message-ID <[email protected]>
Hallo zusammen,

da im Netz das Thema Secure-Boot aktuell ist, weil Zertifikate auslaufen sollen, habe ich mich etwas mit
diesem Thema beschäftigt, auch weil in der c't 2026.13 einige Artikel darüber abgedruckt sind.
Leider sind die Artikel auf Windows PCs gemünzt und wie ich da mit den Linux-Rools die
passenden Informationen bekomme, ist mir nicht so recht klar.
(Aus dem Grund sie eventuell auch einige verwendeten Befehle unten falsch bzw. fehlen)

Bei meinem neuen ASUS Laptop (Nov 2025), auf dem ich Leap 16.0 frisch installiert hatte, habe ich im UEFI-BIOS
nachgeschaut und festgestellt das dort Secure-Boot deaktiviert ist. Das war anscheinend bei Auslieferung
schon so, denn ich hatte da nicht dran geschraubt.
Nach einem Restore der Keys und aktivieren von Secure-Boot kann ich OpenSUSE nicht mehr booten.
Auch ein "fwupdmgr get-updates" und "fwupdmgr update" hat nichts gebracht.

Ich nehme an einige der Keys ist abgelaufen und muss ersetzt werden.
(abgelaufen: bald Key3 (--db) und abgelaufen Key2 (--kek) ??)
Wie aktualisieren?

Vielen dank für Tipps

Werner Franke

Folgende Infos habe ich auf dem ACER zusammengetragen:

mokutil --db
  Key 1: CN=ASUSTeK Notebook SW Key Certificate      2011 bis 2031
  Key 2: CN=ASUSTeK MotherBoard SW Key Certificate   2011 bis 2031
  Key 3: C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2010
                                                     2011 bis 19.10.2026
  Key 4: C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2010
                                                     2013 bis 2035
  Key 5: C=GB, ST=Isle of Man, L=Douglas, O=Canonical Ltd., CN=Canonical Ltd. Master Certificate Authority
                                                     2012 bis 2042

mokutil --kek
  Key 1: CN=ASUSTeK Notebook KEK Certificate         2011 bis 2031
  Key 2: C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Corporation KEK CA 2011
                                                     2011 bis 24.06.2026
  Key 3: C=US, O=Microsoft Corporation, CN=Microsoft RSA Devices Root CA 2021
                                                     2023 bis 2038

mokutil --list-enrolled
  Key 1: CN=SUSE Linux Enterprise Secure Boot CA, C=DE, L=Nuremberg, O=SUSE Linux Products GmbH, OU=Build Team/[email protected]
                                                     2013 bis 2035

sbverify_--list /boot/efi/EFI/opensuse/shim.efi
  signature 1
   image signature issuers:
    - /C=US/ST=Washington/L=Redmond/O=Microsoft Corporation/CN=Microsoft Corporation UEFI CA 2011
   image signature certificates:
    - subject: /C=US/ST=Washington/L=Redmond/O=Microsoft Corporation/CN=Microsoft Windows UEFI Driver Publisher
      issuer:  /C=US/ST=Washington/L=Redmond/O=Microsoft Corporation/CN=Microsoft Corporation UEFI CA 2011
    - subject: /C=US/ST=Washington/L=Redmond/O=Microsoft Corporation/CN=Microsoft Corporation UEFI CA 2011
      issuer:  /C=US/ST=Washington/L=Redmond/O=Microsoft Corporation/CN=Microsoft Corporation Third Party Marketplace Root
  signature 2
   image signature issuers:
    - /C=US/O=Microsoft Corporation/CN=Microsoft UEFI CA 2023
   image signature certificates:
    - subject: /C=US/ST=Washington/L=Redmond/O=Microsoft Corporation/CN=Microsoft UEFI CA 2023 signer
      issuer:  /C=US/O=Microsoft Corporation/CN=Microsoft UEFI CA 2023
    - subject: /C=US/O=Microsoft Corporation/CN=Microsoft UEFI CA 2023
      issuer:  /C=US/O=Microsoft Corporation/CN=Microsoft RSA Devices Root CA 2021
  signature 3
   image signature issuers:
    - /CN=SUSE Linux Enterprise Secure Boot CA/C=DE/L=Nuremberg/O=SUSE Linux Products GmbH/OU=Build Team/[email protected]
   image signature certificates:
    - subject: /CN=SUSE Linux Enterprise Secure Boot Signkey/C=DE/L=Nuremberg/O=SUSE Linux Products GmbH/OU=Build Team/[email protected]
      issuer:  /CN=SUSE Linux Enterprise Secure Boot CA/C=DE/L=Nuremberg/O=SUSE Linux Products GmbH/OU=Build Team/[email protected]

  efi-readvar_-v KEK
   Variable KEK, length 3946
    KEK: List 0, type X509
     Signature 0, size 852, owner 3b053091-6c9f-04cc-b1ac-e2a51e3be5f5
         Subject:
             CN=ASUSTeK Notebook KEK Certificate
         Issuer:
             CN=ASUSTeK Notebook KEK Certificate
    KEK: List 1, type X509
     Signature 0, size 1532, owner 77fa9abd-0359-4d32-bd60-28f4e78f784b
         Subject:
             C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Corporation KEK CA 2011
         Issuer:
             C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Corporation Third Party Marketplace Root
    KEK: List 2, type X509
     Signature 0, size 1478, owner 77fa9abd-0359-4d32-bd60-28f4e78f784b
         Subject:
             C=US, O=Microsoft Corporation, CN=Microsoft Corporation KEK 2K CA 2023
         Issuer:
             C=US, O=Microsoft Corporation, CN=Microsoft RSA Devices Root CA 2021