Re: Secure-Boot auf Leap 16.0 - wie aktivieren
Marcus Meissner <[email protected]> Wed, 1 Jul 2026 19:54:10 +0000
| Newsgroups | gmane.linux.suse.general.german |
|---|---|
| Organization | SUSE Software Solutions Ger many GmbH, Frankenstraße 146, 90461 Nuernberg, Ger many, GF: Ivo Totev, Andrew Myers, Andrew McDonald , Martje Boudien Moerman, HRB 36809, AG Nürnberg |
| Message-ID | <[email protected]> |
Hi, Ok, ist das Paket shim installiert? Wenn nicht, bitte mal installieren. Ich vermute es ist nicht installiert... Ciao, Marcus On Wed, Jul 01, 2026 at 06:12:33PM +0200, Werner Franke wrote: > Hallo Marcus, Stephan, alle, > > Der Laptop startet mit UEFI boot setup. > Es ist ein ASUS EXPERTBOOK BM 1, der hat kein Legacy-BIOS und auch kein Compatibility Support Module. > Ich habe im BIOS jedenfalls nichts dazu gefunden. > > (im Gegensatz zu meinem Desktop PC :-( ) > > Wenn ich Secure Boot im ASUS aktiviere, kommt beim Boot ein roter Bildschirm mit dem Hinweis > > Secure Boot Violation > > Invalid signature detected. Check Secure Boot Policy in Setup > > Wird bei der Installation des neuen Leap 16.0 auch alle notwendigen > Secure-Boot Teile mit installiert, auch wenn Secure-Boot zu dem Zeitpunkt deaktiviert ist ? > Im BIOS Boot-Menü wird die System-Partition mit "opensuse-secureboot" angezeigt. > Eine weitere Partition ist nicht vorhanden. > > @Stephan, > Einen openSUSE Key habe ich nicht explizit installiert. > Wenn ich die Keys unten richtig interpretiere, ist bei "mokutil --list-enrolled" > ein "SUSE Linux Enterprise Secure Boot CA" mit langem Ablaufdatum installiert. > > Ich habe gestern, 31.06.26 erstmalig auf dem Laptop an dem Secure-Boot Zeugs > herumprobiert. Hat da der Fall "Zertifikate ausgelaufen" schon zugeschlagen ? > > Der "CN=Microsoft Corporation KEK CA 2011", der am 24.06.2026 abgelaufen ist. > > liebe Grüße > Werner > > Am 01.07.26 um 11:50 schrieb Marcus Meissner: > > Hi, > > > > Secure boot braucht normalerweise ein UEFI boot setup. Wenn das System > > noch in "traditional BIOS" mode ist, muss neu installiert werden zuerst. > > > > AUch wenn es in UEFI boot mode ist, kann sein das unser shim nicht in > > der Boot Reihenfolge wenn es ohne secure boot installiert wurde. > > > > Also am ehesten muss neu installiert werden muessen. > > > > Ciao, Marcus > > On Wed, Jul 01, 2026 at 10:06:24AM +0200, Werner Franke wrote: > > > Hallo zusammen, > > > > > > da im Netz das Thema Secure-Boot aktuell ist, weil Zertifikate auslaufen sollen, habe ich mich etwas mit > > > diesem Thema besch�ftigt, auch weil in der c't 2026.13 einige Artikel dar�ber abgedruckt sind. > > > Leider sind die Artikel auf Windows PCs gem�nzt und wie ich da mit den Linux-Rools die > > > passenden Informationen bekomme, ist mir nicht so recht klar. > > > (Aus dem Grund sie eventuell auch einige verwendeten Befehle unten falsch bzw. fehlen) > > > > > > Bei meinem neuen ASUS Laptop (Nov 2025), auf dem ich Leap 16.0 frisch installiert hatte, habe ich im UEFI-BIOS > > > nachgeschaut und festgestellt das dort Secure-Boot deaktiviert ist. Das war anscheinend bei Auslieferung > > > schon so, denn ich hatte da nicht dran geschraubt. > > > Nach einem Restore der Keys und aktivieren von Secure-Boot kann ich OpenSUSE nicht mehr booten. > > > Auch ein "fwupdmgr get-updates" und "fwupdmgr update" hat nichts gebracht. > > > > > > Ich nehme an einige der Keys ist abgelaufen und muss ersetzt werden. > > > (abgelaufen: bald Key3 (--db) und abgelaufen Key2 (--kek) ??) > > > Wie aktualisieren? > > > > > > Vielen dank f�r Tipps > > > > > > Werner Franke > > > > > > Folgende Infos habe ich auf dem ACER zusammengetragen: > > > > > > mokutil --db > > > Key 1: CN=ASUSTeK Notebook SW Key Certificate 2011 bis 2031 > > > Key 2: CN=ASUSTeK MotherBoard SW Key Certificate 2011 bis 2031 > > > Key 3: C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2010 > > > 2011 bis 19.10.2026 > > > Key 4: C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2010 > > > 2013 bis 2035 > > > Key 5: C=GB, ST=Isle of Man, L=Douglas, O=Canonical Ltd., CN=Canonical Ltd. Master Certificate Authority > > > 2012 bis 2042 > > > > > > mokutil --kek > > > Key 1: CN=ASUSTeK Notebook KEK Certificate 2011 bis 2031 > > > Key 2: C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Corporation KEK CA 2011 > > > 2011 bis 24.06.2026 > > > Key 3: C=US, O=Microsoft Corporation, CN=Microsoft RSA Devices Root CA 2021 > > > 2023 bis 2038 > > > > > > mokutil --list-enrolled > > > Key 1: CN=SUSE Linux Enterprise Secure Boot CA, C=DE, L=Nuremberg, O=SUSE Linux Products GmbH, OU=Build Team/[email protected] > > > 2013 bis 2035 > > > > > > sbverify_--list /boot/efi/EFI/opensuse/shim.efi > > > signature 1 > > > image signature issuers: > > > - /C=US/ST=Washington/L=Redmond/O=Microsoft Corporation/CN=Microsoft Corporation UEFI CA 2011 > > > image signature certificates: > > > - subject: /C=US/ST=Washington/L=Redmond/O=Microsoft Corporation/CN=Microsoft Windows UEFI Driver Publisher > > > issuer: /C=US/ST=Washington/L=Redmond/O=Microsoft Corporation/CN=Microsoft Corporation UEFI CA 2011 > > > - subject: /C=US/ST=Washington/L=Redmond/O=Microsoft Corporation/CN=Microsoft Corporation UEFI CA 2011 > > > issuer: /C=US/ST=Washington/L=Redmond/O=Microsoft Corporation/CN=Microsoft Corporation Third Party Marketplace Root > > > signature 2 > > > image signature issuers: > > > - /C=US/O=Microsoft Corporation/CN=Microsoft UEFI CA 2023 > > > image signature certificates: > > > - subject: /C=US/ST=Washington/L=Redmond/O=Microsoft Corporation/CN=Microsoft UEFI CA 2023 signer > > > issuer: /C=US/O=Microsoft Corporation/CN=Microsoft UEFI CA 2023 > > > - subject: /C=US/O=Microsoft Corporation/CN=Microsoft UEFI CA 2023 > > > issuer: /C=US/O=Microsoft Corporation/CN=Microsoft RSA Devices Root CA 2021 > > > signature 3 > > > image signature issuers: > > > - /CN=SUSE Linux Enterprise Secure Boot CA/C=DE/L=Nuremberg/O=SUSE Linux Products GmbH/OU=Build Team/[email protected] > > > image signature certificates: > > > - subject: /CN=SUSE Linux Enterprise Secure Boot Signkey/C=DE/L=Nuremberg/O=SUSE Linux Products GmbH/OU=Build Team/[email protected] > > > issuer: /CN=SUSE Linux Enterprise Secure Boot CA/C=DE/L=Nuremberg/O=SUSE Linux Products GmbH/OU=Build Team/[email protected] > > > > > > efi-readvar_-v KEK > > > Variable KEK, length 3946 > > > KEK: List 0, type X509 > > > Signature 0, size 852, owner 3b053091-6c9f-04cc-b1ac-e2a51e3be5f5 > > > Subject: > > > CN=ASUSTeK Notebook KEK Certificate > > > Issuer: > > > CN=ASUSTeK Notebook KEK Certificate > > > KEK: List 1, type X509 > > > Signature 0, size 1532, owner 77fa9abd-0359-4d32-bd60-28f4e78f784b > > > Subject: > > > C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Corporation KEK CA 2011 > > > Issuer: > > > C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Corporation Third Party Marketplace Root > > > KEK: List 2, type X509 > > > Signature 0, size 1478, owner 77fa9abd-0359-4d32-bd60-28f4e78f784b > > > Subject: > > > C=US, O=Microsoft Corporation, CN=Microsoft Corporation KEK 2K CA 2023 > > > Issuer: > > > C=US, O=Microsoft Corporation, CN=Microsoft RSA Devices Root CA 2021 > > -- Marcus Meissner (he/him), Distinguished Engineer / Senior Project Manager Security SUSE Software Solutions Germany GmbH, Frankenstrasse 146, 90461 Nuernberg, Germany GF: Jochen Jaser, Andrew McDonald, HRB 36809, AG Nuernberg