Re: Secure-Boot auf Leap 16.0 - wie aktivieren

Marcus Meissner <[email protected]> Wed, 1 Jul 2026 19:54:10 +0000
Newsgroups gmane.linux.suse.general.german
Organization SUSE Software Solutions Ger many GmbH, Frankenstraße 146, 90461 Nuernberg, Ger many, GF: Ivo Totev, Andrew Myers, Andrew McDonald , Martje Boudien Moerman, HRB 36809, AG Nürnberg
Message-ID <[email protected]>
Hi,

Ok, ist das Paket shim installiert?

Wenn nicht, bitte mal installieren.

Ich vermute es ist nicht installiert...

Ciao, Marcus
On Wed, Jul 01, 2026 at 06:12:33PM +0200, Werner Franke wrote:
> Hallo Marcus, Stephan, alle,
> 
> Der Laptop startet mit UEFI boot setup.
> Es ist ein ASUS EXPERTBOOK BM 1, der hat kein Legacy-BIOS und auch kein Compatibility Support Module.
> Ich habe im BIOS jedenfalls nichts dazu gefunden.
> 
> (im Gegensatz zu meinem Desktop PC  :-(  )
> 
> Wenn ich Secure Boot im ASUS aktiviere, kommt beim Boot ein roter Bildschirm mit dem Hinweis
> 
>           Secure Boot Violation
> 
>  Invalid signature detected. Check Secure Boot Policy in Setup
> 
> Wird bei der Installation des neuen Leap 16.0 auch alle notwendigen
> Secure-Boot Teile mit installiert, auch wenn Secure-Boot zu dem Zeitpunkt deaktiviert ist ?
> Im BIOS Boot-Menü wird die System-Partition mit "opensuse-secureboot" angezeigt.
> Eine weitere Partition ist nicht vorhanden.
> 
> @Stephan,
> Einen openSUSE Key habe ich nicht explizit installiert.
> Wenn ich die Keys unten richtig interpretiere, ist bei "mokutil --list-enrolled"
> ein "SUSE Linux Enterprise Secure Boot CA" mit langem Ablaufdatum installiert.
> 
> Ich habe gestern, 31.06.26 erstmalig auf dem Laptop an dem Secure-Boot Zeugs
> herumprobiert. Hat da der Fall "Zertifikate ausgelaufen" schon zugeschlagen ?
> 
> Der "CN=Microsoft Corporation KEK CA 2011", der am 24.06.2026 abgelaufen ist.
> 
> liebe Grüße
>   Werner
> 
> Am 01.07.26 um 11:50 schrieb Marcus Meissner:
> > Hi,
> > 
> > Secure boot braucht normalerweise ein UEFI boot setup. Wenn das System
> > noch in "traditional BIOS" mode ist, muss neu installiert werden zuerst.
> > 
> > AUch wenn es in UEFI boot mode ist, kann sein das unser shim nicht in
> > der Boot Reihenfolge wenn es ohne secure boot installiert wurde.
> > 
> > Also am ehesten muss neu installiert werden muessen.
> > 
> > Ciao, Marcus
> > On Wed, Jul 01, 2026 at 10:06:24AM +0200, Werner Franke wrote:
> > > Hallo zusammen,
> > > 
> > > da im Netz das Thema Secure-Boot aktuell ist, weil Zertifikate auslaufen sollen, habe ich mich etwas mit
> > > diesem Thema besch�ftigt, auch weil in der c't 2026.13 einige Artikel dar�ber abgedruckt sind.
> > > Leider sind die Artikel auf Windows PCs gem�nzt und wie ich da mit den Linux-Rools die
> > > passenden Informationen bekomme, ist mir nicht so recht klar.
> > > (Aus dem Grund sie eventuell auch einige verwendeten Befehle unten falsch bzw. fehlen)
> > > 
> > > Bei meinem neuen ASUS Laptop (Nov 2025), auf dem ich Leap 16.0 frisch installiert hatte, habe ich im UEFI-BIOS
> > > nachgeschaut und festgestellt das dort Secure-Boot deaktiviert ist. Das war anscheinend bei Auslieferung
> > > schon so, denn ich hatte da nicht dran geschraubt.
> > > Nach einem Restore der Keys und aktivieren von Secure-Boot kann ich OpenSUSE nicht mehr booten.
> > > Auch ein "fwupdmgr get-updates" und "fwupdmgr update" hat nichts gebracht.
> > > 
> > > Ich nehme an einige der Keys ist abgelaufen und muss ersetzt werden.
> > > (abgelaufen: bald Key3 (--db) und abgelaufen Key2 (--kek) ??)
> > > Wie aktualisieren?
> > > 
> > > Vielen dank f�r Tipps
> > > 
> > > Werner Franke
> > > 
> > > Folgende Infos habe ich auf dem ACER zusammengetragen:
> > > 
> > > mokutil --db
> > >   Key 1: CN=ASUSTeK Notebook SW Key Certificate      2011 bis 2031
> > >   Key 2: CN=ASUSTeK MotherBoard SW Key Certificate   2011 bis 2031
> > >   Key 3: C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2010
> > >                                                      2011 bis 19.10.2026
> > >   Key 4: C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2010
> > >                                                      2013 bis 2035
> > >   Key 5: C=GB, ST=Isle of Man, L=Douglas, O=Canonical Ltd., CN=Canonical Ltd. Master Certificate Authority
> > >                                                      2012 bis 2042
> > > 
> > > mokutil --kek
> > >   Key 1: CN=ASUSTeK Notebook KEK Certificate         2011 bis 2031
> > >   Key 2: C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Corporation KEK CA 2011
> > >                                                      2011 bis 24.06.2026
> > >   Key 3: C=US, O=Microsoft Corporation, CN=Microsoft RSA Devices Root CA 2021
> > >                                                      2023 bis 2038
> > > 
> > > mokutil --list-enrolled
> > >   Key 1: CN=SUSE Linux Enterprise Secure Boot CA, C=DE, L=Nuremberg, O=SUSE Linux Products GmbH, OU=Build Team/[email protected]
> > >                                                      2013 bis 2035
> > > 
> > > sbverify_--list /boot/efi/EFI/opensuse/shim.efi
> > >   signature 1
> > >    image signature issuers:
> > >     - /C=US/ST=Washington/L=Redmond/O=Microsoft Corporation/CN=Microsoft Corporation UEFI CA 2011
> > >    image signature certificates:
> > >     - subject: /C=US/ST=Washington/L=Redmond/O=Microsoft Corporation/CN=Microsoft Windows UEFI Driver Publisher
> > >       issuer:  /C=US/ST=Washington/L=Redmond/O=Microsoft Corporation/CN=Microsoft Corporation UEFI CA 2011
> > >     - subject: /C=US/ST=Washington/L=Redmond/O=Microsoft Corporation/CN=Microsoft Corporation UEFI CA 2011
> > >       issuer:  /C=US/ST=Washington/L=Redmond/O=Microsoft Corporation/CN=Microsoft Corporation Third Party Marketplace Root
> > >   signature 2
> > >    image signature issuers:
> > >     - /C=US/O=Microsoft Corporation/CN=Microsoft UEFI CA 2023
> > >    image signature certificates:
> > >     - subject: /C=US/ST=Washington/L=Redmond/O=Microsoft Corporation/CN=Microsoft UEFI CA 2023 signer
> > >       issuer:  /C=US/O=Microsoft Corporation/CN=Microsoft UEFI CA 2023
> > >     - subject: /C=US/O=Microsoft Corporation/CN=Microsoft UEFI CA 2023
> > >       issuer:  /C=US/O=Microsoft Corporation/CN=Microsoft RSA Devices Root CA 2021
> > >   signature 3
> > >    image signature issuers:
> > >     - /CN=SUSE Linux Enterprise Secure Boot CA/C=DE/L=Nuremberg/O=SUSE Linux Products GmbH/OU=Build Team/[email protected]
> > >    image signature certificates:
> > >     - subject: /CN=SUSE Linux Enterprise Secure Boot Signkey/C=DE/L=Nuremberg/O=SUSE Linux Products GmbH/OU=Build Team/[email protected]
> > >       issuer:  /CN=SUSE Linux Enterprise Secure Boot CA/C=DE/L=Nuremberg/O=SUSE Linux Products GmbH/OU=Build Team/[email protected]
> > > 
> > >   efi-readvar_-v KEK
> > >    Variable KEK, length 3946
> > >     KEK: List 0, type X509
> > >      Signature 0, size 852, owner 3b053091-6c9f-04cc-b1ac-e2a51e3be5f5
> > >          Subject:
> > >              CN=ASUSTeK Notebook KEK Certificate
> > >          Issuer:
> > >              CN=ASUSTeK Notebook KEK Certificate
> > >     KEK: List 1, type X509
> > >      Signature 0, size 1532, owner 77fa9abd-0359-4d32-bd60-28f4e78f784b
> > >          Subject:
> > >              C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Corporation KEK CA 2011
> > >          Issuer:
> > >              C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Corporation Third Party Marketplace Root
> > >     KEK: List 2, type X509
> > >      Signature 0, size 1478, owner 77fa9abd-0359-4d32-bd60-28f4e78f784b
> > >          Subject:
> > >              C=US, O=Microsoft Corporation, CN=Microsoft Corporation KEK 2K CA 2023
> > >          Issuer:
> > >              C=US, O=Microsoft Corporation, CN=Microsoft RSA Devices Root CA 2021
> > 

-- 
Marcus Meissner (he/him), Distinguished Engineer / Senior Project Manager Security
SUSE Software Solutions Germany GmbH, Frankenstrasse 146, 90461 Nuernberg, Germany
GF: Jochen Jaser, Andrew McDonald, HRB 36809, AG Nuernberg