Re: Secure-Boot auf Leap 16.0 - wie aktivieren
Werner Franke <[email protected]> Thu, 2 Jul 2026 14:51:49 +0200
| Newsgroups | gmane.linux.suse.general.german |
|---|---|
| Organization | Privat |
| Message-ID | <[email protected]> |
Hi,
vielen Dank für die Antworten.
ist installiert
shim-16.1-160000.1.1.x86_64
Werden noch anderen Infos benötigt ?
Ich hatte am 29.06.26 auch schon
fwupdmgr get-updates und
fwupdmgr update
gemacht.
Jetzt gemacht
root@Idefix (-bash) fwupdmgr get-updates
Devices with no available firmware updates:
• ASUSTeK KEK Certificate
• ASUSTeK SW Key Certificate
• MTFDKBA512QGN-1BN1AABGA
• SNV3SM3500G
• System Firmware
• ASUS FHD webcam
• KEK CA
• Master Certificate Authority
• Windows UEFI CA
Geräte mit der neuesten verfügbaren Firmware-Version:
• UEFI dbx
────────────────────────────────────────────────
Erfolgreich aktualisierte Geräte:
• UEFI dbx (20230301 → 20260402)
viele Grüße
Werner
Am 01.07.26 um 21:54 schrieb Marcus Meissner:
> Hi,
>
> Ok, ist das Paket shim installiert?
>
> Wenn nicht, bitte mal installieren.
>
> Ich vermute es ist nicht installiert...
>
> Ciao, Marcus
> On Wed, Jul 01, 2026 at 06:12:33PM +0200, Werner Franke wrote:
>> Hallo Marcus, Stephan, alle,
>>
>> Der Laptop startet mit UEFI boot setup.
>> Es ist ein ASUS EXPERTBOOK BM 1, der hat kein Legacy-BIOS und auch kein Compatibility Support Module.
>> Ich habe im BIOS jedenfalls nichts dazu gefunden.
>>
>> (im Gegensatz zu meinem Desktop PC :-( )
>>
>> Wenn ich Secure Boot im ASUS aktiviere, kommt beim Boot ein roter Bildschirm mit dem Hinweis
>>
>> Secure Boot Violation
>>
>> Invalid signature detected. Check Secure Boot Policy in Setup
>>
>> Wird bei der Installation des neuen Leap 16.0 auch alle notwendigen
>> Secure-Boot Teile mit installiert, auch wenn Secure-Boot zu dem Zeitpunkt deaktiviert ist ?
>> Im BIOS Boot-Men� wird die System-Partition mit "opensuse-secureboot" angezeigt.
>> Eine weitere Partition ist nicht vorhanden.
>>
>> @Stephan,
>> Einen openSUSE Key habe ich nicht explizit installiert.
>> Wenn ich die Keys unten richtig interpretiere, ist bei "mokutil --list-enrolled"
>> ein "SUSE Linux Enterprise Secure Boot CA" mit langem Ablaufdatum installiert.
>>
>> Ich habe gestern, 31.06.26 erstmalig auf dem Laptop an dem Secure-Boot Zeugs
>> herumprobiert. Hat da der Fall "Zertifikate ausgelaufen" schon zugeschlagen ?
>>
>> Der "CN=Microsoft Corporation KEK CA 2011", der am 24.06.2026 abgelaufen ist.
>>
>> liebe Gr��e
>> Werner
>>
>> Am 01.07.26 um 11:50 schrieb Marcus Meissner:
>>> Hi,
>>>
>>> Secure boot braucht normalerweise ein UEFI boot setup. Wenn das System
>>> noch in "traditional BIOS" mode ist, muss neu installiert werden zuerst.
>>>
>>> AUch wenn es in UEFI boot mode ist, kann sein das unser shim nicht in
>>> der Boot Reihenfolge wenn es ohne secure boot installiert wurde.
>>>
>>> Also am ehesten muss neu installiert werden muessen.
>>>
>>> Ciao, Marcus
>>> On Wed, Jul 01, 2026 at 10:06:24AM +0200, Werner Franke wrote:
>>>> Hallo zusammen,
>>>>
>>>> da im Netz das Thema Secure-Boot aktuell ist, weil Zertifikate auslaufen sollen, habe ich mich etwas mit
>>>> diesem Thema besch�ftigt, auch weil in der c't 2026.13 einige Artikel dar�ber abgedruckt sind.
>>>> Leider sind die Artikel auf Windows PCs gem�nzt und wie ich da mit den Linux-Rools die
>>>> passenden Informationen bekomme, ist mir nicht so recht klar.
>>>> (Aus dem Grund sie eventuell auch einige verwendeten Befehle unten falsch bzw. fehlen)
>>>>
>>>> Bei meinem neuen ASUS Laptop (Nov 2025), auf dem ich Leap 16.0 frisch installiert hatte, habe ich im UEFI-BIOS
>>>> nachgeschaut und festgestellt das dort Secure-Boot deaktiviert ist. Das war anscheinend bei Auslieferung
>>>> schon so, denn ich hatte da nicht dran geschraubt.
>>>> Nach einem Restore der Keys und aktivieren von Secure-Boot kann ich OpenSUSE nicht mehr booten.
>>>> Auch ein "fwupdmgr get-updates" und "fwupdmgr update" hat nichts gebracht.
>>>>
>>>> Ich nehme an einige der Keys ist abgelaufen und muss ersetzt werden.
>>>> (abgelaufen: bald Key3 (--db) und abgelaufen Key2 (--kek) ??)
>>>> Wie aktualisieren?
>>>>
>>>> Vielen dank f�r Tipps
>>>>
>>>> Werner Franke
>>>>
>>>> Folgende Infos habe ich auf dem ACER zusammengetragen:
>>>>
>>>> mokutil --db
>>>> Key 1: CN=ASUSTeK Notebook SW Key Certificate 2011 bis 2031
>>>> Key 2: CN=ASUSTeK MotherBoard SW Key Certificate 2011 bis 2031
>>>> Key 3: C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2010
>>>> 2011 bis 19.10.2026
>>>> Key 4: C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2010
>>>> 2013 bis 2035
>>>> Key 5: C=GB, ST=Isle of Man, L=Douglas, O=Canonical Ltd., CN=Canonical Ltd. Master Certificate Authority
>>>> 2012 bis 2042
>>>>
>>>> mokutil --kek
>>>> Key 1: CN=ASUSTeK Notebook KEK Certificate 2011 bis 2031
>>>> Key 2: C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Corporation KEK CA 2011
>>>> 2011 bis 24.06.2026
>>>> Key 3: C=US, O=Microsoft Corporation, CN=Microsoft RSA Devices Root CA 2021
>>>> 2023 bis 2038
>>>>
>>>> mokutil --list-enrolled
>>>> Key 1: CN=SUSE Linux Enterprise Secure Boot CA, C=DE, L=Nuremberg, O=SUSE Linux Products GmbH, OU=Build Team/[email protected]
>>>> 2013 bis 2035
>>>>
>>>> sbverify_--list /boot/efi/EFI/opensuse/shim.efi
>>>> signature 1
>>>> image signature issuers:
>>>> - /C=US/ST=Washington/L=Redmond/O=Microsoft Corporation/CN=Microsoft Corporation UEFI CA 2011
>>>> image signature certificates:
>>>> - subject: /C=US/ST=Washington/L=Redmond/O=Microsoft Corporation/CN=Microsoft Windows UEFI Driver Publisher
>>>> issuer: /C=US/ST=Washington/L=Redmond/O=Microsoft Corporation/CN=Microsoft Corporation UEFI CA 2011
>>>> - subject: /C=US/ST=Washington/L=Redmond/O=Microsoft Corporation/CN=Microsoft Corporation UEFI CA 2011
>>>> issuer: /C=US/ST=Washington/L=Redmond/O=Microsoft Corporation/CN=Microsoft Corporation Third Party Marketplace Root
>>>> signature 2
>>>> image signature issuers:
>>>> - /C=US/O=Microsoft Corporation/CN=Microsoft UEFI CA 2023
>>>> image signature certificates:
>>>> - subject: /C=US/ST=Washington/L=Redmond/O=Microsoft Corporation/CN=Microsoft UEFI CA 2023 signer
>>>> issuer: /C=US/O=Microsoft Corporation/CN=Microsoft UEFI CA 2023
>>>> - subject: /C=US/O=Microsoft Corporation/CN=Microsoft UEFI CA 2023
>>>> issuer: /C=US/O=Microsoft Corporation/CN=Microsoft RSA Devices Root CA 2021
>>>> signature 3
>>>> image signature issuers:
>>>> - /CN=SUSE Linux Enterprise Secure Boot CA/C=DE/L=Nuremberg/O=SUSE Linux Products GmbH/OU=Build Team/[email protected]
>>>> image signature certificates:
>>>> - subject: /CN=SUSE Linux Enterprise Secure Boot Signkey/C=DE/L=Nuremberg/O=SUSE Linux Products GmbH/OU=Build Team/[email protected]
>>>> issuer: /CN=SUSE Linux Enterprise Secure Boot CA/C=DE/L=Nuremberg/O=SUSE Linux Products GmbH/OU=Build Team/[email protected]
>>>>
>>>> efi-readvar_-v KEK
>>>> Variable KEK, length 3946
>>>> KEK: List 0, type X509
>>>> Signature 0, size 852, owner 3b053091-6c9f-04cc-b1ac-e2a51e3be5f5
>>>> Subject:
>>>> CN=ASUSTeK Notebook KEK Certificate
>>>> Issuer:
>>>> CN=ASUSTeK Notebook KEK Certificate
>>>> KEK: List 1, type X509
>>>> Signature 0, size 1532, owner 77fa9abd-0359-4d32-bd60-28f4e78f784b
>>>> Subject:
>>>> C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Corporation KEK CA 2011
>>>> Issuer:
>>>> C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Corporation Third Party Marketplace Root
>>>> KEK: List 2, type X509
>>>> Signature 0, size 1478, owner 77fa9abd-0359-4d32-bd60-28f4e78f784b
>>>> Subject:
>>>> C=US, O=Microsoft Corporation, CN=Microsoft Corporation KEK 2K CA 2023
>>>> Issuer:
>>>> C=US, O=Microsoft Corporation, CN=Microsoft RSA Devices Root CA 2021
>>>
>