Re: Secure-Boot auf Leap 16.0 - wie aktivieren

Werner Franke <[email protected]> Fri, 3 Jul 2026 09:33:18 +0200
Newsgroups gmane.linux.suse.general.german
Organization Privat
Message-ID <[email protected]>
Zusatz,

auf meinem Desktop PC (auch Leap 16.0, aber mit CSM, damit kein Secure-Boot) bekomme ich
von Discover zwei Updates angeboten

  - Microsoft KEK CA     2011 -> 2023
  - Microsoft UEFI dbx   20250902 -> 20260402

von "Firmware-Aktualisierung (lvfs)".
Auf dem Laptop habe ich das noch nicht gesehen.
Was ist "Firmware-Aktualisierung (lvfs)" ?
Welcher Dienst/Tool ist dafür verantwortlich, dass das kommt ?
In Myrlyn sehe ich die beiden Updates nicht.

Gibt es eigentlich eine Möglichkeit herauszufinden was welchen Key benutzt
um dann den Key identifizieren können, der die Secure Boot Violation
verursacht ?

viele Grüße
   Werner

Am 02.07.26 um 14:51 schrieb Werner Franke:
> Hi,
>   vielen Dank für die Antworten.
> 
> ist installiert
>     shim-16.1-160000.1.1.x86_64
> 
> Werden noch anderen Infos benötigt ?
> 
> Ich hatte am 29.06.26 auch schon
>   fwupdmgr get-updates   und
>   fwupdmgr update
> gemacht.
> 
> Jetzt gemacht
> root@Idefix (-bash) fwupdmgr get-updates
> Devices with no available firmware updates:
>   • ASUSTeK KEK Certificate
>   • ASUSTeK SW Key Certificate
>   • MTFDKBA512QGN-1BN1AABGA
>   • SNV3SM3500G
>   • System Firmware
>   • ASUS FHD webcam
>   • KEK CA
>   • Master Certificate Authority
>   • Windows UEFI CA
> Geräte mit der neuesten verfügbaren Firmware-Version:
>   • UEFI dbx
> ────────────────────────────────────────────────
> Erfolgreich aktualisierte Geräte:
>   • UEFI dbx (20230301 → 20260402)
> 
> viele Grüße
>    Werner
> 
> Am 01.07.26 um 21:54 schrieb Marcus Meissner:
>> Hi,
>>
>> Ok, ist das Paket shim installiert?
>>
>> Wenn nicht, bitte mal installieren.
>>
>> Ich vermute es ist nicht installiert...
>>
>> Ciao, Marcus
>> On Wed, Jul 01, 2026 at 06:12:33PM +0200, Werner Franke wrote:
>>> Hallo Marcus, Stephan, alle,
>>>
>>> Der Laptop startet mit UEFI boot setup.
>>> Es ist ein ASUS EXPERTBOOK BM 1, der hat kein Legacy-BIOS und auch kein Compatibility Support Module.
>>> Ich habe im BIOS jedenfalls nichts dazu gefunden.
>>>
>>> (im Gegensatz zu meinem Desktop PC  :-(  )
>>>
>>> Wenn ich Secure Boot im ASUS aktiviere, kommt beim Boot ein roter Bildschirm mit dem Hinweis
>>>
>>>            Secure Boot Violation
>>>
>>>   Invalid signature detected. Check Secure Boot Policy in Setup
>>>
>>> Wird bei der Installation des neuen Leap 16.0 auch alle notwendigen
>>> Secure-Boot Teile mit installiert, auch wenn Secure-Boot zu dem Zeitpunkt deaktiviert ist ?
>>> Im BIOS Boot-Men� wird die System-Partition mit "opensuse-secureboot" angezeigt.
>>> Eine weitere Partition ist nicht vorhanden.
>>>
>>> @Stephan,
>>> Einen openSUSE Key habe ich nicht explizit installiert.
>>> Wenn ich die Keys unten richtig interpretiere, ist bei "mokutil --list-enrolled"
>>> ein "SUSE Linux Enterprise Secure Boot CA" mit langem Ablaufdatum installiert.
>>>
>>> Ich habe gestern, 31.06.26 erstmalig auf dem Laptop an dem Secure-Boot Zeugs
>>> herumprobiert. Hat da der Fall "Zertifikate ausgelaufen" schon zugeschlagen ?
>>>
>>> Der "CN=Microsoft Corporation KEK CA 2011", der am 24.06.2026 abgelaufen ist.
>>>
>>> liebe Gr��e
>>>    Werner
>>>
>>> Am 01.07.26 um 11:50 schrieb Marcus Meissner:
>>>> Hi,
>>>>
>>>> Secure boot braucht normalerweise ein UEFI boot setup. Wenn das System
>>>> noch in "traditional BIOS" mode ist, muss neu installiert werden zuerst.
>>>>
>>>> AUch wenn es in UEFI boot mode ist, kann sein das unser shim nicht in
>>>> der Boot Reihenfolge wenn es ohne secure boot installiert wurde.
>>>>
>>>> Also am ehesten muss neu installiert werden muessen.
>>>>
>>>> Ciao, Marcus
>>>> On Wed, Jul 01, 2026 at 10:06:24AM +0200, Werner Franke wrote:
>>>>> Hallo zusammen,
>>>>>
>>>>> da im Netz das Thema Secure-Boot aktuell ist, weil Zertifikate auslaufen sollen, habe ich mich etwas mit
>>>>> diesem Thema besch�ftigt, auch weil in der c't 2026.13 einige Artikel dar�ber abgedruckt sind.
>>>>> Leider sind die Artikel auf Windows PCs gem�nzt und wie ich da mit den Linux-Rools die
>>>>> passenden Informationen bekomme, ist mir nicht so recht klar.
>>>>> (Aus dem Grund sie eventuell auch einige verwendeten Befehle unten falsch bzw. fehlen)
>>>>>
>>>>> Bei meinem neuen ASUS Laptop (Nov 2025), auf dem ich Leap 16.0 frisch installiert hatte, habe ich im UEFI-BIOS
>>>>> nachgeschaut und festgestellt das dort Secure-Boot deaktiviert ist. Das war anscheinend bei Auslieferung
>>>>> schon so, denn ich hatte da nicht dran geschraubt.
>>>>> Nach einem Restore der Keys und aktivieren von Secure-Boot kann ich OpenSUSE nicht mehr booten.
>>>>> Auch ein "fwupdmgr get-updates" und "fwupdmgr update" hat nichts gebracht.
>>>>>
>>>>> Ich nehme an einige der Keys ist abgelaufen und muss ersetzt werden.
>>>>> (abgelaufen: bald Key3 (--db) und abgelaufen Key2 (--kek) ??)
>>>>> Wie aktualisieren?
>>>>>
>>>>> Vielen dank f�r Tipps
>>>>>
>>>>> Werner Franke
>>>>>
>>>>> Folgende Infos habe ich auf dem ACER zusammengetragen:
>>>>>
>>>>> mokutil --db
>>>>>    Key 1: CN=ASUSTeK Notebook SW Key Certificate      2011 bis 2031
>>>>>    Key 2: CN=ASUSTeK MotherBoard SW Key Certificate   2011 bis 2031
>>>>>    Key 3: C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2010
>>>>>                                                       2011 bis 19.10.2026
>>>>>    Key 4: C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2010
>>>>>                                                       2013 bis 2035
>>>>>    Key 5: C=GB, ST=Isle of Man, L=Douglas, O=Canonical Ltd., CN=Canonical Ltd. Master Certificate Authority
>>>>>                                                       2012 bis 2042
>>>>>
>>>>> mokutil --kek
>>>>>    Key 1: CN=ASUSTeK Notebook KEK Certificate         2011 bis 2031
>>>>>    Key 2: C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Corporation KEK CA 2011
>>>>>                                                       2011 bis 24.06.2026
>>>>>    Key 3: C=US, O=Microsoft Corporation, CN=Microsoft RSA Devices Root CA 2021
>>>>>                                                       2023 bis 2038
>>>>>
>>>>> mokutil --list-enrolled
>>>>>    Key 1: CN=SUSE Linux Enterprise Secure Boot CA, C=DE, L=Nuremberg, O=SUSE Linux Products GmbH, OU=Build Team/[email protected]
>>>>>                                                       2013 bis 2035
>>>>>
>>>>> sbverify_--list /boot/efi/EFI/opensuse/shim.efi
>>>>>    signature 1
>>>>>     image signature issuers:
>>>>>      - /C=US/ST=Washington/L=Redmond/O=Microsoft Corporation/CN=Microsoft Corporation UEFI CA 2011
>>>>>     image signature certificates:
>>>>>      - subject: /C=US/ST=Washington/L=Redmond/O=Microsoft Corporation/CN=Microsoft Windows UEFI Driver Publisher
>>>>>        issuer:  /C=US/ST=Washington/L=Redmond/O=Microsoft Corporation/CN=Microsoft Corporation UEFI CA 2011
>>>>>      - subject: /C=US/ST=Washington/L=Redmond/O=Microsoft Corporation/CN=Microsoft Corporation UEFI CA 2011
>>>>>        issuer:  /C=US/ST=Washington/L=Redmond/O=Microsoft Corporation/CN=Microsoft Corporation Third Party Marketplace Root
>>>>>    signature 2
>>>>>     image signature issuers:
>>>>>      - /C=US/O=Microsoft Corporation/CN=Microsoft UEFI CA 2023
>>>>>     image signature certificates:
>>>>>      - subject: /C=US/ST=Washington/L=Redmond/O=Microsoft Corporation/CN=Microsoft UEFI CA 2023 signer
>>>>>        issuer:  /C=US/O=Microsoft Corporation/CN=Microsoft UEFI CA 2023
>>>>>      - subject: /C=US/O=Microsoft Corporation/CN=Microsoft UEFI CA 2023
>>>>>        issuer:  /C=US/O=Microsoft Corporation/CN=Microsoft RSA Devices Root CA 2021
>>>>>    signature 3
>>>>>     image signature issuers:
>>>>>      - /CN=SUSE Linux Enterprise Secure Boot CA/C=DE/L=Nuremberg/O=SUSE Linux Products GmbH/OU=Build Team/[email protected]
>>>>>     image signature certificates:
>>>>>      - subject: /CN=SUSE Linux Enterprise Secure Boot Signkey/C=DE/L=Nuremberg/O=SUSE Linux Products GmbH/OU=Build Team/[email protected]
>>>>>        issuer:  /CN=SUSE Linux Enterprise Secure Boot CA/C=DE/L=Nuremberg/O=SUSE Linux Products GmbH/OU=Build Team/[email protected]
>>>>>
>>>>>    efi-readvar_-v KEK
>>>>>     Variable KEK, length 3946
>>>>>      KEK: List 0, type X509
>>>>>       Signature 0, size 852, owner 3b053091-6c9f-04cc-b1ac-e2a51e3be5f5
>>>>>           Subject:
>>>>>               CN=ASUSTeK Notebook KEK Certificate
>>>>>           Issuer:
>>>>>               CN=ASUSTeK Notebook KEK Certificate
>>>>>      KEK: List 1, type X509
>>>>>       Signature 0, size 1532, owner 77fa9abd-0359-4d32-bd60-28f4e78f784b
>>>>>           Subject:
>>>>>               C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Corporation KEK CA 2011
>>>>>           Issuer:
>>>>>               C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Corporation Third Party Marketplace Root
>>>>>      KEK: List 2, type X509
>>>>>       Signature 0, size 1478, owner 77fa9abd-0359-4d32-bd60-28f4e78f784b
>>>>>           Subject:
>>>>>               C=US, O=Microsoft Corporation, CN=Microsoft Corporation KEK 2K CA 2023
>>>>>           Issuer:
>>>>>               C=US, O=Microsoft Corporation, CN=Microsoft RSA Devices Root CA 2021
>>>>
>>