Re: Secure-Boot auf Leap 16.0 - wie aktivieren
Werner Franke <[email protected]> Fri, 3 Jul 2026 09:33:18 +0200
| Newsgroups | gmane.linux.suse.general.german |
|---|---|
| Organization | Privat |
| Message-ID | <[email protected]> |
Zusatz, auf meinem Desktop PC (auch Leap 16.0, aber mit CSM, damit kein Secure-Boot) bekomme ich von Discover zwei Updates angeboten - Microsoft KEK CA 2011 -> 2023 - Microsoft UEFI dbx 20250902 -> 20260402 von "Firmware-Aktualisierung (lvfs)". Auf dem Laptop habe ich das noch nicht gesehen. Was ist "Firmware-Aktualisierung (lvfs)" ? Welcher Dienst/Tool ist dafür verantwortlich, dass das kommt ? In Myrlyn sehe ich die beiden Updates nicht. Gibt es eigentlich eine Möglichkeit herauszufinden was welchen Key benutzt um dann den Key identifizieren können, der die Secure Boot Violation verursacht ? viele Grüße Werner Am 02.07.26 um 14:51 schrieb Werner Franke: > Hi, > vielen Dank für die Antworten. > > ist installiert > shim-16.1-160000.1.1.x86_64 > > Werden noch anderen Infos benötigt ? > > Ich hatte am 29.06.26 auch schon > fwupdmgr get-updates und > fwupdmgr update > gemacht. > > Jetzt gemacht > root@Idefix (-bash) fwupdmgr get-updates > Devices with no available firmware updates: > • ASUSTeK KEK Certificate > • ASUSTeK SW Key Certificate > • MTFDKBA512QGN-1BN1AABGA > • SNV3SM3500G > • System Firmware > • ASUS FHD webcam > • KEK CA > • Master Certificate Authority > • Windows UEFI CA > Geräte mit der neuesten verfügbaren Firmware-Version: > • UEFI dbx > ──────────────────────────────────────────────── > Erfolgreich aktualisierte Geräte: > • UEFI dbx (20230301 → 20260402) > > viele Grüße > Werner > > Am 01.07.26 um 21:54 schrieb Marcus Meissner: >> Hi, >> >> Ok, ist das Paket shim installiert? >> >> Wenn nicht, bitte mal installieren. >> >> Ich vermute es ist nicht installiert... >> >> Ciao, Marcus >> On Wed, Jul 01, 2026 at 06:12:33PM +0200, Werner Franke wrote: >>> Hallo Marcus, Stephan, alle, >>> >>> Der Laptop startet mit UEFI boot setup. >>> Es ist ein ASUS EXPERTBOOK BM 1, der hat kein Legacy-BIOS und auch kein Compatibility Support Module. >>> Ich habe im BIOS jedenfalls nichts dazu gefunden. >>> >>> (im Gegensatz zu meinem Desktop PC :-( ) >>> >>> Wenn ich Secure Boot im ASUS aktiviere, kommt beim Boot ein roter Bildschirm mit dem Hinweis >>> >>> Secure Boot Violation >>> >>> Invalid signature detected. Check Secure Boot Policy in Setup >>> >>> Wird bei der Installation des neuen Leap 16.0 auch alle notwendigen >>> Secure-Boot Teile mit installiert, auch wenn Secure-Boot zu dem Zeitpunkt deaktiviert ist ? >>> Im BIOS Boot-Men� wird die System-Partition mit "opensuse-secureboot" angezeigt. >>> Eine weitere Partition ist nicht vorhanden. >>> >>> @Stephan, >>> Einen openSUSE Key habe ich nicht explizit installiert. >>> Wenn ich die Keys unten richtig interpretiere, ist bei "mokutil --list-enrolled" >>> ein "SUSE Linux Enterprise Secure Boot CA" mit langem Ablaufdatum installiert. >>> >>> Ich habe gestern, 31.06.26 erstmalig auf dem Laptop an dem Secure-Boot Zeugs >>> herumprobiert. Hat da der Fall "Zertifikate ausgelaufen" schon zugeschlagen ? >>> >>> Der "CN=Microsoft Corporation KEK CA 2011", der am 24.06.2026 abgelaufen ist. >>> >>> liebe Gr��e >>> Werner >>> >>> Am 01.07.26 um 11:50 schrieb Marcus Meissner: >>>> Hi, >>>> >>>> Secure boot braucht normalerweise ein UEFI boot setup. Wenn das System >>>> noch in "traditional BIOS" mode ist, muss neu installiert werden zuerst. >>>> >>>> AUch wenn es in UEFI boot mode ist, kann sein das unser shim nicht in >>>> der Boot Reihenfolge wenn es ohne secure boot installiert wurde. >>>> >>>> Also am ehesten muss neu installiert werden muessen. >>>> >>>> Ciao, Marcus >>>> On Wed, Jul 01, 2026 at 10:06:24AM +0200, Werner Franke wrote: >>>>> Hallo zusammen, >>>>> >>>>> da im Netz das Thema Secure-Boot aktuell ist, weil Zertifikate auslaufen sollen, habe ich mich etwas mit >>>>> diesem Thema besch�ftigt, auch weil in der c't 2026.13 einige Artikel dar�ber abgedruckt sind. >>>>> Leider sind die Artikel auf Windows PCs gem�nzt und wie ich da mit den Linux-Rools die >>>>> passenden Informationen bekomme, ist mir nicht so recht klar. >>>>> (Aus dem Grund sie eventuell auch einige verwendeten Befehle unten falsch bzw. fehlen) >>>>> >>>>> Bei meinem neuen ASUS Laptop (Nov 2025), auf dem ich Leap 16.0 frisch installiert hatte, habe ich im UEFI-BIOS >>>>> nachgeschaut und festgestellt das dort Secure-Boot deaktiviert ist. Das war anscheinend bei Auslieferung >>>>> schon so, denn ich hatte da nicht dran geschraubt. >>>>> Nach einem Restore der Keys und aktivieren von Secure-Boot kann ich OpenSUSE nicht mehr booten. >>>>> Auch ein "fwupdmgr get-updates" und "fwupdmgr update" hat nichts gebracht. >>>>> >>>>> Ich nehme an einige der Keys ist abgelaufen und muss ersetzt werden. >>>>> (abgelaufen: bald Key3 (--db) und abgelaufen Key2 (--kek) ??) >>>>> Wie aktualisieren? >>>>> >>>>> Vielen dank f�r Tipps >>>>> >>>>> Werner Franke >>>>> >>>>> Folgende Infos habe ich auf dem ACER zusammengetragen: >>>>> >>>>> mokutil --db >>>>> Key 1: CN=ASUSTeK Notebook SW Key Certificate 2011 bis 2031 >>>>> Key 2: CN=ASUSTeK MotherBoard SW Key Certificate 2011 bis 2031 >>>>> Key 3: C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2010 >>>>> 2011 bis 19.10.2026 >>>>> Key 4: C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2010 >>>>> 2013 bis 2035 >>>>> Key 5: C=GB, ST=Isle of Man, L=Douglas, O=Canonical Ltd., CN=Canonical Ltd. Master Certificate Authority >>>>> 2012 bis 2042 >>>>> >>>>> mokutil --kek >>>>> Key 1: CN=ASUSTeK Notebook KEK Certificate 2011 bis 2031 >>>>> Key 2: C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Corporation KEK CA 2011 >>>>> 2011 bis 24.06.2026 >>>>> Key 3: C=US, O=Microsoft Corporation, CN=Microsoft RSA Devices Root CA 2021 >>>>> 2023 bis 2038 >>>>> >>>>> mokutil --list-enrolled >>>>> Key 1: CN=SUSE Linux Enterprise Secure Boot CA, C=DE, L=Nuremberg, O=SUSE Linux Products GmbH, OU=Build Team/[email protected] >>>>> 2013 bis 2035 >>>>> >>>>> sbverify_--list /boot/efi/EFI/opensuse/shim.efi >>>>> signature 1 >>>>> image signature issuers: >>>>> - /C=US/ST=Washington/L=Redmond/O=Microsoft Corporation/CN=Microsoft Corporation UEFI CA 2011 >>>>> image signature certificates: >>>>> - subject: /C=US/ST=Washington/L=Redmond/O=Microsoft Corporation/CN=Microsoft Windows UEFI Driver Publisher >>>>> issuer: /C=US/ST=Washington/L=Redmond/O=Microsoft Corporation/CN=Microsoft Corporation UEFI CA 2011 >>>>> - subject: /C=US/ST=Washington/L=Redmond/O=Microsoft Corporation/CN=Microsoft Corporation UEFI CA 2011 >>>>> issuer: /C=US/ST=Washington/L=Redmond/O=Microsoft Corporation/CN=Microsoft Corporation Third Party Marketplace Root >>>>> signature 2 >>>>> image signature issuers: >>>>> - /C=US/O=Microsoft Corporation/CN=Microsoft UEFI CA 2023 >>>>> image signature certificates: >>>>> - subject: /C=US/ST=Washington/L=Redmond/O=Microsoft Corporation/CN=Microsoft UEFI CA 2023 signer >>>>> issuer: /C=US/O=Microsoft Corporation/CN=Microsoft UEFI CA 2023 >>>>> - subject: /C=US/O=Microsoft Corporation/CN=Microsoft UEFI CA 2023 >>>>> issuer: /C=US/O=Microsoft Corporation/CN=Microsoft RSA Devices Root CA 2021 >>>>> signature 3 >>>>> image signature issuers: >>>>> - /CN=SUSE Linux Enterprise Secure Boot CA/C=DE/L=Nuremberg/O=SUSE Linux Products GmbH/OU=Build Team/[email protected] >>>>> image signature certificates: >>>>> - subject: /CN=SUSE Linux Enterprise Secure Boot Signkey/C=DE/L=Nuremberg/O=SUSE Linux Products GmbH/OU=Build Team/[email protected] >>>>> issuer: /CN=SUSE Linux Enterprise Secure Boot CA/C=DE/L=Nuremberg/O=SUSE Linux Products GmbH/OU=Build Team/[email protected] >>>>> >>>>> efi-readvar_-v KEK >>>>> Variable KEK, length 3946 >>>>> KEK: List 0, type X509 >>>>> Signature 0, size 852, owner 3b053091-6c9f-04cc-b1ac-e2a51e3be5f5 >>>>> Subject: >>>>> CN=ASUSTeK Notebook KEK Certificate >>>>> Issuer: >>>>> CN=ASUSTeK Notebook KEK Certificate >>>>> KEK: List 1, type X509 >>>>> Signature 0, size 1532, owner 77fa9abd-0359-4d32-bd60-28f4e78f784b >>>>> Subject: >>>>> C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Corporation KEK CA 2011 >>>>> Issuer: >>>>> C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Corporation Third Party Marketplace Root >>>>> KEK: List 2, type X509 >>>>> Signature 0, size 1478, owner 77fa9abd-0359-4d32-bd60-28f4e78f784b >>>>> Subject: >>>>> C=US, O=Microsoft Corporation, CN=Microsoft Corporation KEK 2K CA 2023 >>>>> Issuer: >>>>> C=US, O=Microsoft Corporation, CN=Microsoft RSA Devices Root CA 2021 >>>> >>