Re: Secure-Boot auf Leap 16.0 - wie aktivieren

Marcus Meissner <[email protected]> Fri, 3 Jul 2026 08:00:17 +0000
Newsgroups gmane.linux.suse.general.german
Organization SUSE Software Solutions Ger many GmbH, Frankenstraße 146, 90461 Nuernberg, Ger many, GF: Jochen Jaser, Andrew McDonald, HRB 36809 , AG Nürnberg
Message-ID <[email protected]>
Hi,

Dieses Updates kommen ueber "fwupd", die es von den "Linux Vendor
Firmware Service (LVFS)" beziehen.

Das sind generell BIOS / UEFI / Firmware updates.

Ciao, Marcus
On Fri, Jul 03, 2026 at 09:33:18AM +0200, Werner Franke wrote:
> Zusatz,
> 
> auf meinem Desktop PC (auch Leap 16.0, aber mit CSM, damit kein Secure-Boot) bekomme ich
> von Discover zwei Updates angeboten
> 
>  - Microsoft KEK CA     2011 -> 2023
>  - Microsoft UEFI dbx   20250902 -> 20260402
> 
> von "Firmware-Aktualisierung (lvfs)".
> Auf dem Laptop habe ich das noch nicht gesehen.
> Was ist "Firmware-Aktualisierung (lvfs)" ?
> Welcher Dienst/Tool ist dafür verantwortlich, dass das kommt ?
> In Myrlyn sehe ich die beiden Updates nicht.
> 
> Gibt es eigentlich eine Möglichkeit herauszufinden was welchen Key benutzt
> um dann den Key identifizieren können, der die Secure Boot Violation
> verursacht ?
> 
> viele Grüße
>   Werner
> 
> Am 02.07.26 um 14:51 schrieb Werner Franke:
> > Hi,
> >   vielen Dank für die Antworten.
> > 
> > ist installiert
> >     shim-16.1-160000.1.1.x86_64
> > 
> > Werden noch anderen Infos benötigt ?
> > 
> > Ich hatte am 29.06.26 auch schon
> >   fwupdmgr get-updates   und
> >   fwupdmgr update
> > gemacht.
> > 
> > Jetzt gemacht
> > root@Idefix (-bash) fwupdmgr get-updates
> > Devices with no available firmware updates:
> >   • ASUSTeK KEK Certificate
> >   • ASUSTeK SW Key Certificate
> >   • MTFDKBA512QGN-1BN1AABGA
> >   • SNV3SM3500G
> >   • System Firmware
> >   • ASUS FHD webcam
> >   • KEK CA
> >   • Master Certificate Authority
> >   • Windows UEFI CA
> > Geräte mit der neuesten verfügbaren Firmware-Version:
> >   • UEFI dbx
> > ────────────────────────────────────────────────
> > Erfolgreich aktualisierte Geräte:
> >   • UEFI dbx (20230301 → 20260402)
> > 
> > viele Grüße
> >    Werner
> > 
> > Am 01.07.26 um 21:54 schrieb Marcus Meissner:
> > > Hi,
> > > 
> > > Ok, ist das Paket shim installiert?
> > > 
> > > Wenn nicht, bitte mal installieren.
> > > 
> > > Ich vermute es ist nicht installiert...
> > > 
> > > Ciao, Marcus
> > > On Wed, Jul 01, 2026 at 06:12:33PM +0200, Werner Franke wrote:
> > > > Hallo Marcus, Stephan, alle,
> > > > 
> > > > Der Laptop startet mit UEFI boot setup.
> > > > Es ist ein ASUS EXPERTBOOK BM 1, der hat kein Legacy-BIOS und auch kein Compatibility Support Module.
> > > > Ich habe im BIOS jedenfalls nichts dazu gefunden.
> > > > 
> > > > (im Gegensatz zu meinem Desktop PC  :-(  )
> > > > 
> > > > Wenn ich Secure Boot im ASUS aktiviere, kommt beim Boot ein roter Bildschirm mit dem Hinweis
> > > > 
> > > >            Secure Boot Violation
> > > > 
> > > >   Invalid signature detected. Check Secure Boot Policy in Setup
> > > > 
> > > > Wird bei der Installation des neuen Leap 16.0 auch alle notwendigen
> > > > Secure-Boot Teile mit installiert, auch wenn Secure-Boot zu dem Zeitpunkt deaktiviert ist ?
> > > > Im BIOS Boot-Men� wird die System-Partition mit "opensuse-secureboot" angezeigt.
> > > > Eine weitere Partition ist nicht vorhanden.
> > > > 
> > > > @Stephan,
> > > > Einen openSUSE Key habe ich nicht explizit installiert.
> > > > Wenn ich die Keys unten richtig interpretiere, ist bei "mokutil --list-enrolled"
> > > > ein "SUSE Linux Enterprise Secure Boot CA" mit langem Ablaufdatum installiert.
> > > > 
> > > > Ich habe gestern, 31.06.26 erstmalig auf dem Laptop an dem Secure-Boot Zeugs
> > > > herumprobiert. Hat da der Fall "Zertifikate ausgelaufen" schon zugeschlagen ?
> > > > 
> > > > Der "CN=Microsoft Corporation KEK CA 2011", der am 24.06.2026 abgelaufen ist.
> > > > 
> > > > liebe Gr��e
> > > >    Werner
> > > > 
> > > > Am 01.07.26 um 11:50 schrieb Marcus Meissner:
> > > > > Hi,
> > > > > 
> > > > > Secure boot braucht normalerweise ein UEFI boot setup. Wenn das System
> > > > > noch in "traditional BIOS" mode ist, muss neu installiert werden zuerst.
> > > > > 
> > > > > AUch wenn es in UEFI boot mode ist, kann sein das unser shim nicht in
> > > > > der Boot Reihenfolge wenn es ohne secure boot installiert wurde.
> > > > > 
> > > > > Also am ehesten muss neu installiert werden muessen.
> > > > > 
> > > > > Ciao, Marcus
> > > > > On Wed, Jul 01, 2026 at 10:06:24AM +0200, Werner Franke wrote:
> > > > > > Hallo zusammen,
> > > > > > 
> > > > > > da im Netz das Thema Secure-Boot aktuell ist, weil Zertifikate auslaufen sollen, habe ich mich etwas mit
> > > > > > diesem Thema besch�ftigt, auch weil in der c't 2026.13 einige Artikel dar�ber abgedruckt sind.
> > > > > > Leider sind die Artikel auf Windows PCs gem�nzt und wie ich da mit den Linux-Rools die
> > > > > > passenden Informationen bekomme, ist mir nicht so recht klar.
> > > > > > (Aus dem Grund sie eventuell auch einige verwendeten Befehle unten falsch bzw. fehlen)
> > > > > > 
> > > > > > Bei meinem neuen ASUS Laptop (Nov 2025), auf dem ich Leap 16.0 frisch installiert hatte, habe ich im UEFI-BIOS
> > > > > > nachgeschaut und festgestellt das dort Secure-Boot deaktiviert ist. Das war anscheinend bei Auslieferung
> > > > > > schon so, denn ich hatte da nicht dran geschraubt.
> > > > > > Nach einem Restore der Keys und aktivieren von Secure-Boot kann ich OpenSUSE nicht mehr booten.
> > > > > > Auch ein "fwupdmgr get-updates" und "fwupdmgr update" hat nichts gebracht.
> > > > > > 
> > > > > > Ich nehme an einige der Keys ist abgelaufen und muss ersetzt werden.
> > > > > > (abgelaufen: bald Key3 (--db) und abgelaufen Key2 (--kek) ??)
> > > > > > Wie aktualisieren?
> > > > > > 
> > > > > > Vielen dank f�r Tipps
> > > > > > 
> > > > > > Werner Franke
> > > > > > 
> > > > > > Folgende Infos habe ich auf dem ACER zusammengetragen:
> > > > > > 
> > > > > > mokutil --db
> > > > > >    Key 1: CN=ASUSTeK Notebook SW Key Certificate      2011 bis 2031
> > > > > >    Key 2: CN=ASUSTeK MotherBoard SW Key Certificate   2011 bis 2031
> > > > > >    Key 3: C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2010
> > > > > >                                                       2011 bis 19.10.2026
> > > > > >    Key 4: C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2010
> > > > > >                                                       2013 bis 2035
> > > > > >    Key 5: C=GB, ST=Isle of Man, L=Douglas, O=Canonical Ltd., CN=Canonical Ltd. Master Certificate Authority
> > > > > >                                                       2012 bis 2042
> > > > > > 
> > > > > > mokutil --kek
> > > > > >    Key 1: CN=ASUSTeK Notebook KEK Certificate         2011 bis 2031
> > > > > >    Key 2: C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Corporation KEK CA 2011
> > > > > >                                                       2011 bis 24.06.2026
> > > > > >    Key 3: C=US, O=Microsoft Corporation, CN=Microsoft RSA Devices Root CA 2021
> > > > > >                                                       2023 bis 2038
> > > > > > 
> > > > > > mokutil --list-enrolled
> > > > > >    Key 1: CN=SUSE Linux Enterprise Secure Boot CA, C=DE, L=Nuremberg, O=SUSE Linux Products GmbH, OU=Build Team/[email protected]
> > > > > >                                                       2013 bis 2035
> > > > > > 
> > > > > > sbverify_--list /boot/efi/EFI/opensuse/shim.efi
> > > > > >    signature 1
> > > > > >     image signature issuers:
> > > > > >      - /C=US/ST=Washington/L=Redmond/O=Microsoft Corporation/CN=Microsoft Corporation UEFI CA 2011
> > > > > >     image signature certificates:
> > > > > >      - subject: /C=US/ST=Washington/L=Redmond/O=Microsoft Corporation/CN=Microsoft Windows UEFI Driver Publisher
> > > > > >        issuer:  /C=US/ST=Washington/L=Redmond/O=Microsoft Corporation/CN=Microsoft Corporation UEFI CA 2011
> > > > > >      - subject: /C=US/ST=Washington/L=Redmond/O=Microsoft Corporation/CN=Microsoft Corporation UEFI CA 2011
> > > > > >        issuer:  /C=US/ST=Washington/L=Redmond/O=Microsoft Corporation/CN=Microsoft Corporation Third Party Marketplace Root
> > > > > >    signature 2
> > > > > >     image signature issuers:
> > > > > >      - /C=US/O=Microsoft Corporation/CN=Microsoft UEFI CA 2023
> > > > > >     image signature certificates:
> > > > > >      - subject: /C=US/ST=Washington/L=Redmond/O=Microsoft Corporation/CN=Microsoft UEFI CA 2023 signer
> > > > > >        issuer:  /C=US/O=Microsoft Corporation/CN=Microsoft UEFI CA 2023
> > > > > >      - subject: /C=US/O=Microsoft Corporation/CN=Microsoft UEFI CA 2023
> > > > > >        issuer:  /C=US/O=Microsoft Corporation/CN=Microsoft RSA Devices Root CA 2021
> > > > > >    signature 3
> > > > > >     image signature issuers:
> > > > > >      - /CN=SUSE Linux Enterprise Secure Boot CA/C=DE/L=Nuremberg/O=SUSE Linux Products GmbH/OU=Build Team/[email protected]
> > > > > >     image signature certificates:
> > > > > >      - subject: /CN=SUSE Linux Enterprise Secure Boot Signkey/C=DE/L=Nuremberg/O=SUSE Linux Products GmbH/OU=Build Team/[email protected]
> > > > > >        issuer:  /CN=SUSE Linux Enterprise Secure Boot CA/C=DE/L=Nuremberg/O=SUSE Linux Products GmbH/OU=Build Team/[email protected]
> > > > > > 
> > > > > >    efi-readvar_-v KEK
> > > > > >     Variable KEK, length 3946
> > > > > >      KEK: List 0, type X509
> > > > > >       Signature 0, size 852, owner 3b053091-6c9f-04cc-b1ac-e2a51e3be5f5
> > > > > >           Subject:
> > > > > >               CN=ASUSTeK Notebook KEK Certificate
> > > > > >           Issuer:
> > > > > >               CN=ASUSTeK Notebook KEK Certificate
> > > > > >      KEK: List 1, type X509
> > > > > >       Signature 0, size 1532, owner 77fa9abd-0359-4d32-bd60-28f4e78f784b
> > > > > >           Subject:
> > > > > >               C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Corporation KEK CA 2011
> > > > > >           Issuer:
> > > > > >               C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Corporation Third Party Marketplace Root
> > > > > >      KEK: List 2, type X509
> > > > > >       Signature 0, size 1478, owner 77fa9abd-0359-4d32-bd60-28f4e78f784b
> > > > > >           Subject:
> > > > > >               C=US, O=Microsoft Corporation, CN=Microsoft Corporation KEK 2K CA 2023
> > > > > >           Issuer:
> > > > > >               C=US, O=Microsoft Corporation, CN=Microsoft RSA Devices Root CA 2021
> > > > > 
> > > 

-- 
Marcus Meissner (he/him), Distinguished Engineer / Senior Project Manager Security
SUSE Software Solutions Germany GmbH, Frankenstrasse 146, 90461 Nuernberg, Germany
GF: Jochen Jaser, Andrew McDonald, HRB 36809, AG Nuernberg