Re: Secure-Boot auf Leap 16.0 - wie aktivieren

Werner Franke <[email protected]> Fri, 3 Jul 2026 16:13:24 +0200
Newsgroups gmane.linux.suse.general.german
Organization Privat
Message-ID <[email protected]>
Hi,

Danke.
Bitte nicht auch über PM verschicken. Ich lese in der Liste mit.

Auf dem Laptop:
(Ist das das richtige Kommando?)

root@Idefix (-bash) fwupdtool get-updates
Laden …                  [***** 
]14:01:43.807 GLib-GObject         value "529261620" of type 'guint' is 
invalid or out of range for property 'kind' of type 'guint'
14:01:43.807 GLib-GObject         value "3540208773" of type 'guint' is 
invalid or out of range for property 'last-attempt-status' of type 'guint'
Laden …                  [******************** 
]ERROR:tcti:src/tss2-tcti/tctildr-dl.c:263:tctildr_get_default() No 
standard TCTI could be loaded
ERROR:tcti:src/tss2-tcti/tctildr.c:477:tctildr_init_context_data() 
Failed to instantiate TCTI
ERROR:esys:src/tss2-esys/esys_context.c:71:Esys_Initialize() Initialize 
default tcti. ErrorCode (0x000a000a)
Laden …                  [************************************** ]
Devices with no available firmware updates:
  • ASUSTeK KEK Certificate
  • ASUSTeK SW Key Certificate
  • MTFDKBA512QGN-1BN1AABGA
  • SNV3SM3500G
  • Unknown Firmware
  • ASUS FHD webcam
  • KEK CA
  • Master Certificate Authority
  • Windows UEFI CA
Geräte mit der neuesten verfügbaren Firmware-Version:
  • UEFI dbx
Für die verbleibenden Geräte sind keine Aktualisierungen verfügbar

Viele Grüße
   Werner


Am 03.07.26 um 10:00 schrieb Marcus Meissner:
> Hi,
> 
> Dieses Updates kommen ueber "fwupd", die es von den "Linux Vendor
> Firmware Service (LVFS)" beziehen.
> 
> Das sind generell BIOS / UEFI / Firmware updates.
> 
> Ciao, Marcus
> On Fri, Jul 03, 2026 at 09:33:18AM +0200, Werner Franke wrote:
>> Zusatz,
>>
>> auf meinem Desktop PC (auch Leap 16.0, aber mit CSM, damit kein Secure-Boot) bekomme ich
>> von Discover zwei Updates angeboten
>>
>>   - Microsoft KEK CA     2011 -> 2023
>>   - Microsoft UEFI dbx   20250902 -> 20260402
>>
>> von "Firmware-Aktualisierung (lvfs)".
>> Auf dem Laptop habe ich das noch nicht gesehen.
>> Was ist "Firmware-Aktualisierung (lvfs)" ?
>> Welcher Dienst/Tool ist dafür verantwortlich, dass das kommt ?
>> In Myrlyn sehe ich die beiden Updates nicht.
>>
>> Gibt es eigentlich eine Möglichkeit herauszufinden was welchen Key benutzt
>> um dann den Key identifizieren können, der die Secure Boot Violation
>> verursacht ?
>>
>> viele Grüße
>>    Werner
>>
>> Am 02.07.26 um 14:51 schrieb Werner Franke:
>>> Hi,
>>>    vielen Dank für die Antworten.
>>>
>>> ist installiert
>>>      shim-16.1-160000.1.1.x86_64
>>>
>>> Werden noch anderen Infos benötigt ?
>>>
>>> Ich hatte am 29.06.26 auch schon
>>>    fwupdmgr get-updates   und
>>>    fwupdmgr update
>>> gemacht.
>>>
>>> Jetzt gemacht
>>> root@Idefix (-bash) fwupdmgr get-updates
>>> Devices with no available firmware updates:
>>>    • ASUSTeK KEK Certificate
>>>    • ASUSTeK SW Key Certificate
>>>    • MTFDKBA512QGN-1BN1AABGA
>>>    • SNV3SM3500G
>>>    • System Firmware
>>>    • ASUS FHD webcam
>>>    • KEK CA
>>>    • Master Certificate Authority
>>>    • Windows UEFI CA
>>> Geräte mit der neuesten verfügbaren Firmware-Version:
>>>    • UEFI dbx
>>> ────────────────────────────────────────────────
>>> Erfolgreich aktualisierte Geräte:
>>>    • UEFI dbx (20230301 → 20260402)
>>>
>>> viele Grüße
>>>     Werner
>>>
>>> Am 01.07.26 um 21:54 schrieb Marcus Meissner:
>>>> Hi,
>>>>
>>>> Ok, ist das Paket shim installiert?
>>>>
>>>> Wenn nicht, bitte mal installieren.
>>>>
>>>> Ich vermute es ist nicht installiert...
>>>>
>>>> Ciao, Marcus
>>>> On Wed, Jul 01, 2026 at 06:12:33PM +0200, Werner Franke wrote:
>>>>> Hallo Marcus, Stephan, alle,
>>>>>
>>>>> Der Laptop startet mit UEFI boot setup.
>>>>> Es ist ein ASUS EXPERTBOOK BM 1, der hat kein Legacy-BIOS und auch kein Compatibility Support Module.
>>>>> Ich habe im BIOS jedenfalls nichts dazu gefunden.
>>>>>
>>>>> (im Gegensatz zu meinem Desktop PC  :-(  )
>>>>>
>>>>> Wenn ich Secure Boot im ASUS aktiviere, kommt beim Boot ein roter Bildschirm mit dem Hinweis
>>>>>
>>>>>             Secure Boot Violation
>>>>>
>>>>>    Invalid signature detected. Check Secure Boot Policy in Setup
>>>>>
>>>>> Wird bei der Installation des neuen Leap 16.0 auch alle notwendigen
>>>>> Secure-Boot Teile mit installiert, auch wenn Secure-Boot zu dem Zeitpunkt deaktiviert ist ?
>>>>> Im BIOS Boot-Men� wird die System-Partition mit "opensuse-secureboot" angezeigt.
>>>>> Eine weitere Partition ist nicht vorhanden.
>>>>>
>>>>> @Stephan,
>>>>> Einen openSUSE Key habe ich nicht explizit installiert.
>>>>> Wenn ich die Keys unten richtig interpretiere, ist bei "mokutil --list-enrolled"
>>>>> ein "SUSE Linux Enterprise Secure Boot CA" mit langem Ablaufdatum installiert.
>>>>>
>>>>> Ich habe gestern, 31.06.26 erstmalig auf dem Laptop an dem Secure-Boot Zeugs
>>>>> herumprobiert. Hat da der Fall "Zertifikate ausgelaufen" schon zugeschlagen ?
>>>>>
>>>>> Der "CN=Microsoft Corporation KEK CA 2011", der am 24.06.2026 abgelaufen ist.
>>>>>
>>>>> liebe Gr��e
>>>>>     Werner
>>>>>
>>>>> Am 01.07.26 um 11:50 schrieb Marcus Meissner:
>>>>>> Hi,
>>>>>>
>>>>>> Secure boot braucht normalerweise ein UEFI boot setup. Wenn das System
>>>>>> noch in "traditional BIOS" mode ist, muss neu installiert werden zuerst.
>>>>>>
>>>>>> AUch wenn es in UEFI boot mode ist, kann sein das unser shim nicht in
>>>>>> der Boot Reihenfolge wenn es ohne secure boot installiert wurde.
>>>>>>
>>>>>> Also am ehesten muss neu installiert werden muessen.
>>>>>>
>>>>>> Ciao, Marcus
>>>>>> On Wed, Jul 01, 2026 at 10:06:24AM +0200, Werner Franke wrote:
>>>>>>> Hallo zusammen,
>>>>>>>
>>>>>>> da im Netz das Thema Secure-Boot aktuell ist, weil Zertifikate auslaufen sollen, habe ich mich etwas mit
>>>>>>> diesem Thema besch�ftigt, auch weil in der c't 2026.13 einige Artikel dar�ber abgedruckt sind.
>>>>>>> Leider sind die Artikel auf Windows PCs gem�nzt und wie ich da mit den Linux-Rools die
>>>>>>> passenden Informationen bekomme, ist mir nicht so recht klar.
>>>>>>> (Aus dem Grund sie eventuell auch einige verwendeten Befehle unten falsch bzw. fehlen)
>>>>>>>
>>>>>>> Bei meinem neuen ASUS Laptop (Nov 2025), auf dem ich Leap 16.0 frisch installiert hatte, habe ich im UEFI-BIOS
>>>>>>> nachgeschaut und festgestellt das dort Secure-Boot deaktiviert ist. Das war anscheinend bei Auslieferung
>>>>>>> schon so, denn ich hatte da nicht dran geschraubt.
>>>>>>> Nach einem Restore der Keys und aktivieren von Secure-Boot kann ich OpenSUSE nicht mehr booten.
>>>>>>> Auch ein "fwupdmgr get-updates" und "fwupdmgr update" hat nichts gebracht.
>>>>>>>
>>>>>>> Ich nehme an einige der Keys ist abgelaufen und muss ersetzt werden.
>>>>>>> (abgelaufen: bald Key3 (--db) und abgelaufen Key2 (--kek) ??)
>>>>>>> Wie aktualisieren?
>>>>>>>
>>>>>>> Vielen dank f�r Tipps
>>>>>>>
>>>>>>> Werner Franke
>>>>>>>
>>>>>>> Folgende Infos habe ich auf dem ACER zusammengetragen:
>>>>>>>
>>>>>>> mokutil --db
>>>>>>>     Key 1: CN=ASUSTeK Notebook SW Key Certificate      2011 bis 2031
>>>>>>>     Key 2: CN=ASUSTeK MotherBoard SW Key Certificate   2011 bis 2031
>>>>>>>     Key 3: C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2010
>>>>>>>                                                        2011 bis 19.10.2026
>>>>>>>     Key 4: C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2010
>>>>>>>                                                        2013 bis 2035
>>>>>>>     Key 5: C=GB, ST=Isle of Man, L=Douglas, O=Canonical Ltd., CN=Canonical Ltd. Master Certificate Authority
>>>>>>>                                                        2012 bis 2042
>>>>>>>
>>>>>>> mokutil --kek
>>>>>>>     Key 1: CN=ASUSTeK Notebook KEK Certificate         2011 bis 2031
>>>>>>>     Key 2: C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Corporation KEK CA 2011
>>>>>>>                                                        2011 bis 24.06.2026
>>>>>>>     Key 3: C=US, O=Microsoft Corporation, CN=Microsoft RSA Devices Root CA 2021
>>>>>>>                                                        2023 bis 2038
>>>>>>>
>>>>>>> mokutil --list-enrolled
>>>>>>>     Key 1: CN=SUSE Linux Enterprise Secure Boot CA, C=DE, L=Nuremberg, O=SUSE Linux Products GmbH, OU=Build Team/[email protected]
>>>>>>>                                                        2013 bis 2035
>>>>>>>
>>>>>>> sbverify_--list /boot/efi/EFI/opensuse/shim.efi
>>>>>>>     signature 1
>>>>>>>      image signature issuers:
>>>>>>>       - /C=US/ST=Washington/L=Redmond/O=Microsoft Corporation/CN=Microsoft Corporation UEFI CA 2011
>>>>>>>      image signature certificates:
>>>>>>>       - subject: /C=US/ST=Washington/L=Redmond/O=Microsoft Corporation/CN=Microsoft Windows UEFI Driver Publisher
>>>>>>>         issuer:  /C=US/ST=Washington/L=Redmond/O=Microsoft Corporation/CN=Microsoft Corporation UEFI CA 2011
>>>>>>>       - subject: /C=US/ST=Washington/L=Redmond/O=Microsoft Corporation/CN=Microsoft Corporation UEFI CA 2011
>>>>>>>         issuer:  /C=US/ST=Washington/L=Redmond/O=Microsoft Corporation/CN=Microsoft Corporation Third Party Marketplace Root
>>>>>>>     signature 2
>>>>>>>      image signature issuers:
>>>>>>>       - /C=US/O=Microsoft Corporation/CN=Microsoft UEFI CA 2023
>>>>>>>      image signature certificates:
>>>>>>>       - subject: /C=US/ST=Washington/L=Redmond/O=Microsoft Corporation/CN=Microsoft UEFI CA 2023 signer
>>>>>>>         issuer:  /C=US/O=Microsoft Corporation/CN=Microsoft UEFI CA 2023
>>>>>>>       - subject: /C=US/O=Microsoft Corporation/CN=Microsoft UEFI CA 2023
>>>>>>>         issuer:  /C=US/O=Microsoft Corporation/CN=Microsoft RSA Devices Root CA 2021
>>>>>>>     signature 3
>>>>>>>      image signature issuers:
>>>>>>>       - /CN=SUSE Linux Enterprise Secure Boot CA/C=DE/L=Nuremberg/O=SUSE Linux Products GmbH/OU=Build Team/[email protected]
>>>>>>>      image signature certificates:
>>>>>>>       - subject: /CN=SUSE Linux Enterprise Secure Boot Signkey/C=DE/L=Nuremberg/O=SUSE Linux Products GmbH/OU=Build Team/[email protected]
>>>>>>>         issuer:  /CN=SUSE Linux Enterprise Secure Boot CA/C=DE/L=Nuremberg/O=SUSE Linux Products GmbH/OU=Build Team/[email protected]
>>>>>>>
>>>>>>>     efi-readvar_-v KEK
>>>>>>>      Variable KEK, length 3946
>>>>>>>       KEK: List 0, type X509
>>>>>>>        Signature 0, size 852, owner 3b053091-6c9f-04cc-b1ac-e2a51e3be5f5
>>>>>>>            Subject:
>>>>>>>                CN=ASUSTeK Notebook KEK Certificate
>>>>>>>            Issuer:
>>>>>>>                CN=ASUSTeK Notebook KEK Certificate
>>>>>>>       KEK: List 1, type X509
>>>>>>>        Signature 0, size 1532, owner 77fa9abd-0359-4d32-bd60-28f4e78f784b
>>>>>>>            Subject:
>>>>>>>                C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Corporation KEK CA 2011
>>>>>>>            Issuer:
>>>>>>>                C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Corporation Third Party Marketplace Root
>>>>>>>       KEK: List 2, type X509
>>>>>>>        Signature 0, size 1478, owner 77fa9abd-0359-4d32-bd60-28f4e78f784b
>>>>>>>            Subject:
>>>>>>>                C=US, O=Microsoft Corporation, CN=Microsoft Corporation KEK 2K CA 2023
>>>>>>>            Issuer:
>>>>>>>                C=US, O=Microsoft Corporation, CN=Microsoft RSA Devices Root CA 2021
>>>>>>
>>>>
>