Re: Secure-Boot auf Leap 16.0 - wie aktivieren
Werner Franke <[email protected]> Fri, 3 Jul 2026 16:13:24 +0200
| Newsgroups | gmane.linux.suse.general.german |
|---|---|
| Organization | Privat |
| Message-ID | <[email protected]> |
Hi, Danke. Bitte nicht auch über PM verschicken. Ich lese in der Liste mit. Auf dem Laptop: (Ist das das richtige Kommando?) root@Idefix (-bash) fwupdtool get-updates Laden … [***** ]14:01:43.807 GLib-GObject value "529261620" of type 'guint' is invalid or out of range for property 'kind' of type 'guint' 14:01:43.807 GLib-GObject value "3540208773" of type 'guint' is invalid or out of range for property 'last-attempt-status' of type 'guint' Laden … [******************** ]ERROR:tcti:src/tss2-tcti/tctildr-dl.c:263:tctildr_get_default() No standard TCTI could be loaded ERROR:tcti:src/tss2-tcti/tctildr.c:477:tctildr_init_context_data() Failed to instantiate TCTI ERROR:esys:src/tss2-esys/esys_context.c:71:Esys_Initialize() Initialize default tcti. ErrorCode (0x000a000a) Laden … [************************************** ] Devices with no available firmware updates: • ASUSTeK KEK Certificate • ASUSTeK SW Key Certificate • MTFDKBA512QGN-1BN1AABGA • SNV3SM3500G • Unknown Firmware • ASUS FHD webcam • KEK CA • Master Certificate Authority • Windows UEFI CA Geräte mit der neuesten verfügbaren Firmware-Version: • UEFI dbx Für die verbleibenden Geräte sind keine Aktualisierungen verfügbar Viele Grüße Werner Am 03.07.26 um 10:00 schrieb Marcus Meissner: > Hi, > > Dieses Updates kommen ueber "fwupd", die es von den "Linux Vendor > Firmware Service (LVFS)" beziehen. > > Das sind generell BIOS / UEFI / Firmware updates. > > Ciao, Marcus > On Fri, Jul 03, 2026 at 09:33:18AM +0200, Werner Franke wrote: >> Zusatz, >> >> auf meinem Desktop PC (auch Leap 16.0, aber mit CSM, damit kein Secure-Boot) bekomme ich >> von Discover zwei Updates angeboten >> >> - Microsoft KEK CA 2011 -> 2023 >> - Microsoft UEFI dbx 20250902 -> 20260402 >> >> von "Firmware-Aktualisierung (lvfs)". >> Auf dem Laptop habe ich das noch nicht gesehen. >> Was ist "Firmware-Aktualisierung (lvfs)" ? >> Welcher Dienst/Tool ist dafür verantwortlich, dass das kommt ? >> In Myrlyn sehe ich die beiden Updates nicht. >> >> Gibt es eigentlich eine Möglichkeit herauszufinden was welchen Key benutzt >> um dann den Key identifizieren können, der die Secure Boot Violation >> verursacht ? >> >> viele Grüße >> Werner >> >> Am 02.07.26 um 14:51 schrieb Werner Franke: >>> Hi, >>> vielen Dank für die Antworten. >>> >>> ist installiert >>> shim-16.1-160000.1.1.x86_64 >>> >>> Werden noch anderen Infos benötigt ? >>> >>> Ich hatte am 29.06.26 auch schon >>> fwupdmgr get-updates und >>> fwupdmgr update >>> gemacht. >>> >>> Jetzt gemacht >>> root@Idefix (-bash) fwupdmgr get-updates >>> Devices with no available firmware updates: >>> • ASUSTeK KEK Certificate >>> • ASUSTeK SW Key Certificate >>> • MTFDKBA512QGN-1BN1AABGA >>> • SNV3SM3500G >>> • System Firmware >>> • ASUS FHD webcam >>> • KEK CA >>> • Master Certificate Authority >>> • Windows UEFI CA >>> Geräte mit der neuesten verfügbaren Firmware-Version: >>> • UEFI dbx >>> ──────────────────────────────────────────────── >>> Erfolgreich aktualisierte Geräte: >>> • UEFI dbx (20230301 → 20260402) >>> >>> viele Grüße >>> Werner >>> >>> Am 01.07.26 um 21:54 schrieb Marcus Meissner: >>>> Hi, >>>> >>>> Ok, ist das Paket shim installiert? >>>> >>>> Wenn nicht, bitte mal installieren. >>>> >>>> Ich vermute es ist nicht installiert... >>>> >>>> Ciao, Marcus >>>> On Wed, Jul 01, 2026 at 06:12:33PM +0200, Werner Franke wrote: >>>>> Hallo Marcus, Stephan, alle, >>>>> >>>>> Der Laptop startet mit UEFI boot setup. >>>>> Es ist ein ASUS EXPERTBOOK BM 1, der hat kein Legacy-BIOS und auch kein Compatibility Support Module. >>>>> Ich habe im BIOS jedenfalls nichts dazu gefunden. >>>>> >>>>> (im Gegensatz zu meinem Desktop PC :-( ) >>>>> >>>>> Wenn ich Secure Boot im ASUS aktiviere, kommt beim Boot ein roter Bildschirm mit dem Hinweis >>>>> >>>>> Secure Boot Violation >>>>> >>>>> Invalid signature detected. Check Secure Boot Policy in Setup >>>>> >>>>> Wird bei der Installation des neuen Leap 16.0 auch alle notwendigen >>>>> Secure-Boot Teile mit installiert, auch wenn Secure-Boot zu dem Zeitpunkt deaktiviert ist ? >>>>> Im BIOS Boot-Men� wird die System-Partition mit "opensuse-secureboot" angezeigt. >>>>> Eine weitere Partition ist nicht vorhanden. >>>>> >>>>> @Stephan, >>>>> Einen openSUSE Key habe ich nicht explizit installiert. >>>>> Wenn ich die Keys unten richtig interpretiere, ist bei "mokutil --list-enrolled" >>>>> ein "SUSE Linux Enterprise Secure Boot CA" mit langem Ablaufdatum installiert. >>>>> >>>>> Ich habe gestern, 31.06.26 erstmalig auf dem Laptop an dem Secure-Boot Zeugs >>>>> herumprobiert. Hat da der Fall "Zertifikate ausgelaufen" schon zugeschlagen ? >>>>> >>>>> Der "CN=Microsoft Corporation KEK CA 2011", der am 24.06.2026 abgelaufen ist. >>>>> >>>>> liebe Gr��e >>>>> Werner >>>>> >>>>> Am 01.07.26 um 11:50 schrieb Marcus Meissner: >>>>>> Hi, >>>>>> >>>>>> Secure boot braucht normalerweise ein UEFI boot setup. Wenn das System >>>>>> noch in "traditional BIOS" mode ist, muss neu installiert werden zuerst. >>>>>> >>>>>> AUch wenn es in UEFI boot mode ist, kann sein das unser shim nicht in >>>>>> der Boot Reihenfolge wenn es ohne secure boot installiert wurde. >>>>>> >>>>>> Also am ehesten muss neu installiert werden muessen. >>>>>> >>>>>> Ciao, Marcus >>>>>> On Wed, Jul 01, 2026 at 10:06:24AM +0200, Werner Franke wrote: >>>>>>> Hallo zusammen, >>>>>>> >>>>>>> da im Netz das Thema Secure-Boot aktuell ist, weil Zertifikate auslaufen sollen, habe ich mich etwas mit >>>>>>> diesem Thema besch�ftigt, auch weil in der c't 2026.13 einige Artikel dar�ber abgedruckt sind. >>>>>>> Leider sind die Artikel auf Windows PCs gem�nzt und wie ich da mit den Linux-Rools die >>>>>>> passenden Informationen bekomme, ist mir nicht so recht klar. >>>>>>> (Aus dem Grund sie eventuell auch einige verwendeten Befehle unten falsch bzw. fehlen) >>>>>>> >>>>>>> Bei meinem neuen ASUS Laptop (Nov 2025), auf dem ich Leap 16.0 frisch installiert hatte, habe ich im UEFI-BIOS >>>>>>> nachgeschaut und festgestellt das dort Secure-Boot deaktiviert ist. Das war anscheinend bei Auslieferung >>>>>>> schon so, denn ich hatte da nicht dran geschraubt. >>>>>>> Nach einem Restore der Keys und aktivieren von Secure-Boot kann ich OpenSUSE nicht mehr booten. >>>>>>> Auch ein "fwupdmgr get-updates" und "fwupdmgr update" hat nichts gebracht. >>>>>>> >>>>>>> Ich nehme an einige der Keys ist abgelaufen und muss ersetzt werden. >>>>>>> (abgelaufen: bald Key3 (--db) und abgelaufen Key2 (--kek) ??) >>>>>>> Wie aktualisieren? >>>>>>> >>>>>>> Vielen dank f�r Tipps >>>>>>> >>>>>>> Werner Franke >>>>>>> >>>>>>> Folgende Infos habe ich auf dem ACER zusammengetragen: >>>>>>> >>>>>>> mokutil --db >>>>>>> Key 1: CN=ASUSTeK Notebook SW Key Certificate 2011 bis 2031 >>>>>>> Key 2: CN=ASUSTeK MotherBoard SW Key Certificate 2011 bis 2031 >>>>>>> Key 3: C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2010 >>>>>>> 2011 bis 19.10.2026 >>>>>>> Key 4: C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2010 >>>>>>> 2013 bis 2035 >>>>>>> Key 5: C=GB, ST=Isle of Man, L=Douglas, O=Canonical Ltd., CN=Canonical Ltd. Master Certificate Authority >>>>>>> 2012 bis 2042 >>>>>>> >>>>>>> mokutil --kek >>>>>>> Key 1: CN=ASUSTeK Notebook KEK Certificate 2011 bis 2031 >>>>>>> Key 2: C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Corporation KEK CA 2011 >>>>>>> 2011 bis 24.06.2026 >>>>>>> Key 3: C=US, O=Microsoft Corporation, CN=Microsoft RSA Devices Root CA 2021 >>>>>>> 2023 bis 2038 >>>>>>> >>>>>>> mokutil --list-enrolled >>>>>>> Key 1: CN=SUSE Linux Enterprise Secure Boot CA, C=DE, L=Nuremberg, O=SUSE Linux Products GmbH, OU=Build Team/[email protected] >>>>>>> 2013 bis 2035 >>>>>>> >>>>>>> sbverify_--list /boot/efi/EFI/opensuse/shim.efi >>>>>>> signature 1 >>>>>>> image signature issuers: >>>>>>> - /C=US/ST=Washington/L=Redmond/O=Microsoft Corporation/CN=Microsoft Corporation UEFI CA 2011 >>>>>>> image signature certificates: >>>>>>> - subject: /C=US/ST=Washington/L=Redmond/O=Microsoft Corporation/CN=Microsoft Windows UEFI Driver Publisher >>>>>>> issuer: /C=US/ST=Washington/L=Redmond/O=Microsoft Corporation/CN=Microsoft Corporation UEFI CA 2011 >>>>>>> - subject: /C=US/ST=Washington/L=Redmond/O=Microsoft Corporation/CN=Microsoft Corporation UEFI CA 2011 >>>>>>> issuer: /C=US/ST=Washington/L=Redmond/O=Microsoft Corporation/CN=Microsoft Corporation Third Party Marketplace Root >>>>>>> signature 2 >>>>>>> image signature issuers: >>>>>>> - /C=US/O=Microsoft Corporation/CN=Microsoft UEFI CA 2023 >>>>>>> image signature certificates: >>>>>>> - subject: /C=US/ST=Washington/L=Redmond/O=Microsoft Corporation/CN=Microsoft UEFI CA 2023 signer >>>>>>> issuer: /C=US/O=Microsoft Corporation/CN=Microsoft UEFI CA 2023 >>>>>>> - subject: /C=US/O=Microsoft Corporation/CN=Microsoft UEFI CA 2023 >>>>>>> issuer: /C=US/O=Microsoft Corporation/CN=Microsoft RSA Devices Root CA 2021 >>>>>>> signature 3 >>>>>>> image signature issuers: >>>>>>> - /CN=SUSE Linux Enterprise Secure Boot CA/C=DE/L=Nuremberg/O=SUSE Linux Products GmbH/OU=Build Team/[email protected] >>>>>>> image signature certificates: >>>>>>> - subject: /CN=SUSE Linux Enterprise Secure Boot Signkey/C=DE/L=Nuremberg/O=SUSE Linux Products GmbH/OU=Build Team/[email protected] >>>>>>> issuer: /CN=SUSE Linux Enterprise Secure Boot CA/C=DE/L=Nuremberg/O=SUSE Linux Products GmbH/OU=Build Team/[email protected] >>>>>>> >>>>>>> efi-readvar_-v KEK >>>>>>> Variable KEK, length 3946 >>>>>>> KEK: List 0, type X509 >>>>>>> Signature 0, size 852, owner 3b053091-6c9f-04cc-b1ac-e2a51e3be5f5 >>>>>>> Subject: >>>>>>> CN=ASUSTeK Notebook KEK Certificate >>>>>>> Issuer: >>>>>>> CN=ASUSTeK Notebook KEK Certificate >>>>>>> KEK: List 1, type X509 >>>>>>> Signature 0, size 1532, owner 77fa9abd-0359-4d32-bd60-28f4e78f784b >>>>>>> Subject: >>>>>>> C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Corporation KEK CA 2011 >>>>>>> Issuer: >>>>>>> C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Corporation Third Party Marketplace Root >>>>>>> KEK: List 2, type X509 >>>>>>> Signature 0, size 1478, owner 77fa9abd-0359-4d32-bd60-28f4e78f784b >>>>>>> Subject: >>>>>>> C=US, O=Microsoft Corporation, CN=Microsoft Corporation KEK 2K CA 2023 >>>>>>> Issuer: >>>>>>> C=US, O=Microsoft Corporation, CN=Microsoft RSA Devices Root CA 2021 >>>>>> >>>> >