Re: Secure-Boot auf Leap 16.0 - wie aktivieren
Werner Franke <[email protected]> Sun, 5 Jul 2026 18:27:14 +0200
| Newsgroups | gmane.linux.suse.general.german |
|---|---|
| Organization | Privat |
| Message-ID | <[email protected]> |
Hallo, irgendwie habe ich den Verdacht, dass da etwas grundsätzlich nicht funktioniert. Im BIOS habe ich die Keys auf Werkseinstellung zurückgesetzt und Secue-Boot aktiviert. Danach wollte ich mit dem USB-Stick, mit dem ich Leap 16.0 auf dem Laptop installiert habe, booten. ==> Secure Boot Violation ISO: Leap-16.0-online-installer-x86_64.install.iso Mit imagewriter habe ich das ISO auf einen USB-Stick geschrieben. Auch ein andrer USB-Stick mit Ventory lieferte Secure Boot Violation (vom 6.07 bis 11.07 bin ich nicht zu Hause und kann nicht antworten) Hat noch jemand einen Tipp. Der Laptop ist ein ASUS EXPERTBOOK BM1, Modelname: BM1503CDA viele Grüße Werner Am 03.07.26 um 16:13 schrieb Werner Franke: [...] >>>>>> >>>>>> Der Laptop startet mit UEFI boot setup. >>>>>> Es ist ein ASUS EXPERTBOOK BM 1, der hat kein Legacy-BIOS und auch kein Compatibility Support Module. >>>>>> Ich habe im BIOS jedenfalls nichts dazu gefunden. >>>>>> >>>>>> (im Gegensatz zu meinem Desktop PC :-( ) >>>>>> >>>>>> Wenn ich Secure Boot im ASUS aktiviere, kommt beim Boot ein roter Bildschirm mit dem Hinweis >>>>>> >>>>>> Secure Boot Violation >>>>>> >>>>>> Invalid signature detected. Check Secure Boot Policy in Setup >>>>>> >>>>>> Wird bei der Installation des neuen Leap 16.0 auch alle notwendigen >>>>>> Secure-Boot Teile mit installiert, auch wenn Secure-Boot zu dem Zeitpunkt deaktiviert ist ? >>>>>> Im BIOS Boot-Men� wird die System-Partition mit "opensuse-secureboot" angezeigt. >>>>>> Eine weitere Partition ist nicht vorhanden. >>>>>> >>>>>> @Stephan, >>>>>> Einen openSUSE Key habe ich nicht explizit installiert. >>>>>> Wenn ich die Keys unten richtig interpretiere, ist bei "mokutil --list-enrolled" >>>>>> ein "SUSE Linux Enterprise Secure Boot CA" mit langem Ablaufdatum installiert. >>>>>> >>>>>> Ich habe gestern, 31.06.26 erstmalig auf dem Laptop an dem Secure-Boot Zeugs >>>>>> herumprobiert. Hat da der Fall "Zertifikate ausgelaufen" schon zugeschlagen ? >>>>>> >>>>>> Der "CN=Microsoft Corporation KEK CA 2011", der am 24.06.2026 abgelaufen ist. >>>>>> >>>>>> liebe Gr��e >>>>>> Werner >>>>>> >>>>>> Am 01.07.26 um 11:50 schrieb Marcus Meissner: >>>>>>> Hi, >>>>>>> >>>>>>> Secure boot braucht normalerweise ein UEFI boot setup. Wenn das System >>>>>>> noch in "traditional BIOS" mode ist, muss neu installiert werden zuerst. >>>>>>> >>>>>>> AUch wenn es in UEFI boot mode ist, kann sein das unser shim nicht in >>>>>>> der Boot Reihenfolge wenn es ohne secure boot installiert wurde. >>>>>>> >>>>>>> Also am ehesten muss neu installiert werden muessen. >>>>>>> >>>>>>> Ciao, Marcus >>>>>>> On Wed, Jul 01, 2026 at 10:06:24AM +0200, Werner Franke wrote: >>>>>>>> Hallo zusammen, >>>>>>>> >>>>>>>> da im Netz das Thema Secure-Boot aktuell ist, weil Zertifikate auslaufen sollen, habe ich mich etwas mit >>>>>>>> diesem Thema besch�ftigt, auch weil in der c't 2026.13 einige Artikel dar�ber abgedruckt sind. >>>>>>>> Leider sind die Artikel auf Windows PCs gem�nzt und wie ich da mit den Linux-Rools die >>>>>>>> passenden Informationen bekomme, ist mir nicht so recht klar. >>>>>>>> (Aus dem Grund sie eventuell auch einige verwendeten Befehle unten falsch bzw. fehlen) >>>>>>>> >>>>>>>> Bei meinem neuen ASUS Laptop (Nov 2025), auf dem ich Leap 16.0 frisch installiert hatte, habe ich im UEFI-BIOS >>>>>>>> nachgeschaut und festgestellt das dort Secure-Boot deaktiviert ist. Das war anscheinend bei Auslieferung >>>>>>>> schon so, denn ich hatte da nicht dran geschraubt. >>>>>>>> Nach einem Restore der Keys und aktivieren von Secure-Boot kann ich OpenSUSE nicht mehr booten. >>>>>>>> Auch ein "fwupdmgr get-updates" und "fwupdmgr update" hat nichts gebracht. >>>>>>>> >>>>>>>> Ich nehme an einige der Keys ist abgelaufen und muss ersetzt werden. >>>>>>>> (abgelaufen: bald Key3 (--db) und abgelaufen Key2 (--kek) ??) >>>>>>>> Wie aktualisieren? >>>>>>>> >>>>>>>> Vielen dank f�r Tipps >>>>>>>> >>>>>>>> Werner Franke >>>>>>>> >>>>>>>> Folgende Infos habe ich auf dem ACER zusammengetragen: >>>>>>>> >>>>>>>> mokutil --db >>>>>>>> Key 1: CN=ASUSTeK Notebook SW Key Certificate 2011 bis 2031 >>>>>>>> Key 2: CN=ASUSTeK MotherBoard SW Key Certificate 2011 bis 2031 >>>>>>>> Key 3: C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2010 >>>>>>>> 2011 bis 19.10.2026 >>>>>>>> Key 4: C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2010 >>>>>>>> 2013 bis 2035 >>>>>>>> Key 5: C=GB, ST=Isle of Man, L=Douglas, O=Canonical Ltd., CN=Canonical Ltd. Master Certificate Authority >>>>>>>> 2012 bis 2042 >>>>>>>> >>>>>>>> mokutil --kek >>>>>>>> Key 1: CN=ASUSTeK Notebook KEK Certificate 2011 bis 2031 >>>>>>>> Key 2: C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Corporation KEK CA 2011 >>>>>>>> 2011 bis 24.06.2026 >>>>>>>> Key 3: C=US, O=Microsoft Corporation, CN=Microsoft RSA Devices Root CA 2021 >>>>>>>> 2023 bis 2038 >>>>>>>> >>>>>>>> mokutil --list-enrolled >>>>>>>> Key 1: CN=SUSE Linux Enterprise Secure Boot CA, C=DE, L=Nuremberg, O=SUSE Linux Products GmbH, OU=Build Team/[email protected] >>>>>>>> 2013 bis 2035 >>>>>>>> >>>>>>>> sbverify_--list /boot/efi/EFI/opensuse/shim.efi >>>>>>>> signature 1 >>>>>>>> image signature issuers: >>>>>>>> - /C=US/ST=Washington/L=Redmond/O=Microsoft Corporation/CN=Microsoft Corporation UEFI CA 2011 >>>>>>>> image signature certificates: >>>>>>>> - subject: /C=US/ST=Washington/L=Redmond/O=Microsoft Corporation/CN=Microsoft Windows UEFI Driver Publisher >>>>>>>> issuer: /C=US/ST=Washington/L=Redmond/O=Microsoft Corporation/CN=Microsoft Corporation UEFI CA 2011 >>>>>>>> - subject: /C=US/ST=Washington/L=Redmond/O=Microsoft Corporation/CN=Microsoft Corporation UEFI CA 2011 >>>>>>>> issuer: /C=US/ST=Washington/L=Redmond/O=Microsoft Corporation/CN=Microsoft Corporation Third Party Marketplace Root >>>>>>>> signature 2 >>>>>>>> image signature issuers: >>>>>>>> - /C=US/O=Microsoft Corporation/CN=Microsoft UEFI CA 2023 >>>>>>>> image signature certificates: >>>>>>>> - subject: /C=US/ST=Washington/L=Redmond/O=Microsoft Corporation/CN=Microsoft UEFI CA 2023 signer >>>>>>>> issuer: /C=US/O=Microsoft Corporation/CN=Microsoft UEFI CA 2023 >>>>>>>> - subject: /C=US/O=Microsoft Corporation/CN=Microsoft UEFI CA 2023 >>>>>>>> issuer: /C=US/O=Microsoft Corporation/CN=Microsoft RSA Devices Root CA 2021 >>>>>>>> signature 3 >>>>>>>> image signature issuers: >>>>>>>> - /CN=SUSE Linux Enterprise Secure Boot CA/C=DE/L=Nuremberg/O=SUSE Linux Products GmbH/OU=Build Team/[email protected] >>>>>>>> image signature certificates: >>>>>>>> - subject: /CN=SUSE Linux Enterprise Secure Boot Signkey/C=DE/L=Nuremberg/O=SUSE Linux Products GmbH/OU=Build Team/[email protected] >>>>>>>> issuer: /CN=SUSE Linux Enterprise Secure Boot CA/C=DE/L=Nuremberg/O=SUSE Linux Products GmbH/OU=Build Team/[email protected] >>>>>>>> >>>>>>>> efi-readvar_-v KEK >>>>>>>> Variable KEK, length 3946 >>>>>>>> KEK: List 0, type X509 >>>>>>>> Signature 0, size 852, owner 3b053091-6c9f-04cc-b1ac-e2a51e3be5f5 >>>>>>>> Subject: >>>>>>>> CN=ASUSTeK Notebook KEK Certificate >>>>>>>> Issuer: >>>>>>>> CN=ASUSTeK Notebook KEK Certificate >>>>>>>> KEK: List 1, type X509 >>>>>>>> Signature 0, size 1532, owner 77fa9abd-0359-4d32-bd60-28f4e78f784b >>>>>>>> Subject: >>>>>>>> C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Corporation KEK CA 2011 >>>>>>>> Issuer: >>>>>>>> C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Corporation Third Party Marketplace Root >>>>>>>> KEK: List 2, type X509 >>>>>>>> Signature 0, size 1478, owner 77fa9abd-0359-4d32-bd60-28f4e78f784b >>>>>>>> Subject: >>>>>>>> C=US, O=Microsoft Corporation, CN=Microsoft Corporation KEK 2K CA 2023 >>>>>>>> Issuer: >>>>>>>> C=US, O=Microsoft Corporation, CN=Microsoft RSA Devices Root CA 2021 >>>>>>> >>>>> >>