-
Notifications
You must be signed in to change notification settings - Fork 514
-
|
I've been running Secure Boot with custom keys plus Microsoft's vendor keys for a few years now, and in light of the upcoming expiry of the 2011 Microsoft keys, I just reinstalled my keys (which I've verified now includes both the 2011 and 2023 versions). That reinstall required entering SB Setup Mode, which of course wiped the existing pk, kek, db, and dbx. All of these except the dbx were repopulated by I don't recall this being an issue when I did my original SB setup, though that was a while back. I do know I received a dbx update via So far, I've tried:
Based on these, it feels like maybe the (nearly) empty dbx is causing problems just because fwupd can't identify which version it's upgrading from? I'm by no means an expert, though, so this is a complete guess. Additional, hopefully-relevant, device details:
$ fwupdmgr get-devices 362301da643102b9f38477387e2193e57abaa590
LENOVO 81Y6
β
ββUEFI dbx:
Device ID: 362301da643102b9f38477387e2193e57abaa590
Summary: UEFI revocation database
Vendor: UEFI:Microsoft
Install Duration: 1 second
GUIDs: 14c6aa96-5c0b-5c9f-8889-b0d7207f9af5 β UEFI\CRT_905B17F0A8854E9522CD919DD5137654160D40B531E349A7DFD4F7E1C3BDD3B3&ARCH_X64
f8ba2887-9411-5c36-9cee-88995bb39731 β UEFI\CRT_A1117F516A32CEFCBA3F2D1ACE10A87972FD6BBE8FE0D0B996E09E65D802A503&ARCH_X64
d07ff664-b0e1-5f4e-a723-d7fbcbfcb94f β UEFI\CRT_3CD3F0309EDAE228767A976DD40D9F4AFFC4FBD5218F2E8CC3C9DD97E8AC6F9D&ARCH_X64
Device Flags: β’ Internal device
β’ Updatable
β’ Supported on remote server
β’ Needs a reboot after installation
β’ Device is usable for the duration of the update
β’ Only version upgrades are allowed
β’ Signed Payload
β’ Can tag for emulation
Firmware update history:
$ fwupdmgr get-history
LENOVO 81Y6
β
ββUEFI dbx:
β Device ID: 362301da643102b9f38477387e2193e57abaa590
β Previous version: 20241101
β Update State: Success
β Last modified: 2025-06-27
β GUID: f8ba2887-9411-5c36-9cee-88995bb39731
β Device Flags: β’ Internal device
β β’ Updatable
β β’ Supported on remote server
β β’ Needs a reboot after installation
β β’ Reported to remote server
β β’ Device is usable for the duration of the update
β β’ Only version upgrades are allowed
β β’ Full disk encryption secrets may be invalidated when updating
β β’ Signed Payload
β β’ Can tag for emulation
β
ββSecure Boot dbx Configuration Update:
New version: 20250507
Remote ID: lvfs
Release ID: 115586
Summary: UEFI Secure Boot Forbidden Signature Database
Variant: x64
License: Proprietary
Size: 24.0Β kB
Created: 2025-01-17
Urgency: High
Tested: 2025-06-11
Distribution: fedora 42 (workstation)
Old version: 20241101
Version[fwupd]: 2.0.11
Vendor: Linux Foundation
Release Flags: β’ Trusted payload
β’ Trusted metadata
Description:
This updates the list of forbidden signatures (the "dbx") to the latest release from Microsoft.
|
Beta Was this translation helpful? Give feedback.
All reactions
Replies: 1 comment · 4 replies
-
|
What's the output of |
Beta Was this translation helpful? Give feedback.
All reactions
-
|
and also the output of |
Beta Was this translation helpful? Give feedback.
All reactions
-
|
Sure, here go.
|
Beta Was this translation helpful? Give feedback.
All reactions
-
|
I've opened a PR here: #9122 |
Beta Was this translation helpful? Give feedback.
All reactions
-
|
Nice, thanks! I'll probably wait to test this until the next release hits the Arch repos, but I think it's safe to mark this as solved :) Edit: 2.0.14 was just released, and I immediately got a dbx update. Thanks again! |
Beta Was this translation helpful? Give feedback.
I've opened a PR here: #9122