- 
                Notifications
    You must be signed in to change notification settings 
- Fork 514
-
| I've been running Secure Boot with custom keys plus Microsoft's vendor keys for a few years now, and in light of the upcoming expiry of the 2011 Microsoft keys, I just reinstalled my keys (which I've verified now includes both the 2011 and 2023 versions). That reinstall required entering SB Setup Mode, which of course wiped the existing pk, kek, db, and dbx. All of these except the dbx were repopulated by  I don't recall this being an issue when I did my original SB setup, though that was a while back. I do know I received a dbx update via  So far, I've tried: 
 Based on these, it feels like maybe the (nearly) empty dbx is causing problems just because fwupd can't identify which version it's upgrading from? I'm by no means an expert, though, so this is a complete guess. Additional, hopefully-relevant, device details:
 $ fwupdmgr get-devices 362301da643102b9f38477387e2193e57abaa590
LENOVO 81Y6
β
ββUEFI dbx:
      Device ID:          362301da643102b9f38477387e2193e57abaa590
      Summary:            UEFI revocation database
      Vendor:             UEFI:Microsoft
      Install Duration:   1 second
      GUIDs:              14c6aa96-5c0b-5c9f-8889-b0d7207f9af5 β UEFI\CRT_905B17F0A8854E9522CD919DD5137654160D40B531E349A7DFD4F7E1C3BDD3B3&ARCH_X64
                          f8ba2887-9411-5c36-9cee-88995bb39731 β UEFI\CRT_A1117F516A32CEFCBA3F2D1ACE10A87972FD6BBE8FE0D0B996E09E65D802A503&ARCH_X64
                          d07ff664-b0e1-5f4e-a723-d7fbcbfcb94f β UEFI\CRT_3CD3F0309EDAE228767A976DD40D9F4AFFC4FBD5218F2E8CC3C9DD97E8AC6F9D&ARCH_X64
      Device Flags:       β’ Internal device
                          β’ Updatable
                          β’ Supported on remote server
                          β’ Needs a reboot after installation
                          β’ Device is usable for the duration of the update
                          β’ Only version upgrades are allowed
                          β’ Signed Payload
                          β’ Can tag for emulation
Firmware update history:
 $ fwupdmgr get-history
LENOVO 81Y6
β
ββUEFI dbx:
  β   Device ID:          362301da643102b9f38477387e2193e57abaa590
  β   Previous version:   20241101
  β   Update State:       Success
  β   Last modified:      2025-06-27
  β   GUID:               f8ba2887-9411-5c36-9cee-88995bb39731
  β   Device Flags:       β’ Internal device
  β                       β’ Updatable
  β                       β’ Supported on remote server
  β                       β’ Needs a reboot after installation
  β                       β’ Reported to remote server
  β                       β’ Device is usable for the duration of the update
  β                       β’ Only version upgrades are allowed
  β                       β’ Full disk encryption secrets may be invalidated when updating
  β                       β’ Signed Payload
  β                       β’ Can tag for emulation
  β
  ββSecure Boot dbx Configuration Update:
        New version:      20250507
        Remote ID:        lvfs
        Release ID:       115586
        Summary:          UEFI Secure Boot Forbidden Signature Database
        Variant:          x64
        License:          Proprietary
        Size:             24.0Β kB
        Created:          2025-01-17
        Urgency:          High
          Tested:         2025-06-11
          Distribution:   fedora 42 (workstation)
          Old version:    20241101
          Version[fwupd]: 2.0.11
        Vendor:           Linux Foundation
        Release Flags:    β’ Trusted payload
                          β’ Trusted metadata
        Description:
        This updates the list of forbidden signatures (the "dbx") to the latest release from Microsoft.
 | 
Beta Was this translation helpful? Give feedback.
All reactions
Replies: 1 comment · 4 replies
-
| What's the output of  | 
Beta Was this translation helpful? Give feedback.
All reactions
-
| and also the output of  | 
Beta Was this translation helpful? Give feedback.
All reactions
-
| Sure, here go. 
 | 
Beta Was this translation helpful? Give feedback.
All reactions
-
| I've opened a PR here: #9122 | 
Beta Was this translation helpful? Give feedback.
All reactions
-
| Nice, thanks! I'll probably wait to test this until the next release hits the Arch repos, but I think it's safe to mark this as solved :) Edit: 2.0.14 was just released, and I immediately got a dbx update. Thanks again! | 
Beta Was this translation helpful? Give feedback.
I've opened a PR here: #9122