I have 2 secure boot downloads in Software. Are these safe to install?

I'm running Zorin 18.1 and I have noticed a couple entries in the Software app that relate to secure boot downloads. "Secure Boot dbx Configuration update 20230501-20260402" and "> Secure Boot Signature Configuration Update 2011-2013"' these are listed under Intergrated Firmware. I was just wondering if I should download these. At the moment I have secure boot turned off. Should I turn it back on before I do these downloads.

no need to turn on secure boot..it will update the secure boot to the newest version is all...with secure boot off the install is safe I do assume zorin is all your running tho

I guess this is an Update for the new Secure Boot Keys. When You don't have the Intention to use Secure Boot, You can ignore it.

For the Case, You want install it, it could be neccessary to enable Secure Boot to make the Update. Another Option would be to make a BIOS Update to get these.

You say that Secure Boot is disabled? Are You sure about that? When You run in Terminal the Command mokutil --sb-state what Output do You get?

1 Like

Yes it is disabled. I'm on dual boot so I disabled it before the june 23 windows update so I could backup my laptop. I have not enabled it yet. Do I actually need it for Zorin or Windows for that matter? I have my backup now so I could strt it if I should.

No I'm on dual boot. Should I enable secure boot because of windows?

Lot of stuff works better in Zorin with secure boot disabled

Need ... Well this is a bit argueable. Secure Boot for Windows can be a nice to have additional Security Layer. At least in my Opinion.

That being said: As I was using Windows in the Past, I had already Secure Boot disabled. And when You go Linux-only, I don't think Secure Boot offers You too much. And the Thing is: Microsoft certifies what is ''secure''. So, the Question is: Do You trust Microsoft enough for that?

I have Secure Boot off. For several Reasons. A practical Reason is that I simply want avoid Issues or addition Setup Steps to make Stuff work. I also use a different Kernel what wouldn't work with enabled Secure Boot.

But at the End: You decide if You want use it or not.

Thanks for your help

Thank you very much for your help

Not worth fixing it to me, am on a Lenovo laptop myself. Some of them installed and went away, another one is just 'stuck' in the updater and I'm ignoring it. I could try and update my bios more or enable secureboot but I don't need them for other reasons than the software updater showing me that update.

You'll find some people troubleshooting say they had to 'delete all their secure boot keys' in order to install the update, however there are Lenovo bios updates that brick the whole laptop if you delete the bootkeys. The motherboard becomes trash. So you'd need to be aware and get an older BIOS first or lucky enough your model doesn't have that problem. No idea how buggy and bad secure boot has been implemented by other OEMs and vendors. Generally not worth your time with such risks involved imho.

1 Like

Thanks for your input. Yes I have a Lenovo and after what I read I will just leave secure boot off and not install those update.