Secure Boot Certificate expiration effects

Good. Linux itself is a form of "secure boot". :slight_smile:

EDIT:
Moderator Note:

@wsmather, I hope you do not mind if I sit next to you in this post for a moment and spew the existence of this new thread.

This topic is split from a pinned thread.

The following posts here are member thoughts and opinions as well as some fears covering MS influence over GnuLinux.

WsMather, I will hop up out of your post, now. If I was a good and decent sort of fellow, I would, like a camper, leave the site as I found it.
But, most likely, I left a tin can laying on the ground somewhere and a circle of rocks with embers smoldering within it.

3 Likes

a secure boot controlled by microsoft, is this really secure ?
Linux doesn't need this creepy control

3 Likes

Guess I wasn't clear. Sorry. My point was LInux out of the box is more secure than Windows, even with their creation - secure boot. I have it disabled on both my Linux boxes.

1 Like

I agree and I guess I was not clear to :wink:

1 Like

Looks like Microslop is still trying to keep Linux out of the hands of us all they wish to stay in control...sad if ya think about it. but expected..surprised they havnt called us racist......lol

1 Like

Every time developers change something, they make it harder for newbies. I dont understand this constant push to drop support for something, then reinvent the wheel, which many cant put on. This is why computing is always hit or miss, as long as someone keeps making changes. It really gets old fast.


An after they say "why people don't want to use linux?"...

3 Likes

The problem with doing that is that come June 24th, the update will prevent any GNU/Linux from booting.

The LTS issue is that newer hardware is likely to come with this pre-installed, making demand for dedicated Linux hardware grow - but as it is a scarce resource, the prices for these machines too will grow in size.

"The problem with doing that is that come June 24th, the update will prevent any GNU/Linux from booting.".

That is not true.

So how will it not get updated?

I disabled secure boot when I first installed Zorin as dual boot nine months ago and kept it disabled when I deleted windows four months ago. I also used the option to remove all existing certificates at the beginning. I always assumed that I had no real need of secure boot anyway. Am I correct that none of these Microsoft actions will affect me in any way?

Yes.
You are insulated since you are not reliant on their certificates.

2 Likes

Only to bring something up to this:

When using Windows and Secure Boot enabled, this here isn't a big Issue. Microsoft brings out Updates for the Certificates with the normal System Updates. So, when the System is up-to-date this is already done.

One Point would be when Secure Boot is disabled. Then the Update can't preceed as far as I understand it. I mean it lands on the System but doesn't affect. So, enabling Secure Boot would be neccessary and keep it enabled.

Another Option would be a BIOS Update. This adresses that Topic, too. OR: Let Secue Boot disabled and don't even use it.

Can some one tell me if I need to do anything regarding this situation.

I have a new Lenovo laptop that had Win11 home preinstalled which I've since upgraded to Pro with a cheap pro key and all updates are applied so far.

I dual boot with Zorin 18.1 pro.

Secure boot cannot be disabled on this laptop as it causes 2 probllems.

  1. I cant't log into Windows
  2. It totally wrecked The Zorin install as Zorin is also using the secure boot TPM2

In the last couple of days Lenovo released a new bios/UEFI update which I have installed.

I've just carried out the check through Win11 and 1 out of 4 checks returned false

I did query it with Lenovo support and this is their response

Thanks for the details. A quick heads-up on the June changes: recent Secure Boot updates from Microsoft update the UEFI key databases (PK/KEK/db/dbx). After applying a BIOS/firmware package with those changes, some tools will show one of the four checks as “false” if the legacy “Microsoft 3rd‑party UEFI CA 2011” is no longer present or has been revoked. That’s expected behavior and is intended to close security gaps. The newer “Microsoft UEFI CA 2023” and updated dbx entries should be in place.

About dual-boot with Linux: - If your distro still uses an older shim/bootloader signed with the 2011 CA, it may fail Secure Boot after this change. Updating your Linux shim/grub to the latest versions from your distro (signed with the newer CA) typically resolves it.

It's still not clear to me.
Is there anything I need to do?

Thanks

I would not change firmware keys again until you have a Windows recovery key and a Zorin live USB handy. From what Lenovo wrote, the “false” check alone may just mean the old 2011 CA is gone. The practical check is whether Zorin’s shim/grub packages are fully updated before the revocation matters. In Zorin I’d run the normal Software Updater/apt upgrade, then reboot once with Secure Boot still on. If both OSes boot now, I’d avoid resetting Secure Boot keys unless Lenovo or Zorin specifically tell you.

1 Like

When You have an already enabled Secure Boot and Windows is up-to-date, this should be fine for You. Microsoft already has delivered and still delivers the Updates.

And when the mentioned BIOS Update adresses that, too You should have no Issues. On Zorin, You can check it with this, too:

1 Like

Thanks both, I did the 2 checks, all seems to be microsoft stuff.

Should I be seeing anything related to Ubuntu?

I have two computers that used to have Windows 10 on them. One I'm using now I installed Zorin OS by itself on. The other I'm currently trying to install Zorin OS or Mint! I just changed my BIOs in this Computer to TPM enabled-PTT, Secure Boot enabled, Fast Boot disabled, UEFI enabled. I don't plan on using Windows in any fashion other than possibly "bottles" I think it's called. I'm strictly a Home User. Would you recommend I just go back to CSM BIOs Mode, disable UEFI & Secure Boot, & TPM?

Hope you don't mind me butting into this thread. I'm a newbie, I might be ackward when following protocols. I saw your title as Moderator so who best to ask. I just used your suggested sudo mokutil --kek sudo mokutil --db to check for "Certs". I was met with an avalanche of Options. There in is the problem for this Newbie. Whether to go back to My CSM settings, or proceed to learn about & install the Updated Secure Boot shim keys if available? As a home user I'm looking for direction?

It seems that there is something coming. I saw Updates (not all available yet) in the Software Updater what seems to adress that:

When You click on each and then look at the Changelog, You see these:

When You click on the blue Link, You get a Launchpad Website where at the Top is a List of Packages but when You scoll down, You get the Description where the Situation with the Certificates is mentioned. And because of that these Updates are made.

2 Likes