The following posts here are member thoughts and opinions as well as some fears covering MS influence over GnuLinux.
WsMather, I will hop up out of your post, now. If I was a good and decent sort of fellow, I would, like a camper, leave the site as I found it.
But, most likely, I left a tin can laying on the ground somewhere and a circle of rocks with embers smoldering within it.
Guess I wasn't clear. Sorry. My point was LInux out of the box is more secure than Windows, even with their creation - secure boot. I have it disabled on both my Linux boxes.
Looks like Microslop is still trying to keep Linux out of the hands of us all they wish to stay in control...sad if ya think about it. but expected..surprised they havnt called us racist......lol
Every time developers change something, they make it harder for newbies. I dont understand this constant push to drop support for something, then reinvent the wheel, which many cant put on. This is why computing is always hit or miss, as long as someone keeps making changes. It really gets old fast.
The problem with doing that is that come June 24th, the update will prevent any GNU/Linux from booting.
The LTS issue is that newer hardware is likely to come with this pre-installed, making demand for dedicated Linux hardware grow - but as it is a scarce resource, the prices for these machines too will grow in size.
I disabled secure boot when I first installed Zorin as dual boot nine months ago and kept it disabled when I deleted windows four months ago. I also used the option to remove all existing certificates at the beginning. I always assumed that I had no real need of secure boot anyway. Am I correct that none of these Microsoft actions will affect me in any way?
When using Windows and Secure Boot enabled, this here isn't a big Issue. Microsoft brings out Updates for the Certificates with the normal System Updates. So, when the System is up-to-date this is already done.
One Point would be when Secure Boot is disabled. Then the Update can't preceed as far as I understand it. I mean it lands on the System but doesn't affect. So, enabling Secure Boot would be neccessary and keep it enabled.
Another Option would be a BIOS Update. This adresses that Topic, too. OR: Let Secue Boot disabled and don't even use it.
I did query it with Lenovo support and this is their response
Thanks for the details. A quick heads-up on the June changes: recent Secure Boot updates from Microsoft update the UEFI key databases (PK/KEK/db/dbx). After applying a BIOS/firmware package with those changes, some tools will show one of the four checks as “false” if the legacy “Microsoft 3rd‑party UEFI CA 2011” is no longer present or has been revoked. That’s expected behavior and is intended to close security gaps. The newer “Microsoft UEFI CA 2023” and updated dbx entries should be in place.
About dual-boot with Linux: - If your distro still uses an older shim/bootloader signed with the 2011 CA, it may fail Secure Boot after this change. Updating your Linux shim/grub to the latest versions from your distro (signed with the newer CA) typically resolves it.
It's still not clear to me.
Is there anything I need to do?
I would not change firmware keys again until you have a Windows recovery key and a Zorin live USB handy. From what Lenovo wrote, the “false” check alone may just mean the old 2011 CA is gone. The practical check is whether Zorin’s shim/grub packages are fully updated before the revocation matters. In Zorin I’d run the normal Software Updater/apt upgrade, then reboot once with Secure Boot still on. If both OSes boot now, I’d avoid resetting Secure Boot keys unless Lenovo or Zorin specifically tell you.
When You have an already enabled Secure Boot and Windows is up-to-date, this should be fine for You. Microsoft already has delivered and still delivers the Updates.
And when the mentioned BIOS Update adresses that, too You should have no Issues. On Zorin, You can check it with this, too:
I have two computers that used to have Windows 10 on them. One I'm using now I installed Zorin OS by itself on. The other I'm currently trying to install Zorin OS or Mint! I just changed my BIOs in this Computer to TPM enabled-PTT, Secure Boot enabled, Fast Boot disabled, UEFI enabled. I don't plan on using Windows in any fashion other than possibly "bottles" I think it's called. I'm strictly a Home User. Would you recommend I just go back to CSM BIOs Mode, disable UEFI & Secure Boot, & TPM?
Hope you don't mind me butting into this thread. I'm a newbie, I might be ackward when following protocols. I saw your title as Moderator so who best to ask. I just used your suggested sudo mokutil --kek sudo mokutil --db to check for "Certs". I was met with an avalanche of Options. There in is the problem for this Newbie. Whether to go back to My CSM settings, or proceed to learn about & install the Updated Secure Boot shim keys if available? As a home user I'm looking for direction?
When You click on the blue Link, You get a Launchpad Website where at the Top is a List of Packages but when You scoll down, You get the Description where the Situation with the Certificates is mentioned. And because of that these Updates are made.