Old hardware?
Old hardware?
Posted Jul 19, 2025 8:30 UTC (Sat) by linuxtardis (guest, #178362)In reply to: Old hardware? by pabs
Parent article: Linux and Secure Boot certificate expiration
You may also be able to install the new "db" certificate that Microsoft will likely use to sign shim in the future. In [1] it is the "Microsoft UEFI CA 2023" certificate. This is IMO the more important certificate in the short-term, as adding it will allow you to run newly signed bootloaders. Luckily, this is also the certificate that LVFS can potentially update even without the help from vendors. This is because the update package for this certificate is already published and is signed by the old, commonly trusted Microsoft KEK (see [2]).
[1]: https://learn.microsoft.com/en-us/windows-hardware/manufa...
[2]: https://github.com/microsoft/secureboot_objects/blob/main...