I have a Invalid setting from fwupd ✘ UEFI db: Invalid
but i’m not sure how to fix it. A user on Fedora Forum explained about the meaning of this setting.
I installed my Tumbleweed three months ago, I thought with only checking secure boot enabled, setting password for system and swap, installing tpm2-tools
that was all, but in recent fwupd update i got this feature as invalid.
When i installed the OS left it such this secure boot state.
My bootctl
$ bootctl
System:
Firmware: UEFI 2.70 (American Megatrends 5.17)
Firmware Arch: x64
Secure Boot: enabled (deployed)
TPM2 Support: yes
Measured UKI: no
Boot into FW: supported
Current Boot Loader:
Product: systemd-boot 257.5+suse.8.gc10a66fb4d
Features: ✓ Boot counting
✓ Menu timeout control
✓ One-shot menu timeout control
✓ Default entry control
✓ One-shot entry control
✓ Support for XBOOTLDR partition
✓ Support for passing random seed to OS
✓ Load drop-in drivers
✓ Support Type #1 sort-key field
✓ Support @saved pseudo-entry
✓ Support Type #1 devicetree field
✓ Enroll SecureBoot keys
✓ Retain SHIM protocols
✓ Menu can be disabled
✓ Multi-Profile UKIs are supported
✓ Boot loader set partition information
Partition: /dev/disk/by-partuuid/8be37297-448b-4d46-8e7f-aaaf813f7168
Loader: └─/EFI/systemd/grub.efi
Current Entry: opensuse-tumbleweed-6.14.5-1-default-1.conf
Default Entry: opensuse-tumbleweed-6.14.5-1-default-1.conf
Random Seed:
System Token: set
Exists: yes
Available Boot Loaders on ESP:
ESP: /boot/efi (/dev/disk/by-partuuid/8be37297-448b-4d46-8e7f-aaaf813f7168)
File: ├─/EFI/systemd/MokManager.efi
├─/EFI/systemd/shim.efi
├─/EFI/systemd/grub.efi (systemd-boot 257.5+suse.8.gc10a66fb4d)
├─/EFI/systemd/fwupdx64.efi
├─/EFI/BOOT/MokManager.efi
├─/EFI/BOOT/fallback.efi
└─/EFI/BOOT/BOOTX64.EFI
Boot Loaders Listed in EFI Variables:
Title: openSUSE Boot Manager (systemd-boot)
ID: 0x0000
Status: active, boot-order
Partition: /dev/disk/by-partuuid/8be37297-448b-4d46-8e7f-aaaf813f7168
File: └─/EFI/systemd/shim.efi
Title: Linux Firmware Updater
ID: 0x0001
Status: active, boot-order
Partition: /dev/disk/by-partuuid/8be37297-448b-4d46-8e7f-aaaf813f7168
File: └─/EFI/systemd/shim.efi
Boot Loader Entries:
$BOOT: /boot/efi (/dev/disk/by-partuuid/8be37297-448b-4d46-8e7f-aaaf813f7168)
token: opensuse-tumbleweed
Default Boot Loader Entry:
type: Boot Loader Specification Type #1 (.conf)
title: openSUSE Tumbleweed 20250508 (1@6.14.5-1-default)
id: opensuse-tumbleweed-6.14.5-1-default-1.conf
source: /boot/efi//loader/entries/opensuse-tumbleweed-6.14.5-1-default-1.conf (on the EFI System Partition)
sort-key: opensuse-tumbleweed
version: 1@6.14.5-1-default
linux: /boot/efi//opensuse-tumbleweed/6.14.5-1-default/linux-a6c6ff2034bd25bd70f2b56ab04e638af44d5690
initrd: /boot/efi//opensuse-tumbleweed/6.14.5-1-default/initrd-dcf61a3a3558a04d07b50639aa8e26851d98766e
I don’t know what to do, I’ve read about it on the forum and on the internet, but this part of the enroll keys is completely abstract for my presentation and I’m afraid I’ll damage the system even more. Author of this issue here, but closed as i saw it as my prob more than fwupd issue.
Anyone can shed some light what should i do? Thanks!
My Details:
Operating System: openSUSE Tumbleweed 20250509
KDE Plasma Version: 6.3.5
KDE Frameworks Version: 6.13.0
Qt Version: 6.9.0
Kernel Version: 6.14.5-1-default (64-bit)
Graphics Platform: Wayland
Processors: 8 × Intel® Core™ i7-10700 CPU @ 2.90GHz
Memory: 30.9 GiB of RAM
Graphics Processor: Intel® UHD Graphics 630
Manufacturer: Dell Inc.
Product Name: OptiPlex 5080