There have been many YouTubes concerning the rapidly oncoming (26 Jun 2026) expiry of Microsoft CA 2011, and potential dire straits (including bricked motherboards) if Secure Boot is not correctly installed and the system correctly updated. One example is: “Secure Boot Certificate Expiry (Windows & Linux)” at:
https://www.youtube.com/watch?v=_AwzaZmRNsI .
I use OpenSuSE Leap 15.6: I cannot migrate to 16.0 because the kernel no longer supports my Areca RAID card (which contains all my important data and downloads). I originally chose not to implement Secure Boot (perhaps mistakenly feeling I did not want MicroSoft to dictate the software I used), but now realise it is an important tool to protect against a RootKit attack — it protects the (UEFI) BIOS.
I use a Gigabyte X870 AORUS Elite WIFI7 ICE motherboard, which has built-in fTPM2.0, and have even installed their (only) recommended GIGABYTE GC-TPM 2.0 SPI V2. I use UEFI, with appropriate drive partitioning, but cannot get Secure Boot to run. Some symptoms:
sudo mokutil --sb-state
SecureBoot disabled
Platform is in Setup Mode
sudo mokutil --kek
(No kek keys!!)
sudo fwupdmgr refresh
Updating lvfs
Downloading? [ - ]
Successfully downloaded new metadata: 0 local devices supportedsudo fwupdmgr get-updates
Devices with no available firmware updates:
? SSD PLUS 240GB
? UEFI Device Firmware
? UEFI Device Firmware
? USB4 host controller
No updatable devices
lee@mozart:~> sudo fwupdmgr update
Devices with no available firmware updates:
? SSD PLUS 240GB
? UEFI Device Firmware
? UEFI Device Firmware
? USB4 host controller
No updatable devices
I get the impression I have no KEK or other keys.
Questions:
- To date I have not been using Secure Boot. Should I continue to try (so far, abysmal failure).
- Assuming Secure Boot is a good idea, how do I fix this? What will happen to my system after the old 2011 CA Authorisation Certificate expires?
- I note the SUSE Security Keys Portal at: https://www.suse.com/support/security/keys/ . However, this seems to include keys only for Enterprise SuSE. Are OpenSuSE owners not expected to use Secure Boot?
Help and advice desperately needed!!
