18.06.2026 | 20 Uhr | krautspace Jena - Vortrag:
Secure Boot Control - Secure Boot ohne Microsoft (Arch Linux-based)
18.06.2026 | 20 Uhr | krautspace Jena - Vortrag:
Secure Boot Control - Secure Boot ohne Microsoft (Arch Linux-based)
Problema: Secure Boot Violation. Invalid signature detected.
Vía: @acaele
#Divulgación #Hardware #Tecnología #Cómputo #BIOS #SecureBoot #KeyManamegent #Clonación #Particiones #Acaele #AntonioKhouri #UEFI

Migrazione certificati Secure Boot in Windows 11: guida agli script PowerShell di KB5089549
Il Patch Tuesday di maggio 2026 porta KB5089549, che aggiunge in Windows 11 sette script PowerShell per automatizzare la migrazione dei certificati Secure Boot in vista della scadenza di giugno. Guida completa per sysadmin enterprise.Mich hat etwas wuschig gemacht, dass das Zertifikat für Secure Boot in meinem PC am 24. Juni 2026 abläuft. Der shimx64.efi ist mit genau diesem Zertifikat unterzeichnet.
Das ist aber kein Problem, weil Secure Boot weiter ein efi-file bootet, welches innerhalb der Zeit unterzeichnet war, zu der das Zertifikat noch gültig war. So lange also niemand das shimx64.efi aktualisieren will, braucht es auch auch noch kein neues Zertifikat von Microslop im uefi.

The things you didn't even know you had to worry about. Watched an #ExplainingComputers video last night on "Secure Boot Certificate Expiry (Windows & Linux)". As best as I can tell, I should be okay since I don't have it active:
bok@sqr128zena:~$
sudo mokutil --sb-state
[sudo] password for bok:
SecureBoot disabled
Platform is in Setup Mode
I hope so, since the update command fails:
bok@sqr128zena:~$ sudo fwupdmgr update
WARNING: UEFI capsule updates not available […]
Devices with no available firmware updates:
• SPCC M.2 SSD
• UEFI dbx
I'll see what happens in forty days:
Microsoft Corporation Third Party Marketplace Root
Validity
Not Before: Jun 27 21:22:45 2011 GMT
Not After : Jun 27 21:32:45 2026 GMT
If my March 2015 NUC5i5RYK dies, I'll take it as a sign to upgrade. #Linux #SecureBoot

Microsoft hat im Zuge der Auslieferung der üblichen allmonatlichen Updates für Windows 10 und Windows 11 zum Patch-Day Anfang April einen neuen Ordner mit dem Namen "SecureBoot" hinzugefügt, der wohl manche User verunsichert.
Has anyone succeed to boot a Debian system on an UEFI+Secure boot host with an ISCSI network drive via iPXE?
Having iPXE working with secureboot is okay, they have a signed shim.
Using `sanboot` directive gives me grub, as expected and start the Kernel.
But then the Linux Kernel detects a Secureboot violation and halt the booting process & the machine.
Mood : https://www.youtube.com/shorts/o56qL2t4swA
Doing network booting (#DHCP, #TFTP, #iPXE, #UEFI, #SecureBoot)
I haven't reached the “Oh, that's why” so far. But very annoyed
https://ipxe.org/secboot
“The Secure Boot shim (e.g. ipxe-shim.efi or snponly-shim.efi) will automatically load the iPXE binary with the corresponding name (e.g. ipxe.efi or snponly.efi).”
Definitely not what's happening…
So It kept loading the wrong iPXE firmware (not the snmponly) and I kept wondering why my keyboard wasn't working :<
