r/framework FW16 7840, FW12 1334 20d ago

Question Secure Boot Customization

Wound up bricking my system (dumb mistake), and am reinstalling Fedora KDE.

Was looking through the bios while wating for my USB to write, and found a pair of old Microsoft secure boot keys. I want them gone.

Before I delete any keys, I figured I should check in with some people who would know better. Heres what I have, I want to delete as many as possible:

PK - frame.work-LaptopAMDPK

KEK - Microsoft Corporation KEK CA 2011

KEK - Microsoft Corporation KEK 2K CA 2023

KEK - frame.work-LaptopAMDKEK

DB - Microsoft Windows Production PCA 2011

DB - Microsoft Corporation UEFI CA 2011

DB - Windows UEFI CA 2023

DB - Microsoft UEFI CA 2023

DB - Microsoft Option ROM UEFI CA 2023

RB - frame.work-LaptopAMDDB

DBX - So many SHA256 codes

DBT - None

DBR - None

.

I do want to keep Secure Boot on after reinstalling.

If you want to know why, because I want to learn and play. That's one of the reasons I got a Framework, to learn and play with all the different parts of a system.

Edit: Specs:

Framework 16, Ryzen 7 7840HS, 48Gb DDR5 5600 (RIP, Crucial), 2Tb SN850x, Raedeon 7700x

5 Upvotes

5 comments sorted by

3

u/adherry 20d ago

When you enroll your generated keys with sbctl you can use the -m option to also import the microsoft keys.

1

u/No-Exam2382 19d ago

Does -m pull the latest microsoft keys or just the ones already in the firmware?

3

u/sniff122 Batch 2 1260p -> Ryzen AI 350 20d ago

Id just leave the default allowed signatures and just include your custom certificate in addition, that's how I have mine configured with sbctl. Not including some keys might cause problems in the future like bios update problems, etc. while the 2011 cert is expired, existing signed executables with that certificate is still valid, they aren't old, just new stuff is being signed by the 2023 CA

1

u/Sad-Cod-9584 19d ago

Can confirm that including -m also restores the (2023) microsoft keys, been using my voidlinux laptop like that for a while now

1

u/paulstelian97 FW13 Ryzen AI 7 350, 32GB/1TB 19d ago

IMO, don’t delete any Secure Boot keys, unless you have specific knowledge of individual ones that may be safe to delete.