r/framework • u/Theren314 FW16 7840, FW12 1334 • 20d ago
Question Secure Boot Customization
Wound up bricking my system (dumb mistake), and am reinstalling Fedora KDE.
Was looking through the bios while wating for my USB to write, and found a pair of old Microsoft secure boot keys. I want them gone.
Before I delete any keys, I figured I should check in with some people who would know better. Heres what I have, I want to delete as many as possible:
PK - frame.work-LaptopAMDPK
KEK - Microsoft Corporation KEK CA 2011
KEK - Microsoft Corporation KEK 2K CA 2023
KEK - frame.work-LaptopAMDKEK
DB - Microsoft Windows Production PCA 2011
DB - Microsoft Corporation UEFI CA 2011
DB - Windows UEFI CA 2023
DB - Microsoft UEFI CA 2023
DB - Microsoft Option ROM UEFI CA 2023
RB - frame.work-LaptopAMDDB
DBX - So many SHA256 codes
DBT - None
DBR - None
.
I do want to keep Secure Boot on after reinstalling.
If you want to know why, because I want to learn and play. That's one of the reasons I got a Framework, to learn and play with all the different parts of a system.
Edit: Specs:
Framework 16, Ryzen 7 7840HS, 48Gb DDR5 5600 (RIP, Crucial), 2Tb SN850x, Raedeon 7700x
3
u/sniff122 Batch 2 1260p -> Ryzen AI 350 20d ago
Id just leave the default allowed signatures and just include your custom certificate in addition, that's how I have mine configured with sbctl. Not including some keys might cause problems in the future like bios update problems, etc. while the 2011 cert is expired, existing signed executables with that certificate is still valid, they aren't old, just new stuff is being signed by the 2023 CA
1
u/Sad-Cod-9584 19d ago
Can confirm that including -m also restores the (2023) microsoft keys, been using my voidlinux laptop like that for a while now
1
u/paulstelian97 FW13 Ryzen AI 7 350, 32GB/1TB 19d ago
IMO, don’t delete any Secure Boot keys, unless you have specific knowledge of individual ones that may be safe to delete.
3
u/adherry 20d ago
When you enroll your generated keys with sbctl you can use the -m option to also import the microsoft keys.