logoalt Hacker News

Linux and Secure Boot certificate expiration (2025)

113 pointsby weaksauceyesterday at 6:24 PM55 commentsview on HN

Comments

Benderyesterday at 7:56 PM

They left out the steps to update it. I made a rough attempt at a document for this. [1] Please let me know if I missed a validation step. I have done this on six machines but they were all Linux. Not tested on BSD.

Archive [2] in the event I was too aggressive in blocking bots.

[1] - https://nochan.net/b/Internet-Crap/20260621-Update-Secure-Bo...

[2] - https://archive.is/ml3jv

show 2 replies
0xCMPyesterday at 9:52 PM

> triggering a "de-fragmentation" of the available efivar space so that there's enough contiguous space to deploy the update.

I didn't even realize this could be a problem despite the next paragraph implying it's very well known.

laserbeamyesterday at 7:58 PM

I saw 2-3 flavors of this news. None of them include a basic “how do I check if I need to do anything” guide that a linux newbie can do.

show 2 replies
h4kunamatatoday at 1:12 AM

Well, it seems like keeping secure boot disabled was gonna help me in the future haha

I know it is not recommended but the options to have my own keys seemed a bit of a hack than a solution.

drnick1yesterday at 8:30 PM

Last time I installed Arch, I put Secure Boot in setup mode and enrolled by own keys. The idea of using someone else's keys seems absurd.

its-summertimeyesterday at 7:57 PM

> The KEK updates are going out at ~98% success, and db update is ~99% success

glad to see the opt in fwupd analytics being so useful for something like this

Not envious of the running around contacting vendors they must of been doing on such short order.

arczayesterday at 8:00 PM

What is the convincing reason that MicroSlop is the trusted party to sign the shim with their (presumably NSA-blessed key)? Why is there no charitable equivalent like a small/mini LetsEncrypt foundation for the PKI aspect of Secure Boot? I also do not see a convincing reason it meaningfully improves security posture.

show 6 replies
dangyesterday at 8:32 PM

Discussed at the time (of the article):

Linux and Secure Boot certificate expiration - https://news.ycombinator.com/item?id=44601045 - July 2025 (265 comments)

NelsonMinaryesterday at 8:13 PM

I'm surprised more people aren't freaking out about this. It seems likely a whole lot of Linux machines are going to fail to reboot in the next few months. The problem affects VMs too. I was grateful Proxmox put a little warning in its hypervisor GUI with a button to press to fix the BIOS of its VMs.

Secure Boot has been deeply broken for years, not providing meaningful security on most consumer machines.

show 2 replies
charcircuittoday at 1:24 AM

How do desktop Linux distros avoid attackers from rolling back the operating system to a vulnerable, but signed version?

tsouth2today at 1:01 AM

[dead]

jmclnxyesterday at 8:24 PM

It needs to be said, this is what you get by "trusting" Microsoft.

There really is no need for secure boot in Linux. The only reason to have it is if you dual boot because M/S says so. If using Linux by itself, just disable secure boot and have done with it.

show 1 reply
naturalmovementyesterday at 9:24 PM

The word from Red Hat is existing systems will continue to boot — presumably because they are time-stamped and counter-signed or because the dates are ignored entirely.

99% of secure boot discussions are drowned out by people who don't have a clue what they're talking about, yet are spittingly, furiously mad.

They've also had over a year to prepare for this so if Linux distros are only telling you now, that's on them.

show 2 replies