Since September 2025 many users have been unable to install the KEK CA 2023 firmware update. It seems in June affected users may be unable to boot their systems with secure boot enabled. The only “solution” I have found online is to try disabling secure boot which degrades user security.
Does anyone know if a fix is being worked on in time? Or is Ubuntu unable to support secure boot on systems affected by this issue?
Ah I wasn’t aware the 2011 keys were compromised. Wouldn’t it still be worth upgrading to KEK CA 2023 to prevent attacks in the future? Or are the new keys also compromised?
That’s what the update, which fails for some, does. And it’s not only about the compromised keys; those are dealt with by revocation. But then you’d be left without valid keys, hence the new KEK CA, which signs those.
BTW, you might be able to install a UEFI update, containing said KEK CA 2023, via the usual manual procedure. But that depends on whether your hardware vendor provides one.
I wonder if Secure Boot in Setup Mode could be the solution. In that mode machine owners can enroll any key they like.
Another user in the linked thread suggested switching to User Mode fixed it, but you never reacted to that, @letter3770.
Consult your UEFI manual on how to switch Secure Boot modes. I know from more recent visits to that setting on my Thinkpad 495, that Setup Mode can be enabled; one can even wipe all keys, if that’s required. I am not sure if the latter is advisable, though, vis-a-vis “other OS”. But then again, expired keys will be just as useless as a blank key database.