Bug#1112197: fails to boot on a laptop without Microsoft 2011 UEFI CA
Hello Anton!
On Tue, 02 Sep 2025 09:15:16 +0200 Anton Khirnov <anton@khirnov.net> wrote:
> > >my new laptop (ASUS EXPERTBOOK B9403CVAR) fails to boot with Secure Boot
> > >enabled, with the UEFI firmware showing a "Secure Boot violation"
> > >message. This seems to be caused by the fact that shim is signed by
> > >"Microsoft Corporation UEFI CA 2011", which is not present in the
> > >laptop's db list. Instead it has the newer "Windows UEFI CA 2023"
Experiencing the exact same issue on ASUS EXPERTBOOK P1403CVA.
> Yeah...I've already got one email asking how to work around this, so I
> added a quick guide to https://wiki.debian.org/SecureBoot
Thank you very much for updating the wiki with the workaround. It
fixed the issue.
Regards,
Avinash Sonawane
https://rootkea.me
Reply to: