Hi again @Beelink CS-Bony ,
I did some digging and this is what i found.
I ran:
mokutil --pk
and found that the Platform Key is:
Subject: CN=DO NOT TRUST - AMI Test PK
Issuer: CN=DO NOT TRUST - AMI Test PK
SHA1:
65:92:a5:06:36:fa:f8:be:9a:e7:4f:0f:7f:8b:d7:44:fa:44:b3:29
Valid:
Nov 8 2017 - Nov 8 2021
I also ran:
mokutil --kek
and found:
Microsoft Corporation KEK 2K CA 2023
Microsoft Corporation KEK CA 2011
So the 2023 Microsoft KEK is present.
Finally, fwupdmgr security reports:
UEFI secure boot: Enabled
UEFI platform key: Invalid
UEFI db: Not found
I also tried restoring the factory/default Secure Boot keys from the BIOS, but the same AMI Test PK remains.
Is this a known issue that your R&D team knows about? are they going to fix it?