Comment # 7 on bug 1129471 from
(In reply to Hendrik Woltersdorf from comment #0)
> Sins Tumbleweed 20190314, with kernel 5.0.1-1-default (x86_64) I get the
> following message during boot:
> integrity: Problem loading X.509 certificate -65
> 
> Log snippet:
> [    2.985576] sched_clock: Marking stable (2989021511,
> -3468039)->(2994215803, -8662331)
> [    2.986009] registered taskstats version 1
> [    2.986012] Loading compiled-in X.509 certificates
> [    2.986062] Loaded X.509 cert 'openSUSE Secure Boot Signkey:
> 0332fa9cbf0d88bf21924b0de82a09a54d5defc8'
> [    2.986093] zswap: loaded using pool lzo/zbud
> [    2.998908] Key type big_key registered
> [    3.005600] Key type encrypted registered
> [    3.005606] AppArmor: AppArmor sha1 policy hashing enabled
> [    3.008353] integrity: Loading X.509 certificate: UEFI:db
> [    3.008414] integrity: Loaded X.509 cert 'Microsoft Windows Production
> PCA 2011: a92902398e16c49778cd90f99e4f9ae17c55af53'
> [    3.008415] integrity: Loading X.509 certificate: UEFI:db
> [    3.008452] integrity: Loaded X.509 cert 'Microsoft Corporation UEFI CA
> 2011: 13adbf4309bd82709c8cd54f316ed522988a1bd4'
> [    3.008453] integrity: Loading X.509 certificate: UEFI:db
> [    3.008476] integrity: Loaded X.509 cert 'Acer Database:
> 84f00f5841571abd2cc11a8c26d5c9c8d2b6b0b5'
> [    3.008477] integrity: Loading X.509 certificate: UEFI:db
> [    3.008482] integrity: Problem loading X.509 certificate -65
> [    3.008494] fbcon: Taking over console
> [    3.008496] Error adding keys to platform keyring UEFI:db
> [    3.008497] integrity: Loading X.509 certificate: UEFI:db
> [    3.008501] integrity: Problem loading X.509 certificate -65
> [    3.008505] Error adding keys to platform keyring UEFI:db
> [    3.008596] Console: switching to colour frame buffer device 240x67
> [    3.009680] integrity: Loading X.509 certificate: UEFI:MokListRT
> [    3.009739] integrity: Loaded X.509 cert 'openSUSE Secure Boot Signkey:
> 0332fa9cbf0d88bf21924b0de82a09a54d5defc8'
> [    3.009740] integrity: Loading X.509 certificate: UEFI:MokListRT
> [    3.012608] integrity: Loaded X.509 cert 'openSUSE Secure Boot CA:
> 6842600de22c4c477e95be23dfea9513e5971762'
> [    3.014923] ima: Allocated hash algorithm: sha256
> [    3.052885] evm: Initialising EVM extended attributes:
> 
> hardware: Laptop Acer Aspire A517-51-5832, one year old

Base on this log, there have two unkown certificates can not be parsed. Other
certificates are parsed success. MS Windows, Acer (in db), and openSUSE (in
MOK) are no problem.

Please help to attach the result of "mokutil --db". 

Thanks


You are receiving this mail because: