Created attachment 853091 [details] mokutil --list-enrolled (In reply to Michal Suchanek from comment #8) > Also you might need --ignore-keyring option Thanks a lot, Michal. The "--ignore-keyring" option worked: > # mokutil --import /etc/uefi/certs/6A4E915C.crt --ignore-keyring > input password: > input password again: After reboot, the new certificate 6A4E915C.crt is enrolled (also seen in the attached "mokutil --list-enrolled" output) and the newest Kernel:stable kernel 5.14.11-1.1.g834dddd successfully booted with Secure Boot enabled.