(In reply to Takashi Iwai from comment #6) > Indeed they seem to have been built with different keys. > > % rpm -ql kernel-default-5.3.18-lp152.19.2.x86_64 | grep /etc/uefi/certs/ > /etc/uefi/certs/F1C08E27.crt > > % rpm -ql kernel-default-5.3.18-lp152.20.7.1.x86_64 | grep /etc/uefi/certs/ > /etc/uefi/certs/188EA6FA.crt IIRC lp152.19 was the GM kernel and lp152.20 is the first maintenance update (I would have to check commit ids to be sure). Could this be the reason why is each signed by a different key?