Fedora Workstation - How Can I Pass Security Checks?

Hello all,

When I check Device Security tab in settings menu I see a red “Security Checks Failed” warning. When I click on it I see “UEFI Memory Protection” is red with the explanation. I wonder how I can sort this out so the machine can pass security checks.

I know it’s probably not important but let’s say I am curious and would like to know. I will share system specs and the technical report below.

Device Security Report
======================

Report details
  Date generated:                                  2026-08-03 12:34:39
  fwupd version:                                   2.1.7

System details
  Hardware model:                                  Micro-Star International Co., Ltd. MS-7C56
  Processor:                                       AMD Ryzen 5 5600 6-Core Processor
  OS:                                              Fedora Linux 44 (Forty Four)
  Security level:                                  HSI:0! (v2.1.7)

HSI-1 Tests
  UEFI Bootservice Variables:                      Pass (Locked)
  UEFI Platform Key:                               Pass (Valid)
  TPM v2.0:                                        Pass (Found)
  System Management Mode:                          Pass (Locked)
  BIOS Firmware Updates:                         ! Fail (Not Enabled)
  UEFI Secure Boot:                                Pass (Enabled)
  Fused Platform:                                  Pass (Locked)
  TPM Platform Configuration:                      Pass (Valid)

HSI-2 Tests
  AMD Firmware Write Protection:                 ! Fail (Not Enabled)
  AMD Platform Secure Boot:                      ! Fail (Not Enabled)
  TPM Reconstruction:                              Pass (Valid)
  IOMMU Protection:                                Pass (Enabled)
  Platform Debugging:                              Pass (Locked)

HSI-3 Tests
  UEFI Memory Protection:                        ! Fail (Not Locked)
  Pre-boot DMA Protection:                       ! Fail (Not Enabled)
  AMD Firmware Replay Protection:                ! Fail (Not Supported)
  Suspend To RAM:                                ! Fail (Enabled)
  Control-flow Enforcement Technology:             Pass (Supported)
  Suspend To Idle:                               ! Fail (Not Enabled)

HSI-4 Tests
  Hardware Disk Encryption:                      ! Fail (Not Supported)
  Encrypted RAM:                                 ! Fail (Not Supported)
  Supervisor Mode Access Prevention:               Pass (Enabled)
  AMD Secure Processor Rollback Protection:      ! Fail (Not Enabled)

Runtime Tests
  UEFI NX Protection:                            ! Fail (Not Enabled)
  Linux Swap:                                      Pass (Encrypted)
  UEFI db:                                         Pass (Valid)
  Firmware Updater Verification:                   Pass (Not Tainted)
  Control-flow Enforcement Technology:             Pass (Supported)
  Linux Kernel Verification:                       Pass (Not Tainted)
  Linux Kernel Lockdown:                           Pass (Enabled)

Host security events
  2026-07-31 19:37:27   Linux Kernel Lockdown        Pass (Not Enabled → Enabled)
  2026-07-31 19:37:27   UEFI Secure Boot             Pass (Not Enabled → Enabled)
  2026-07-31 19:22:12   UEFI Memory Protection     ! Fail (Not Enabled → Not Locked)

For information on the contents of this report, see https://fwupd.github.io/hsi.html
# System Details Report
---

## Report details
- **Date generated:**                              2026-08-03 12:40:03

## Hardware Information:
- **Hardware Model:**                              Micro-Star International Co., Ltd. MS-7C56
- **Memory:**                                      32.0 GiB
- **Processor:**                                   AMD Ryzen™ 5 5600 × 12
- **Graphics:**                                    AMD Radeon™ RX 7600
- **Disk Capacity:**                               2.0 TB

## Software Information:
- **Firmware Version:**                            1.M1
- **OS Name:**                                     Fedora Linux 44 (Forty Four)
- **OS Build:**                                    (null)
- **OS Type:**                                     64-bit
- **GNOME Version:**                               50
- **Windowing System:**                            Wayland
- **Kernel Version:**                              Linux 7.1.5-201.fc44.x86_64

It seems this is a functionality that should be provided by the bios provider according to fwupd website: FwupdPlugin – 1.0: Host Security ID Specification

Resolution: Contact your OEM, who may be able to issue a firmware update.”

Do I understand correctly that some security features are hardware related and not necessarily all of them are available for all devices?

Exactly this.

Some might become available with a firmware update, some just may not be available at all for a particular device.