Secure Boot DBX configuration refuses to update


Every time I attempt to update the secure boot DBX configuration in software, it always appears again.

Have you tried sudo fwupdmgr refresh & sudo fwupdmgr update?

Yes, I’ve tried both, twice. no promising results.

Have you reset secure boot keys in the BIOS?

No, I only have the option to clear secure boot keys. I have no expertise with this, so I am unfamiliar with what to do.

I am not in any rush to fix things; any help will be appreciated.

What is the output of the sudo fwupdmgr update command?

Upgrade UEFI dbx from 20230501 to 20260402?                                  β•‘
╠══════════════════════════════════════════════════════════════════════════════╣
β•‘ This updates the list of forbidden signatures (the "dbx") to the latest      β•‘
β•‘ release from Microsoft.                                                      β•‘
β•‘                                                                              β•‘
β•‘ Some insecure bootloaders were added, due to security vulnerabilities that   β•‘
β•‘ allowed an attacker to bypass UEFI Secure Boot. The additional entries were  β•‘
β•‘ from:                                                                        β•‘
β•‘                                                                              β•‘
β•‘ β€’ Baramanudi Management Suite                                                β•‘
β•‘ β€’ EAZ EasyFix                                                                β•‘
β•‘ β€’ Finland Matriculation Examination Board                                    β•‘
β•‘ β€’ NTC IT ROSA Linux                                                          β•‘
β•‘ β€’ PC-Doctor                                                                  β•‘
β•‘ β€’ Spyrus WTGCreator                                                          β•‘
β•‘ β€’ WhiteCanyon blancco                                                        β•‘
β•‘ β€’ Some ancient shim releases for OpenSUSE, Oracle and Red Hat                β•‘
β•‘Preformatted text

After i typed "N’ after β€œPerform operation? [Y|n]:” i got:

Devices with the latest available firmware version:
 β€’ Windows UEFI CA

What happens if you type β€œY” to allow it to do the update?

It updates as it would if i updated via Software

Problem solved then?

No, I mean after I update it, it keeps giving me the same update to download in Software.

Have had a similar issue in the past. First make sure your bios is up to date. Then try using the firmware app on flathub, strangely this worked for me when other options did not:

From my knowledge my BIOS is up to date, but firmware still didn’t work for me, somehow.

Software maybe using out of date information.
Once it updates I hope you will stop seeing the update offered.

Maybe it’s just a bug that hopefully will be fixed in the future; it’s not giving me any trouble considering it’s just a secure boot update, so I’m in no rush to fix it. I will, however, have to address it sometime soon, which sucks a bit.