@rodsmith
the MSFT key is there:
ubuntu@xwing:~$ efi-readvar Variable PK, length 862 PK: List 0, type X509 Signature 0, size 834, owner 26dc4851-195f-4ae1-9a19-fbf883bbb35e Subject: CN=DO NOT TRUST - AMI Test PK Issuer: CN=DO NOT TRUST - AMI Test PK Variable KEK, length 1560 KEK: List 0, type X509 Signature 0, size 1532, owner 77fa9abd-0359-4d32-bd60-28f4e78f784b Subject: C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Corporation KEK CA 2011 Issuer: C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Corporation Third Party Marketplace Root Variable db, length 4867 db: List 0, type X509 Signature 0, size 834, owner 26dc4851-195f-4ae1-9a19-fbf883bbb35e Subject: CN=Trust - Lenovo Certificate Issuer: CN=Trust - Lenovo Certificate db: List 1, type X509 Signature 0, size 834, owner 26dc4851-195f-4ae1-9a19-fbf883bbb35e Subject: CN=Trust - Lenovo Certificate Issuer: CN=Trust - Lenovo Certificate db: List 2, type X509 Signature 0, size 1515, owner 77fa9abd-0359-4d32-bd60-28f4e78f784b Subject: C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Production PCA 2011 Issuer: C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2010 db: List 3, type X509 Signature 0, size 1572, owner 77fa9abd-0359-4d32-bd60-28f4e78f784b Subject: C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Corporation UEFI CA 2011 Issuer: C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Corporation Third Party Marketplace Root Variable dbx, length 76 dbx: List 0, type SHA256 Signature 0, size 48, owner 26dc4851-195f-4ae1-9a19-fbf883bbb35e Hash:e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 Variable MokList has no entries
@rodsmith
the MSFT key is there:
ubuntu@xwing:~$ efi-readvar 195f-4ae1- 9a19-fbf883bbb3 5e 0359-4d32- bd60-28f4e78f78 4b 195f-4ae1- 9a19-fbf883bbb3 5e
CN= Trust - Lenovo Certificate
CN= Trust - Lenovo Certificate 195f-4ae1- 9a19-fbf883bbb3 5e
CN= Trust - Lenovo Certificate
CN= Trust - Lenovo Certificate 0359-4d32- bd60-28f4e78f78 4b 0359-4d32- bd60-28f4e78f78 4b 195f-4ae1- 9a19-fbf883bbb3 5e
Hash:e3b0c4429 8fc1c149afbf4c8 996fb92427ae41e 4649b934ca49599 1b7852b855
Variable PK, length 862
PK: List 0, type X509
Signature 0, size 834, owner 26dc4851-
Subject:
CN=DO NOT TRUST - AMI Test PK
Issuer:
CN=DO NOT TRUST - AMI Test PK
Variable KEK, length 1560
KEK: List 0, type X509
Signature 0, size 1532, owner 77fa9abd-
Subject:
C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Corporation KEK CA 2011
Issuer:
C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Corporation Third Party Marketplace Root
Variable db, length 4867
db: List 0, type X509
Signature 0, size 834, owner 26dc4851-
Subject:
Issuer:
db: List 1, type X509
Signature 0, size 834, owner 26dc4851-
Subject:
Issuer:
db: List 2, type X509
Signature 0, size 1515, owner 77fa9abd-
Subject:
C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Production PCA 2011
Issuer:
C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2010
db: List 3, type X509
Signature 0, size 1572, owner 77fa9abd-
Subject:
C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Corporation UEFI CA 2011
Issuer:
C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Corporation Third Party Marketplace Root
Variable dbx, length 76
dbx: List 0, type SHA256
Signature 0, size 48, owner 26dc4851-
Variable MokList has no entries