Device Information
System Model or SKU
Please select one of the following
BIOS VERSION
- 04.02
- quoting fwupdmgr: System Firmware (0.0.3.5 → 0.0.4.2)
DIY Edition information
Technically I'm on a DIY system, but purchased the self-assembly kit by framework. If you need more information, ask, please.
Standalone Operation (Laptop Only)
Are you running your mainboard as a standalone device. Is standalone mode enabled in the BIOS?
Describe the bug
After the update to UEFI 04.02 my secure boot certs were not enrolled in the firmware anymore.
Instead the certs of Framework and Microslop were re-added and updated.
On my FW 13 I enrolled my own RSA4096 keys and deleted all other keys.
I use systemd-boot as my bootloader in combination with unified kernel images.
A fellow Gentoo user with a similar FW 13 mentioned the upgrade went smoothly.
He left the default keys as they are and just added his ones.
(If I'll get more information about differences here I'll add them.)
Steps To Reproduce
Steps to reproduce the behavior:
- Enroll your own custom secure boot keys.
- Update the UEFI to 04.02.
- Get greeted by "We couldn't detect an operating system or bootable device. […]".
Workaround:
- Disable secure boot.
- Reboot into your OS and re-enroll your keys.
- Enable secure boot again.
- Write a github issue ;)
Expected behavior
I expected that the setup prevails, i.e. that only my previously enrolled key would be kept and that only the defaults in the UEFI setup were updated, i.e. the parts of the UEFI that contains the default material that a user can restore by resetting the UEFI to defaults.
Operating System (please complete the following information):
- OS/Distribution: Gentoo/Linux
- Version: 2.18
- Linux Kernel Version:
uname -a: gentoo-kernel 7.1.4
uname -a is a bit noisy: "Linux pygoscelis 7.1.4-framework13 <build ID 1> SMP PREEMPT Sat Jul 18 22:00:00 CEST 2026 x86_64 AMD Ryzen AI 9 HX 370 w/ Radeon 890M AuthenticAMD GNU/Linux"
Device Information
System Model or SKU
Please select one of the following
BIOS VERSION
DIY Edition information
Technically I'm on a DIY system, but purchased the self-assembly kit by framework. If you need more information, ask, please.
Standalone Operation (Laptop Only)
Are you running your mainboard as a standalone device. Is standalone mode enabled in the BIOS?
Describe the bug
After the update to UEFI 04.02 my secure boot certs were not enrolled in the firmware anymore.
Instead the certs of Framework and Microslop were re-added and updated.
On my FW 13 I enrolled my own RSA4096 keys and deleted all other keys.
I use systemd-boot as my bootloader in combination with unified kernel images.
A fellow Gentoo user with a similar FW 13 mentioned the upgrade went smoothly.
He left the default keys as they are and just added his ones.
(If I'll get more information about differences here I'll add them.)
Steps To Reproduce
Steps to reproduce the behavior:
Workaround:
Expected behavior
I expected that the setup prevails, i.e. that only my previously enrolled key would be kept and that only the defaults in the UEFI setup were updated, i.e. the parts of the UEFI that contains the default material that a user can restore by resetting the UEFI to defaults.
Operating System (please complete the following information):
uname -a: gentoo-kernel 7.1.4uname -a is a bit noisy: "Linux pygoscelis 7.1.4-framework13 <build ID 1> SMP PREEMPT Sat Jul 18 22:00:00 CEST 2026 x86_64 AMD Ryzen AI 9 HX 370 w/ Radeon 890M AuthenticAMD GNU/Linux"