22.2. Applying an online Revocation List update
You can update the Secure Boot Revocation List on your system so that Secure Boot prevents known security issues. This procedure is safe and ensures that the update does not prevent your system from booting.
Prerequisites
- Secure Boot is enabled on your system.
- Your system is connected to internet for updates.
Procedure
Determine the current version of the Revocation List:
# *fwupdmgr get-devices*See the
Current versionfield underUEFI dbx.Enable the LVFS Revocation List repository:
# *fwupdmgr enable-remote lvfs*Refresh the repository metadata:
# *fwupdmgr refresh*Apply the Revocation List update:
On the command line:
# *fwupdmgr update*In the graphical interface:
- Open the Software application
- Navigate to the Updates tab.
- Find the Secure Boot dbx Configuration Update entry.
- Click .
-
At the end of the update,
fwupdmgror Software asks you to reboot the system. Confirm the reboot.
Verification
After the reboot, check the current version of the Revocation List again:
# *fwupdmgr get-devices*