Secure Boot dbx Configuration Update
New Linux user here, been using Bazzite for a few months with little issue, none really, other than growing pains. When I run a System Update, I've had this Secure Boot dbx Configuration update thing show up every time, and it remains after rebooting. I don't have Secure Boot turned on.. I turned it off when I installed Bazzite and never changed it back.
I found that I would need to run "fwupdmgr update" to fix this issue. When I do, I get a message that full disk encryption is detected, which after searching that message, seems to be related to Bitlocker and Windows. I'm not dual booting windows on this machine though. I did previously have Win11 on this drive, but I reformatted it and installed Bazzite over it. So 2 questions:
1. Is this a standard thing on Bazzite, as in, did I perhaps select disk encryption on install? I can't recall if that was a thing. And then I can just go ahead with the update? Or is there something else going on here?
2. Is having secure boot on more preferable on Bazzite?
Thanks!



6 Replies
i think you can ignore that if you don't have secure boot enabled, the dbx configuration is like a blacklist for Secure Boot
it can be useful if you play anti-cheat games in a dual-boot configuration since many of them require it these days
thanks, so I guess the reason I'm getting the Full Disk Encryption message is because I encrypted the disk on install. I don't remember doing that LOL. And I can't find any passkey that I might have made.
So I see this mess about full disk encryption - how can I confirm if I enabled that? I didn't originally set a login password when I installed so I was never prompted for one. But have since set one up a few days ago and have had to enter it when performing certain actions.

Hey! nope, I don't get a prompt before teh login screen where I input the password to login.
Any ideas why I'm get that prompt then that FDE is detected?


I did that, but nothing out of the ordinary .. to me at least. Unless that EFI partiton in FAT32 shouldn't be there.
just bumping this to see if anyone can give me some insight as to why I'm getting the Full Disk Encryption message when running the fwupdmgr update command.
Please see screenshots and shit. π