Framework Laptop 13, 11th Gen Intel, BIOS 03.25.
Secure Boot Database is Unlocked, Secure Boot Disabled, PK Signature List empty.
Restore Secure Boot to Factory Settings does not restore the PK.
TPM has been cleared successfully.
I followed the official BIOS 3.22 missing-Secure-Boot-key recovery procedure using Framework_Laptop_13_11th_Gen_Intel_Core_BIOS_3.22_ClearVar.zip, SHA256 7B3B...AC3A.
The EFI updater reports Error 387: Update to image with lower SVN is not allowed, Target 03.22 / Current 03.25. It then reboots, remains on 03.25, and the PK remains absent.
What is the supported ClearVar/key-recovery procedure for an 11th-gen system already running BIOS 03.25?
I’m reticent to downgrade the BIOS back to 3.22 because there are some pretty big changes
What got me all started with this:
i used to have a windows 11 laptop. I now want an Ubuntu laptop. I’m trying to install Ubuntu with the encrypted partition, and the BIOS won’t let me do this.
Check out how the Secure Boot Database is Unlocked, but Secure Boot status is “Disabled” and I can’t enforce secure boot because it’s greyed out.
I’m running BIOS 3.25. The clearvar instructions were for Version 3.22. When I try the clearvar bios, i get this angry message saying it can’t do it because there is a newer version of the BIOS in the system.
So I’m pretty much stuck and unable to get Ubuntu to have a secure boot, right?
IDK if I can plug my Windows 11 nvme back in and boot to that (after typing in the BitLocker key that I’ve safely got stored away).
Any suggestions?

