BIOS 3.25 Framework 11, Secure boot is AFU

Framework Laptop 13, 11th Gen Intel, BIOS 03.25.

Secure Boot Database is Unlocked, Secure Boot Disabled, PK Signature List empty.
Restore Secure Boot to Factory Settings does not restore the PK.
TPM has been cleared successfully.
I followed the official BIOS 3.22 missing-Secure-Boot-key recovery procedure using Framework_Laptop_13_11th_Gen_Intel_Core_BIOS_3.22_ClearVar.zip, SHA256 7B3B...AC3A.
The EFI updater reports Error 387: Update to image with lower SVN is not allowed, Target 03.22 / Current 03.25. It then reboots, remains on 03.25, and the PK remains absent.
What is the supported ClearVar/key-recovery procedure for an 11th-gen system already running BIOS 03.25?

I’m reticent to downgrade the BIOS back to 3.22 because there are some pretty big changes

What got me all started with this:

i used to have a windows 11 laptop. I now want an Ubuntu laptop. I’m trying to install Ubuntu with the encrypted partition, and the BIOS won’t let me do this.

Check out how the Secure Boot Database is Unlocked, but Secure Boot status is “Disabled” and I can’t enforce secure boot because it’s greyed out.

I’m running BIOS 3.25. The clearvar instructions were for Version 3.22. When I try the clearvar bios, i get this angry message saying it can’t do it because there is a newer version of the BIOS in the system.

So I’m pretty much stuck and unable to get Ubuntu to have a secure boot, right?

IDK if I can plug my Windows 11 nvme back in and boot to that (after typing in the BitLocker key that I’ve safely got stored away).

Any suggestions?

As I remember reading the clearvar process only worked for the v3.22 BIOS, then some resetting and then after an unspecified amount of time Windows updated the new certificates from Microsoft but it was not a straightforward process.

Only after the BIOS has the updated certificates can one then update to the newest BIOS. This certificate migration process is less than clear to everyone.

I did not think Ubuntu needed the updated certificate from Microsoft in order to have secure boot working.

Most Linux distros do not require secure boot to install or to run.

Secure boot has been compromised a number of times and sometimes causes problems itself.

I’ve been running Linux for 30 years on over 100 computers without using secure boot and not one of them has ever been broken into or compromised so it’s not clear to me that secure boot is worth the trouble.

Requires? No, it does not require it in order to get Secure Boot working if you are willing to enroll your own keys. If somebody doesn’t want to go through that hassle then it’s best to have a distro that supports Shim which is signed by MS keys. Pretty sure that’s badly worded/explained but it’s early and gets the point across.

Enrolling your own keys isn’t too difficult assuming everything is working properly. I have no idea how to recover this off the top of my head