If you're running Linux on hardware with Secure Boot enabled, there's a good chance Microsoft already renewed the shim loader signing keys in your firmware. But "good chance" isn't the same as "definitely."

Here's what you can do right now to audit your Secure Boot state.

Check if Secure Boot is even enabled

mokutil --sb-state

Enter fullscreen mode