Signing and subkeys

I have moved my three subkeys generated inside a Disp Qube, to my Librem Key, and with my public.key stored inside my Vault. When I attempt to resign my Bios, I can see the public key, but PureBoot complains there is no default secret key. What should I be doing? Do I need to create a new private key? I want to have my Pureboot signed with subkeys, not my master key?

1 Like

I am also dealing with this problem and don’t want to brick my device. Is there a solution, I know how to generate a new private key via the Pureboot setup, but I want to keep my master key on another keychain. The keys I have are my public key inside my Vault, and three subkeys recommended, that I exported to my LibremKey. The system finds my public key, but still complains about lack of a secret key. Surely the only keys it needs are the ones on my Librem?

1 Like

Provide information about your hardware model and PureBoot release version.

Thanks FranklyFlawless

Model: Purism Librem Mini v2

PureBoot release version: PureBoot-Release-18.1

Any guidance appreciated.

1 Like