Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Clear out junk files and repair common Windows errors3Scan for outdated or missing drivers - takes under a minuteIn the January 2022 Linux Foundation Forums discussion, ShuahKhanLF confirmed the poster’s change in that specific build context. The reply described the relevant configuration as clearing CONFIG_MODULE_SIG_KEY and CONFIG_SYSTEM_TRUSTED_KEYS to indicate that signing and trusted keys are not being used. That is a context-bound forum confirmation, not a guarantee for every kernel version, distribution, or security policy.
What error was reported?
The poster said make oldconfig or make all stopped because debian/canonical-certs.pem was required by certs/x509_certificate_list, but no make rule existed to create it. The discussion is in the Linux Foundation Forums’ LFD103 Class Forum and began in January 2022.
The poster reported following an Ask Ubuntu article, generating certs/mycert.pem with OpenSSL, and changing kernel configuration values to reference that file. The question was whether those changes were correct.
What did the forum respondent confirm?
“Yes this is the right change to make. You are clearing the CONFIG_MODULE_SIG_KEY and CONFIG_SYSTEM_TRUSTED_KEYS to indicate keys aren’t used.”
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.#1 Best Overall
— ShuahKhanLF, Linux Foundation Forums discussion
That statement confirms the change as described in that thread. It does not establish that disabling or clearing these settings is appropriate for a different kernel tree, distribution build, Secure Boot arrangement, or organization that requires signed modules and trusted certificates.
Rank #2
How to interpret the reported workaround
| Item | What the thread reports | What is established |
|---|---|---|
| Missing dependency | debian/canonical-certs.pem was requested for certs/x509_certificate_list. |
This was the build failure described by the original poster. |
| Local certificate | The poster generated certs/mycert.pem with OpenSSL. |
The source does not independently validate the generated certificate or its parameters. |
| Kernel configuration | The poster changed signing/trusted-key configuration values to point at the local file; the respondent characterized the relevant change as clearing CONFIG_MODULE_SIG_KEY and CONFIG_SYSTEM_TRUSTED_KEYS. |
The confirmation applies to the configuration shown in that discussion, not universally. |
Checks to make before reusing the change
- Identify the exact kernel source and distribution configuration. A Debian- or Ubuntu-oriented source tree may expect distribution certificate paths that are absent from a separately obtained or modified tree.
- Inspect the symbols in the tree you are building. Confirm how that version defines and consumes
CONFIG_MODULE_SIG_KEYandCONFIG_SYSTEM_TRUSTED_KEYS; symbol behavior can differ across kernel versions and vendor configurations. - Decide whether your build needs signing or trusted keys. Clearing the settings indicates that those keys are not being used, which may be unsuitable where module verification, Secure Boot integration, or a local trust chain is required.
- Follow the distribution’s build instructions first. If the build is intended to reproduce a distribution kernel, use the certificate path and key-handling procedure documented for that release rather than copying a forum workaround.
- Recheck the resulting configuration and build output. A successful make invocation only shows that this dependency problem was handled; it does not prove that the resulting kernel meets your signing or trust requirements.
What the thread does not prove
- It does not identify a precise kernel version or fully document the poster’s distribution build environment.
- It does not show that the workaround is valid for every current Ubuntu or Debian release.
- It does not provide a general recommendation to disable module signing or trusted certificates.
- It does not include a confirmed answer to the February 2025 follow-up asking whether the information helps users of Ubuntu newer than 20.04.
Source and date
Read the original discussion, including the February 2025 follow-up, at Linux Foundation Forums: “Need someone confirmation for the changes I did”. Treat the reply as historical, context-specific guidance and compare it with the documentation for the kernel source and distribution you are actually building.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.The Bottom Line
The forum answer is a confirmation of the poster’s January 2022 configuration change, not blanket approval for modern kernels. Reuse it only after checking your source tree’s certificate expectations and deciding whether your build can safely operate without module-signing and trusted-key configuration.
Quick Recap
Best Value
Rank #4
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




