Driver FixRecommendedSound, Wi-Fi or graphics acting up? Check drivers firstFind missing or outdated drivers fast.Check DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run Scan×
Skip to content
World desk3 min

Need Confirmation for My Linux Kernel Build Changes: What the Linux Foundation Forum Reply Actually Confirms

A Linux Foundation Forums respondent confirmed a 2022 fix for a missing Debian certificate dependency, while warning that clearing kernel signing and trusted-key settings is context-specific.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

In the January 2022 Linux Foundation Forums discussion, ShuahKhanLF confirmed the poster’s change in that specific build context. The reply described the relevant configuration as clearing CONFIG_MODULE_SIG_KEY and CONFIG_SYSTEM_TRUSTED_KEYS to indicate that signing and trusted keys are not being used. That is a context-bound forum confirmation, not a guarantee for every kernel version, distribution, or security policy.

What error was reported?

The poster said make oldconfig or make all stopped because debian/canonical-certs.pem was required by certs/x509_certificate_list, but no make rule existed to create it. The discussion is in the Linux Foundation Forums’ LFD103 Class Forum and began in January 2022.

The poster reported following an Ask Ubuntu article, generating certs/mycert.pem with OpenSSL, and changing kernel configuration values to reference that file. The question was whether those changes were correct.

What did the forum respondent confirm?

“Yes this is the right change to make. You are clearing the CONFIG_MODULE_SIG_KEY and CONFIG_SYSTEM_TRUSTED_KEYS to indicate keys aren’t used.”

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

— ShuahKhanLF, Linux Foundation Forums discussion

That statement confirms the change as described in that thread. It does not establish that disabling or clearing these settings is appropriate for a different kernel tree, distribution build, Secure Boot arrangement, or organization that requires signed modules and trusted certificates.

How to interpret the reported workaround

Item What the thread reports What is established
Missing dependency debian/canonical-certs.pem was requested for certs/x509_certificate_list. This was the build failure described by the original poster.
Local certificate The poster generated certs/mycert.pem with OpenSSL. The source does not independently validate the generated certificate or its parameters.
Kernel configuration The poster changed signing/trusted-key configuration values to point at the local file; the respondent characterized the relevant change as clearing CONFIG_MODULE_SIG_KEY and CONFIG_SYSTEM_TRUSTED_KEYS. The confirmation applies to the configuration shown in that discussion, not universally.

Checks to make before reusing the change

  1. Identify the exact kernel source and distribution configuration. A Debian- or Ubuntu-oriented source tree may expect distribution certificate paths that are absent from a separately obtained or modified tree.
  2. Inspect the symbols in the tree you are building. Confirm how that version defines and consumes CONFIG_MODULE_SIG_KEY and CONFIG_SYSTEM_TRUSTED_KEYS; symbol behavior can differ across kernel versions and vendor configurations.
  3. Decide whether your build needs signing or trusted keys. Clearing the settings indicates that those keys are not being used, which may be unsuitable where module verification, Secure Boot integration, or a local trust chain is required.
  4. Follow the distribution’s build instructions first. If the build is intended to reproduce a distribution kernel, use the certificate path and key-handling procedure documented for that release rather than copying a forum workaround.
  5. Recheck the resulting configuration and build output. A successful make invocation only shows that this dependency problem was handled; it does not prove that the resulting kernel meets your signing or trust requirements.

What the thread does not prove

  • It does not identify a precise kernel version or fully document the poster’s distribution build environment.
  • It does not show that the workaround is valid for every current Ubuntu or Debian release.
  • It does not provide a general recommendation to disable module signing or trusted certificates.
  • It does not include a confirmed answer to the February 2025 follow-up asking whether the information helps users of Ubuntu newer than 20.04.

Source and date

Read the original discussion, including the February 2025 follow-up, at Linux Foundation Forums: “Need someone confirmation for the changes I did”. Treat the reply as historical, context-specific guidance and compare it with the documentation for the kernel source and distribution you are actually building.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

The Bottom Line

The forum answer is a confirmation of the poster’s January 2022 configuration change, not blanket approval for modern kernels. Reuse it only after checking your source tree’s certificate expectations and deciding whether your build can safely operate without module-signing and trusted-key configuration.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. Shenzhen desk3 min
    HONOR Expands Beyond Smartphones With Humanoid Robot RevealHONOR said it unveiled its first humanoid robot at MWC 2026 and named shopping assistance, workplace inspections, and supportive companionship as intended uses. Later Robotics D1 claims and a reported…
  2. Cupertino desk5 min
    Apple Unveils AirPods Max 2: The Upgrade That Should Have Happened Years AgoAirPods Max 2 adds H2-powered audio features and Apple claims up to 1.5× more effective ANC, but its design, Smart Case, and 20-hour battery rating are unchanged. Wired lossless audio…
  3. Cupertino desk4 min
    Apple’s OLED Touch MacBooks Are Coming—but the Dynamic Island Is the Real GambleApple has not announced an OLED touchscreen MacBook, but reports point to high-end models arriving in late 2026 or early 2027. The reported Mac Dynamic Island could be useful, but…
Recommended PC Tool
Recommended PC Tool
Windows Errors? Fix Them Before They SpreadFree repair scan
Outdated Drivers Are Slowing You DownFree scan - exact matches

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.