I'm also unable to update to the latest uefi-dbx:
```
$ fwupdmgr update
...
Blocked executable in the ESP, ensure grub and shim are up to date:
/boot/EFI/EFI/debian/shimx64.efi Authenticode checksum
[af79b14064601bc0987d4747af1e914a228c05d622ceda03b7a4f67014fee767] is
present in dbx
```
I am on the latest shims though:
```
root@rider:/boot/EFI/EFI/debian# dpkg -l | awk '/ shim/ {print $1"
"$2"\t\t"$3}'
ii node-set-immediate-shim 2.0.0-2
ii shim-helpers-amd64-signed 1+15.6+1
ii shim-signed:amd64 1.38+15.4-7
ii shim-signed-common 1.38+15.4-7
ii shim-unsigned 15.7-1
```
And I've run `grub-install` with my EFI dir mounted. What's interesting
is the version in EFI is different than the version staged by the package:
```
# sum /usr/lib/shim/shimx64.efi /boot/EFI/EFI/debian/shimx64.efi
47979 918 /usr/lib/shim/shimx64.efi
36147 913 /boot/EFI/EFI/debian/shimx64.efi
```
I even explicitly ran it with `--uefi-secure-boot` to ensure it installs
the shim binary.
--
Phil Dibowitz p...@ipom.com
Open Source software and tech docs Insanity Palace of Metallica
http://www.phildev.net/ http://www.ipom.com/
"Be who you are and say what you feel, because those who mind don't
matter and those who matter don't mind."
- Dr. Seuss