Package: shim-signed
Version: 1.47+15.8-1 (Actually 1.48+16.1-2)
Severity: serious
Justification: unsure
X-Debbugs-Cc: [email protected]
User: [email protected]
Usertags: amd64

Dear Maintainer,

Running apt update with tries to install shim-signed_1.48+16.1-2_amd64.deb but
fails with the following:

No valid UEFI Secure Boot signatures found

 │
 │ UEFI Secure Boot is enabled on your system, but the signed shim binary in
this package is not signed with a key that your system trusts. This is a FATAL
ERROR - your system will not currently boot with this
 │ signed shim installed.
 │
 │ To fix this error, you probably need to update the trusted certificates list
(DB) on your system. See
 │
 │ https://wiki.debian.org/SecureBoot/CAChanges
 │
 │ for more information about how to do this.

mokutil --sb-state
SecureBoot disabled
Platform is in Setup Mode

mokutil --list-enrolled
#Only have
Subject: CN=Debian Secure Boot CA

Points to https://wiki.debian.org/SecureBoot/CAChanges
Which just says:
"More to come soon..."




-- System Information:
Debian Release: forky/sid
  APT prefers unstable-debug
  APT policy: (500, 'unstable-debug'), (500, 'unstable')
Architecture: amd64 (x86_64)
Foreign Architectures: i386

Kernel: Linux 6.19.11+deb14-amd64 (SMP w/12 CPU threads; PREEMPT)
Kernel taint flags: TAINT_PROPRIETARY_MODULE, TAINT_OOT_MODULE, 
TAINT_UNSIGNED_MODULE
Locale: LANG=en_NZ.UTF-8, LC_CTYPE=en_NZ.UTF-8 (charmap=UTF-8), 
LANGUAGE=en_NZ:en
Shell: /bin/sh linked to /usr/bin/dash
Init: systemd (via /run/systemd/system)

Versions of packages shim-signed depends on:
ii  grub-efi-amd64-bin         2.14~git20250718.0e36779-2
ii  grub2-common               2.14~git20250718.0e36779-2
ii  shim-helpers-amd64-signed  1+16.1+2
iu  shim-signed-common         1.48+16.1-2

shim-signed recommends no packages.

shim-signed suggests no packages.

-- debconf information:
* shim-signed/no-valid-sigs:
  shim-signed/revoked-sig:

Reply via email to