Package: shim-signed
Version: 1.51~1+deb13u1+16.1-2~deb13u1
Severity: normal

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Dear Maintainer,

As requested, I am filing this bug as even after following the Wiki
instructions, my Lenovo M73 fails to boot in secure boot mode with the
current version of shim-signed in Stable.

Apparently the main keys updated correctly:

# mokutil --db | grep "Subject:.*Microsoft"
        Subject: C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, 
CN=Microsoft Windows Production PCA 2011
        Subject: C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, 
CN=Microsoft Corporation UEFI CA 2011
        Subject: C=US, O=Microsoft Corporation, CN=Microsoft UEFI CA 2023
        Subject: C=US, O=Microsoft Corporation, CN=Microsoft Option ROM UEFI CA 
2023

However, the KEK key did not:

#  mokutil --kek | grep Subject:.*Microsoft
        Subject: C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, 
CN=Microsoft Corporation KEK CA 2011

My attempt to update it showed no update available:

# fwupdtool update
Loading…                 [*******************                    ]17:40:41.296 
FuEngine             failed to add device 
/sys/devices/pci0000:00/0000:00:1f.2/ata2/host1/target1:0:0/1:0:0:0/block/sr0: 
failed to subclass open: failed to open /dev/sr0: No medium found
17:40:41.432 FuEngine             failed to add device 
/sys/devices/pci0000:00/0000:00:1f.2/ata2/host1/target1:0:0/1:0:0:0/block/sr0: 
failed to subclass open: failed to open /dev/sr0: No medium found
Loading…                 [************************************** ]
Devices with the latest available firmware version:
 • UEFI CA
 • UEFI dbx
Devices with no available firmware updates:
 • Option ROM UEFI CA
 • Trust - Lenovo Certificate
 • UEFI CA
 • Windows Production PCA
 • CT2000P310SSD8
 • KEK CA
 • System Firmware
 • WDS500G2B0A-00SM50

(Unfortunately, I did not save the original 'fwupdtool update' output
when the UEFI CA keys were updated)

So far I've not downgraded shim-signed to version 1.47 to enable secure
boot again but so far have secure boot disabled in the BIOS setup.

M73 system info:

# dmidecode
# dmidecode 3.6
Getting SMBIOS data from sysfs.
SMBIOS 2.8 present.
37 structures occupying 1720 bytes.
Table at 0x9DED2018.

Handle 0x0000, DMI type 0, 24 bytes
BIOS Information
        Vendor: LENOVO
        Version: FCKT97AUS
        Release Date: 01/07/2020
        Address: 0xF0000
        Runtime Size: 64 kB
        ROM Size: 4 MB
        Characteristics:
                PCI is supported
                BIOS is upgradeable
                BIOS shadowing is allowed
                Boot from CD is supported
                Selectable boot is supported
                BIOS ROM is socketed
                EDD is supported
                5.25"/1.2 MB floppy services are supported (int 13h)
                3.5"/720 kB floppy services are supported (int 13h)
                3.5"/2.88 MB floppy services are supported (int 13h)
                Print screen service is supported (int 5h)
                8042 keyboard services are supported (int 9h)
                Serial services are supported (int 14h)
                Printer services are supported (int 17h)
                ACPI is supported
                USB legacy is supported
                BIOS boot specification is supported
                Targeted content distribution is supported
                UEFI is supported
        BIOS Revision: 1.151

Handle 0x0001, DMI type 1, 27 bytes
System Information
        Manufacturer: LENOVO
        Product Name: 10B00005US
        Version: ThinkCentre M73
        Serial Number: MJ00D7ZZ
        UUID: 66e5795c-9a63-11e3-89c1-3d4e9daf1a00
        Wake-up Type: Power Switch
        SKU Number: LENOVO_MT_10B0
        Family:

Handle 0x0002, DMI type 2, 15 bytes
Base Board Information
        Manufacturer: LENOVO
        Product Name: 3098
        Version: 0B98401 PRO
        Serial Number: INVALID
        Asset Tag:
        Features:
                Board is a hosting board
                Board is replaceable
        Location In Chassis:
        Chassis Handle: 0x0003
        Type: Motherboard
        Contained Object Handles: 0

Handle 0x0003, DMI type 3, 25 bytes
Chassis Information
        Manufacturer: LENOVO
        Type: Desktop
        Lock: Not Present
        Version:
        Serial Number: MJ00D7ZZ
        Asset Tag:
        Boot-up State: Safe
        Power Supply State: Safe
        Thermal State: Safe
        Security Status: None
        OEM Information: 0x00000000
        Height: Unspecified
        Number Of Power Cords: 1
        Contained Elements: 1
                <OUT OF SPEC> (0)
        SKU Number:

Handle 0x0004, DMI type 9, 17 bytes
System Slot Information
        Designation: J6B2
        Type: PCI Express
        Data Bus Width: 16x or x16
        Current Usage: In Use
        Length: Long
        ID: 0
        Characteristics:
                3.3 V is provided
                Opening is shared
                PME signal is supported
        Bus Address: 0000:00:01.0

Handle 0x0005, DMI type 9, 17 bytes
System Slot Information
        Designation: J6B1
        Type: PCI Express
        Data Bus Width: 1x or x1
        Current Usage: In Use
        Length: Short
        ID: 1
        Characteristics:
                3.3 V is provided
                Opening is shared
                PME signal is supported
        Bus Address: 0000:00:1c.3

Handle 0x0006, DMI type 9, 17 bytes
System Slot Information
        Designation: J6D1
        Type: PCI Express
        Data Bus Width: 1x or x1
        Current Usage: In Use
        Length: Short
        ID: 2
        Characteristics:
                3.3 V is provided
                Opening is shared
                PME signal is supported
        Bus Address: 0000:00:1c.4

Handle 0x0007, DMI type 9, 17 bytes
System Slot Information
        Designation: J7B1
        Type: PCI Express
        Data Bus Width: 1x or x1
        Current Usage: In Use
        Length: Short
        ID: 3
        Characteristics:
                3.3 V is provided
                Opening is shared
                PME signal is supported
        Bus Address: 0000:00:1c.5

Handle 0x0008, DMI type 9, 17 bytes
System Slot Information
        Designation: J8B4
        Type: PCI Express
        Data Bus Width: 1x or x1
        Current Usage: In Use
        Length: Short
        ID: 4
        Characteristics:
                3.3 V is provided
                Opening is shared
                PME signal is supported
        Bus Address: 0000:00:1c.6

Handle 0x0009, DMI type 10, 12 bytes
On Board Device 1 Information
        Type: Video
        Status: Enabled
        Description:    Onboard Video
On Board Device 2 Information
        Type: Ethernet
        Status: Enabled
        Description:    Onboard Lan
On Board Device 3 Information
        Type: Sound
        Status: Enabled
        Description:    Onboard Audio
On Board Device 4 Information
        Type: SATA Controller
        Status: Enabled
        Description:    Onboard SATA

Handle 0x000A, DMI type 11, 5 bytes
OEM Strings
        String 1: LENOVO ThinkCentre Embedded Controller -[N/A]-
        String 2: LENOVO ThinkCentre BIOS Boot Block Revision 1.97

Handle 0x000B, DMI type 12, 5 bytes
System Configuration Options
        Option 1: scre++

Handle 0x000C, DMI type 24, 5 bytes
Hardware Security
        Power-On Password Status: Disabled
        Keyboard Password Status: Enabled
        Administrator Password Status: Disabled
        Front Panel Reset Status: Not Implemented

Handle 0x000D, DMI type 32, 20 bytes
System Boot Information
        Status: No errors detected

Handle 0x000E, DMI type 4, 42 bytes
Processor Information
        Socket Designation: SOCKET 0
        Type: Central Processor
        Family: Core i5
        Manufacturer: Intel
        ID: C3 06 03 00 FF FB EB BF
        Signature: Type 0, Family 6, Model 60, Stepping 3
        Flags:
                FPU (Floating-point unit on-chip)
                VME (Virtual mode extension)
                DE (Debugging extension)
                PSE (Page size extension)
                TSC (Time stamp counter)
                MSR (Model specific registers)
                PAE (Physical address extension)
                MCE (Machine check exception)
                CX8 (CMPXCHG8 instruction supported)
                APIC (On-chip APIC hardware supported)
                SEP (Fast system call)
                MTRR (Memory type range registers)
                PGE (Page global enable)
                MCA (Machine check architecture)
                CMOV (Conditional move instruction supported)
                PAT (Page attribute table)
                PSE-36 (36-bit page size extension)
                CLFSH (CLFLUSH instruction supported)
                DS (Debug store)
                ACPI (ACPI supported)
                MMX (MMX technology supported)
                FXSR (FXSAVE and FXSTOR instructions supported)
                SSE (Streaming SIMD extensions)
                SSE2 (Streaming SIMD extensions 2)
                SS (Self-snoop)
                HTT (Multi-threading)
                TM (Thermal monitor supported)
                PBE (Pending break enabled)
        Version: Intel(R) Core(TM) i5-4570 CPU @ 3.20GHz
        Voltage: 1.2 V
        External Clock: 100 MHz
        Max Speed: 3200 MHz
        Current Speed: 3200 MHz
        Status: Populated, Enabled
        Upgrade: Socket BGA1155
        L1 Cache Handle: 0x0010
        L2 Cache Handle: 0x000F
        L3 Cache Handle: 0x0011
        Serial Number: Not Specified
        Asset Tag: Fill By OEM
        Part Number: Fill By OEM
        Core Count: 4
        Core Enabled: 4
        Thread Count: 4
        Characteristics:
                64-bit capable

Handle 0x000F, DMI type 7, 19 bytes
Cache Information
        Socket Designation: CPU Internal L2
        Configuration: Enabled, Not Socketed, Level 2
        Operational Mode: Write Back
        Location: Internal
        Installed Size: 1 MB
        Maximum Size: 1 MB
        Supported SRAM Types:
                Unknown
        Installed SRAM Type: Unknown
        Speed: Unknown
        Error Correction Type: Single-bit ECC
        System Type: Unified
        Associativity: 8-way Set-associative

Handle 0x0010, DMI type 7, 19 bytes
Cache Information
        Socket Designation: CPU Internal L1
        Configuration: Enabled, Not Socketed, Level 1
        Operational Mode: Write Back
        Location: Internal
        Installed Size: 256 kB
        Maximum Size: 256 kB
        Supported SRAM Types:
                Unknown
        Installed SRAM Type: Unknown
        Speed: Unknown
        Error Correction Type: Single-bit ECC
        System Type: Other
        Associativity: 8-way Set-associative

Handle 0x0011, DMI type 7, 19 bytes
Cache Information
        Socket Designation: CPU Internal L3
        Configuration: Enabled, Not Socketed, Level 3
        Operational Mode: Write Back
        Location: Internal
        Installed Size: 6 MB
        Maximum Size: 6 MB
        Supported SRAM Types:
                Unknown
        Installed SRAM Type: Unknown
        Speed: Unknown
        Error Correction Type: Single-bit ECC
        System Type: Unified
        Associativity: 12-way Set-associative

Handle 0x0012, DMI type 16, 23 bytes
Physical Memory Array
        Location: System Board Or Motherboard
        Use: System Memory
        Error Correction Type: None
        Maximum Capacity: 16 GB
        Error Information Handle: Not Provided
        Number Of Devices: 2

Handle 0x0013, DMI type 17, 40 bytes
Memory Device
        Array Handle: 0x0012
        Error Information Handle: Not Provided
        Total Width: 64 bits
        Data Width: 64 bits
        Size: 8 GB
        Form Factor: DIMM
        Set: None
        Locator: ChannelA-DIMM0
        Bank Locator: BANK 0
        Type: DDR3
        Type Detail: Synchronous
        Speed: 1600 MT/s
        Manufacturer: Micron
        Serial Number: 10CD0955
        Asset Tag: 9876543210
        Part Number: 16KTF1G64AZ-1G6P1
        Rank: 2
        Configured Memory Speed: 1600 MT/s
        Minimum Voltage: 1.35 V
        Maximum Voltage: 1.5 V
        Configured Voltage: 1.5 V

Handle 0x0014, DMI type 15, 73 bytes
System Event Log
        Area Length: 4096 bytes
        Header Start Offset: 0x0000
        Header Length: 16 bytes
        Data Start Offset: 0x0010
        Access Method: Memory-mapped physical 32-bit address
        Access Address: 0xFFE6D000
        Status: Valid, Not Full
        Change Token: 0x00000001
        Header Format: Type 1
        Supported Log Type Descriptors: 25
        Descriptor 1: Single-bit ECC memory error
        Data Format 1: None
        Descriptor 2: Multi-bit ECC memory error
        Data Format 2: None
        Descriptor 3: Parity memory error
        Data Format 3: None
        Descriptor 4: Bus timeout
        Data Format 4: None
        Descriptor 5: I/O channel block
        Data Format 5: None
        Descriptor 6: Software NMI
        Data Format 6: None
        Descriptor 7: POST memory resize
        Data Format 7: None
        Descriptor 8: POST error
        Data Format 8: POST results bitmap
        Descriptor 9: PCI parity error
        Data Format 9: None
        Descriptor 10: PCI system error
        Data Format 10: None
        Descriptor 11: CPU failure
        Data Format 11: None
        Descriptor 12: EISA failsafe timer timeout
        Data Format 12: None
        Descriptor 13: Correctable memory log disabled
        Data Format 13: None
        Descriptor 14: Logging disabled
        Data Format 14: None
        Descriptor 15: System limit exceeded
        Data Format 15: None
        Descriptor 16: Asynchronous hardware timer expired
        Data Format 16: None
        Descriptor 17: System configuration information
        Data Format 17: None
        Descriptor 18: Hard disk information
        Data Format 18: None
        Descriptor 19: System reconfigured
        Data Format 19: None
        Descriptor 20: Uncorrectable CPU-complex error
        Data Format 20: None
        Descriptor 21: Log area reset/cleared
        Data Format 21: None
        Descriptor 22: System boot
        Data Format 22: None
        Descriptor 23: End of log
        Data Format 23: None
        Descriptor 24: OEM-specific
        Data Format 24: OEM-specific
        Descriptor 25: OEM-specific
        Data Format 25: OEM-specific

Handle 0x0015, DMI type 20, 35 bytes
Memory Device Mapped Address
        Starting Address: 0x00000000000
        Ending Address: 0x001FFFFFFFF
        Range Size: 8 GB
        Physical Device Handle: 0x0013
        Memory Array Mapped Address Handle: 0x0018
        Partition Row Position: Unknown
        Interleave Position: 1
        Interleaved Data Depth: 1

Handle 0x0016, DMI type 17, 40 bytes
Memory Device
        Array Handle: 0x0012
        Error Information Handle: Not Provided
        Total Width: 64 bits
        Data Width: 64 bits
        Size: 8 GB
        Form Factor: DIMM
        Set: None
        Locator: ChannelB-DIMM0
        Bank Locator: BANK 2
        Type: DDR3
        Type Detail: Synchronous
        Speed: 1600 MT/s
        Manufacturer: Micron
        Serial Number: 10CD0958
        Asset Tag: 9876543210
        Part Number: 16KTF1G64AZ-1G6P1
        Rank: 2
        Configured Memory Speed: 1600 MT/s
        Minimum Voltage: 1.35 V
        Maximum Voltage: 1.5 V
        Configured Voltage: 1.5 V

Handle 0x0017, DMI type 20, 35 bytes
Memory Device Mapped Address
        Starting Address: 0x00200000000
        Ending Address: 0x003FFFFFFFF
        Range Size: 8 GB
        Physical Device Handle: 0x0016
        Memory Array Mapped Address Handle: 0x0018
        Partition Row Position: Unknown
        Interleave Position: 2
        Interleaved Data Depth: 1

Handle 0x0018, DMI type 19, 31 bytes
Memory Array Mapped Address
        Starting Address: 0x00000000000
        Ending Address: 0x003FFFFFFFF
        Range Size: 16 GB
        Physical Array Handle: 0x0012
        Partition Width: 2

Handle 0x001C, DMI type 140, 19 bytes
OEM-specific Type
        Header and Data:
                8C 13 1C 00 4C 45 4E 4F 56 4F 0B 05 01 0F 00 00
                00 53 55

Handle 0x001D, DMI type 140, 23 bytes
OEM-specific Type
        Header and Data:
                8C 17 1D 00 4C 45 4E 4F 56 4F 0B 06 01 00 00 00
                00 00 00 00 00 00 00

Handle 0x001E, DMI type 131, 22 bytes
ThinkVantage Technologies
        Version: 1
        Diagnostics: Available

Handle 0x001F, DMI type 136, 6 bytes
OEM-specific Type
        Header and Data:
                88 06 1F 00 5A 5A

Handle 0x0020, DMI type 140, 85 bytes
OEM-specific Type
        Header and Data:
                8C 55 20 00 4C 45 4E 4F 56 4F 0B 00 01 3B 94 F7
                3D 84 37 39 80 FF 27 CB 4E 68 BC C1 DA 01 00 00
                00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                00 00 00 00 00

Handle 0x0021, DMI type 140, 47 bytes
OEM-specific Type
        Header and Data:
                8C 2F 21 00 4C 45 4E 4F 56 4F 0B 01 01 09 00 3C
                D9 4D 88 4E E7 CA 0C 23 C7 DF 63 AE 6C 1A F5 00
                00 00 00 10 00 10 00 10 01 D0 00 20 01 00 01

Handle 0x0022, DMI type 140, 63 bytes
OEM-specific Type
        Header and Data:
                8C 3F 22 00 4C 45 4E 4F 56 4F 0B 02 01 00 00 00
                00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Handle 0x0023, DMI type 140, 17 bytes
OEM-specific Type
        Header and Data:
                8C 11 23 00 4C 45 4E 4F 56 4F 0B 03 01 00 00 00
                00

Handle 0x0024, DMI type 140, 19 bytes
OEM-specific Type
        Header and Data:
                8C 13 24 00 4C 45 4E 4F 56 4F 0B 04 01 B2 00 4D
                53 20 00

Handle 0x0025, DMI type 131, 64 bytes
OEM-specific Type
        Header and Data:
                83 40 25 00 35 00 00 00 00 00 00 00 00 00 00 00
                F8 00 5C 8C 00 00 00 00 01 20 00 00 00 00 09 00
                B6 05 15 00 00 00 00 00 C8 00 FF FF 00 00 00 00
                00 00 00 00 66 00 00 00 76 50 72 6F 00 00 00 00

Handle 0x0026, DMI type 13, 22 bytes
BIOS Language Information
        Language Description Format: Long
        Installable Languages: 3
                en|US|iso8859-1
                fr|FR|iso8859-1
                zh|CN|unicode
        Currently Installed Language: en|US|iso8859-1

Handle 0x0029, DMI type 127, 4 bytes
End Of Table


- -- System Information:
Debian Release: 13.6
  APT prefers stable-updates
  APT policy: (500, 'stable-updates'), (500, 'stable-security'), (500, 'stable')
Architecture: amd64 (x86_64)
Foreign Architectures: i386

Kernel: Linux 6.12.95+deb13-amd64 (SMP w/4 CPU threads; PREEMPT)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8), LANGUAGE not set
Shell: /bin/sh linked to /usr/bin/dash
Init: systemd (via /run/systemd/system)
LSM: AppArmor: enabled

Versions of packages shim-signed depends on:
ii  debconf [debconf-2.0]      1.5.91
ii  grub-efi-amd64-bin         2.12-9+deb13u2
ii  grub2-common               2.12-9+deb13u2
ii  mokutil                    0.7.2-1
ii  shim-helpers-amd64-signed  1+16.1+2~deb13u1
ii  shim-signed-common         1.51~1+deb13u1+16.1-2~deb13u1

shim-signed recommends no packages.

shim-signed suggests no packages.

- -- debconf information:
  shim-signed/revoked-sig:
  shim-signed/no-valid-sigs:

-----BEGIN PGP SIGNATURE-----

iGsEARECACsWIQSC1k9rDmfNQfaJu6b7LFEw1VqIGQUCalzZcw0cbjBuYkBuMG5i
LnVzAAoJEPssUTDVWogZs7UAn1Zv2ifNm92nAN4lNbaRUQJmiGd9AJ49i8llIw1Q
vp+7MJ5dmnSEZ5dQQg==
=UmFN
-----END PGP SIGNATURE-----

Reply via email to