Package: shim-signed Version: 1.47+15.8-1 Severity: important -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1
Dear Maintainer, Trying to upgrade the package results in the error box shown at: https://wiki.debian.org/SecureBoot/CAChanges#A1._No_valid_UEFI_Secure_Boot_signatures_found This, despite Secure Boot being enabled and apparently working for Debian, Windows 10 Pro, and Arch Linux on this particular machine (triple boot setup all loaded from Debian's GRUB). My discovery is that the firmware (latest available as of last week) does not make the db, dbx, kek, or pk rings visible to the OS: $ mokutil --db --short $ mokutil --dbx --short $ mokutil --kek --short $ mokutil --pk --short However, local keys are visible: $ mokutil --list-enrolled --short 53610cf81f Debian Secure Boot CA 877d1dfca0 Machine Owner Key 877d1dfca0 Machine Owner Key And Secure Boot is active: $ mokutil --sb-state SecureBoot enabled Attempts at firmware updates result in: # fwupdtool refresh Loading… [********************* ]ERROR:tcti:src/tss2-tcti/tcti-device.c:455:Tss2_Tcti_Device_Init() Failed to open specified TCTI device file /dev/tpmrm0: No such file or directory ERROR:tcti:src/tss2-tcti/tctildr-dl.c:149:tcti_from_file() Could not initialize TCTI file: libtss2-tcti-device.so.0 ERROR:tcti:src/tss2-tcti/tcti-device.c:506:Tss2_Tcti_Device_Init() timeout waiting for response from fd 17 Loading… [************************************** ] Metadata is up to date; use --force to refresh again. # fwupdtool get-updates Loading… [********************* ]ERROR:tcti:src/tss2-tcti/tcti-device.c:455:Tss2_Tcti_Device_Init() Failed to open specified TCTI device file /dev/tpmrm0: No such file or directory ERROR:tcti:src/tss2-tcti/tctildr-dl.c:149:tcti_from_file() Could not initialize TCTI file: libtss2-tcti-device.so.0 ERROR:tcti:src/tss2-tcti/tcti-device.c:506:Tss2_Tcti_Device_Init() timeout waiting for response from fd 17 Loading… [************************************** ] Devices with no available firmware updates: • SPCC M.2 SSD • System Firmware • UEFI Device Firmware • UEFI Device Firmware • SBAT No updates available for remaining devices # fwupdtool update Loading… [********************* ]ERROR:tcti:src/tss2-tcti/tcti-device.c:455:Tss2_Tcti_Device_Init() Failed to open specified TCTI device file /dev/tpmrm0: No such file or directory ERROR:tcti:src/tss2-tcti/tctildr-dl.c:149:tcti_from_file() Could not initialize TCTI file: libtss2-tcti-device.so.0 ERROR:tcti:src/tss2-tcti/tcti-device.c:506:Tss2_Tcti_Device_Init() timeout waiting for response from fd 18 Loading… [************************************** ] Devices with no available firmware updates: • SPCC M.2 SSD • System Firmware • UEFI Device Firmware • UEFI Device Firmware • SBAT Further research led me to this link which summarizes well what I have found with this laptop: https://forums.gentoo.org/viewtopic.php?t=1168749 So far I've not found a setting which exposes the key rings to the OS. As near as I can tell, /sys/firmware/efi/efivars/ is correctly mounted: # ls /sys/firmware/efi/efivars/ 54EE7594E70B-937fe521-95ae-4d1a-8929-48bcd90ad31a LBOP0007-2a4dc6b7-41f5-45dd-b46f-2dd334c1cf65 AcpiGlobalVariable-c020489e-6db2-4ef2-9aa5-ca06fc11d36a LBOP0008-2a4dc6b7-41f5-45dd-b46f-2dd334c1cf65 AcpiProtocolSetupVar-1054354b-b543-4dfe-558b-a7ad6351c9d8 LBOP0009-2a4dc6b7-41f5-45dd-b46f-2dd334c1cf65 AmtSetup-4b9f56be-f68e-4bbc-9bab-cdf600f52d30 LBOP000A-2a4dc6b7-41f5-45dd-b46f-2dd334c1cf65 BiosSetup-0b7646a4-6b44-4332-8588-c8998117f2ef LBOP000B-2a4dc6b7-41f5-45dd-b46f-2dd334c1cf65 Boot0000-8be4df61-93ca-11d2-aa0d-00e098032b8c LBOP000C-2a4dc6b7-41f5-45dd-b46f-2dd334c1cf65 Boot0001-8be4df61-93ca-11d2-aa0d-00e098032b8c LBOP000D-2a4dc6b7-41f5-45dd-b46f-2dd334c1cf65 Boot0002-8be4df61-93ca-11d2-aa0d-00e098032b8c LBOP000E-2a4dc6b7-41f5-45dd-b46f-2dd334c1cf65 Boot0003-8be4df61-93ca-11d2-aa0d-00e098032b8c LBOP000F-2a4dc6b7-41f5-45dd-b46f-2dd334c1cf65 Boot0004-8be4df61-93ca-11d2-aa0d-00e098032b8c LBOP0010-2a4dc6b7-41f5-45dd-b46f-2dd334c1cf65 Boot0005-8be4df61-93ca-11d2-aa0d-00e098032b8c LBOP0011-2a4dc6b7-41f5-45dd-b46f-2dd334c1cf65 Boot0006-8be4df61-93ca-11d2-aa0d-00e098032b8c LBOP0012-2a4dc6b7-41f5-45dd-b46f-2dd334c1cf65 Boot0007-8be4df61-93ca-11d2-aa0d-00e098032b8c LBOP0013-2a4dc6b7-41f5-45dd-b46f-2dd334c1cf65 Boot0008-8be4df61-93ca-11d2-aa0d-00e098032b8c LenovoBDG-49ad5446-9d32-4455-af9b-d774bda2cf8b Boot0009-8be4df61-93ca-11d2-aa0d-00e098032b8c LenovoConfig-2a4dc6b7-41f5-45dd-b46f-2dd334c1cf65 Boot000A-8be4df61-93ca-11d2-aa0d-00e098032b8c LenovoFprData-867eff85-1886-4a9e-a74f-ab374360e719 Boot000B-8be4df61-93ca-11d2-aa0d-00e098032b8c LenovoFunctionConfig-580020c3-6c9c-4f93-8008-7fadc1fcfedd Boot000C-8be4df61-93ca-11d2-aa0d-00e098032b8c LenovoHdpSmm-edf349d8-12f2-4163-ab09-a11c8f748f0d Boot000D-8be4df61-93ca-11d2-aa0d-00e098032b8c LenovoHiddenSetting-1827cfc7-4e61-4273-b796-d35f4b0c88fc Boot000E-8be4df61-93ca-11d2-aa0d-00e098032b8c LenovoScratchData-67c3208e-4fcb-498f-9729-0760bb4109a7 Boot000F-8be4df61-93ca-11d2-aa0d-00e098032b8c LenovoSecurityConfig-a2c1808f-0d4f-4cc9-a619-d1e641d39d49 Boot0010-8be4df61-93ca-11d2-aa0d-00e098032b8c LenovoSkipACCheck-c69efd4d-8c49-437a-803b-0b5434f398ca Boot0011-8be4df61-93ca-11d2-aa0d-00e098032b8c LenovoSystemConfig-2a4dc6b7-41f5-45dd-b46f-2dd334c1cf65 Boot0012-8be4df61-93ca-11d2-aa0d-00e098032b8c LenovoThermalShutdown-943d1460-da6e-499a-af6d-4593b12bc4d7 Boot0013-8be4df61-93ca-11d2-aa0d-00e098032b8c LenovoWmaSupport-286091ef-33a8-48e6-af77-1e03344c7a18 BootAllCDROM-0b7646a4-6b44-4332-8588-c8998117f2ef LenovoWolInfo-0af4027f-9b58-41c0-b62f-cd3a1cef54ee BootAllHDD-0b7646a4-6b44-4332-8588-c8998117f2ef LFS-90564d52-f26b-4fac-8d16-7a51422c51f1 BootAllPciLan-0b7646a4-6b44-4332-8588-c8998117f2ef LKOP0000-2a4dc6b7-41f5-45dd-b46f-2dd334c1cf65 BootCurrent-8be4df61-93ca-11d2-aa0d-00e098032b8c LKOP0001-2a4dc6b7-41f5-45dd-b46f-2dd334c1cf65 BootMenu-0b7646a4-6b44-4332-8588-c8998117f2ef LKOP0002-2a4dc6b7-41f5-45dd-b46f-2dd334c1cf65 BootOptionNo_01-0b7646a4-6b44-4332-8588-c8998117f2ef LKOP0003-2a4dc6b7-41f5-45dd-b46f-2dd334c1cf65 BootOptionNo_02-0b7646a4-6b44-4332-8588-c8998117f2ef LKOP0004-2a4dc6b7-41f5-45dd-b46f-2dd334c1cf65 BootOptionNo_03-0b7646a4-6b44-4332-8588-c8998117f2ef LKOP0005-2a4dc6b7-41f5-45dd-b46f-2dd334c1cf65 BootOptionSupport-8be4df61-93ca-11d2-aa0d-00e098032b8c LKOP0006-2a4dc6b7-41f5-45dd-b46f-2dd334c1cf65 BootOrder-8be4df61-93ca-11d2-aa0d-00e098032b8c LnvActivationVar-e5bbf7be-2417-499b-97db-39f4896391bc BootOrderDefault-0b7646a4-6b44-4332-8588-c8998117f2ef LnvOA3ID-e5bbf7be-2417-499b-97db-39f4896391bc BugCheckCode-ba57e015-65b3-4c3c-b274-659192f699e3 LnvOSLicDesc-e5bbf7be-2417-499b-97db-39f4896391bc BugCheckParameter1-ba57e015-65b3-4c3c-b274-659192f699e3 LoaderSystemToken-4a67b082-0a4c-41cf-b6c7-440b29bb8c4f BugCheckProgress-ba57e015-65b3-4c3c-b274-659192f699e3 LocalSecurityVars-47355e9f-0857-45e1-8a6f-a4f5eda89a77 BuildTime-e5bbf7be-2417-499b-97db-39f4896391bc LWO-2a4dc6b7-41f5-45dd-b46f-2dd334c1cf65 ClientId-9fb9a8a1-2f4a-43a6-889c-d0f7b6c47ad5 MailBoxQ-67c3208e-4fcb-498f-9729-0760bb4109a7 ConIn-8be4df61-93ca-11d2-aa0d-00e098032b8c MeBiosExtensionSetup-1bad711c-d451-4241-b1f3-8537812e0c70 ConInDev-8be4df61-93ca-11d2-aa0d-00e098032b8c MemoryOverwriteRequestControl-e20939be-32d4-41be-a150-897f85d49829 ConOut-8be4df61-93ca-11d2-aa0d-00e098032b8c MemoryTypeInformation-4c19049f-4137-4dd3-9c10-8b97a83ffdfa ConOutDev-8be4df61-93ca-11d2-aa0d-00e098032b8c MemoryTypeInformationBackup-4c19049f-4137-4dd3-9c10-8b97a83ffdfa ConsoleLock-368cda0d-cf31-4b9b-8cf6-e7d1bfff157e MemRestoreVariable-608dc793-15de-4a7f-a0c5-6c29beaf5d23 CpuPpiSetupVar-d1b99f1a-084b-49c3-b88e-378abefa118b MeSetup-fb7b1de3-295b-433c-95a2-091fe3218bf9 CpuProtocolSetupVar-7d4adce1-930d-40c7-9cd2-6d2148413dc7 MokListRT-605dab50-e046-4300-abb6-3dd810dd8b23 CurrentPolicy-77fa9abd-0359-4d32-bd60-28f4e78f784b MokListTrustedRT-605dab50-e046-4300-abb6-3dd810dd8b23 DIAGSPLSHSCRN-a7d8d9a6-6ab0-4aeb-ad9d-163e59a7a380 MokListXRT-605dab50-e046-4300-abb6-3dd810dd8b23 DisplaySaveStateVar-be3e3f80-7aca-4101-852d-7616929094d9 MTC-eb704011-1402-11d3-8e77-00a0c969723b ErrOutDev-8be4df61-93ca-11d2-aa0d-00e098032b8c OfflineUniqueIDEKPubCRC-eaec226f-c9a3-477a-a826-ddc716cdc0e3 ESRTPLATFORMENTRY-6eb9a2b4-58bf-41bc-81a6-c9bad152efb3 OfflineUniqueIDEKPub-eaec226f-c9a3-477a-a826-ddc716cdc0e3 FirmwarePerformanceDataTable-9dab39a4-3f8a-47ac-80c3-400729332c81 OsIndications-8be4df61-93ca-11d2-aa0d-00e098032b8c GopConfigSetupVar-6e61d5b9-70d0-4c18-8af2-f1ccde2d88cf OsIndicationsSupported-8be4df61-93ca-11d2-aa0d-00e098032b8c IccString-c1e2774b-9ed4-4103-aefa-33b8149eccf6 PartNumber-e5bbf7be-2417-499b-97db-39f4896391bc IEIT-955b9041-133a-4bcf-90d1-97e1693c0e30 PbaStatusVar-0ec1a7f5-4904-40a0-8eab-4bcc4666da45 Key0000-8be4df61-93ca-11d2-aa0d-00e098032b8c PBRDevicePath-a9b5f8d2-cb6d-42c2-bc01-b5ffaae4335e Key0001-8be4df61-93ca-11d2-aa0d-00e098032b8c PchPolicyVar-e274d08e-69b6-4497-a4eb-d39c4b2f9fcb Key0002-8be4df61-93ca-11d2-aa0d-00e098032b8c PlatformLang-8be4df61-93ca-11d2-aa0d-00e098032b8c Key0003-8be4df61-93ca-11d2-aa0d-00e098032b8c PlatformLangCodes-8be4df61-93ca-11d2-aa0d-00e098032b8c Key0004-8be4df61-93ca-11d2-aa0d-00e098032b8c PreBootEventLogReset-8b604cac-3c4f-4e6c-862e-00b8b7436e5f Key0005-8be4df61-93ca-11d2-aa0d-00e098032b8c ProtectedBootOptions-0b7646a4-6b44-4332-8588-c8998117f2ef Key0006-8be4df61-93ca-11d2-aa0d-00e098032b8c PwdStatusVar-3e72b3ad-2b91-424a-ad73-c3270e91ed88 LastBootCurrent-0b7646a4-6b44-4332-8588-c8998117f2ef SaPpiSetupVar-7da81437-866b-4143-8e08-a25c6ef0fa5b LastBootOrder-0b7646a4-6b44-4332-8588-c8998117f2ef SaProtocolSetupVar-34f73d4d-963e-4c65-b3b3-515e720175d6 LBC-2a4dc6b7-41f5-45dd-b46f-2dd334c1cf65 SbatLevelRT-605dab50-e046-4300-abb6-3dd810dd8b23 LBL-2a4dc6b7-41f5-45dd-b46f-2dd334c1cf65 SctHotkey-4650c401-93f1-4aeb-b87d-c8204c047dec LBOL-2a4dc6b7-41f5-45dd-b46f-2dd334c1cf65 SecureBoot-8be4df61-93ca-11d2-aa0d-00e098032b8c lBoot0000-146b234d-4052-4e07-b326-11220f8e1fe8 SecureBootOption-955b9041-133a-4bcf-90d1-97e1693c0e30 lBoot0001-146b234d-4052-4e07-b326-11220f8e1fe8 Setup-4dfbbaab-1392-4fde-abb8-c41cc5ad7d5d lBoot0002-146b234d-4052-4e07-b326-11220f8e1fe8 SetupHotKey-a7d8d9a6-6ab0-4aeb-ad9d-163e59a7a380 lBoot0003-146b234d-4052-4e07-b326-11220f8e1fe8 SetupMode-8be4df61-93ca-11d2-aa0d-00e098032b8c lBoot0004-146b234d-4052-4e07-b326-11220f8e1fe8 SignatureSupport-8be4df61-93ca-11d2-aa0d-00e098032b8c lBoot0005-146b234d-4052-4e07-b326-11220f8e1fe8 SioPolicy-729c67cc-e109-4bc7-97b5-fa7c386e387d lBoot0006-146b234d-4052-4e07-b326-11220f8e1fe8 SMBIOSELOG000-c3eeae98-23bf-412b-ab60-efcbb48e1534 lBoot0007-146b234d-4052-4e07-b326-11220f8e1fe8 SMBIOSELOGNUMBER-c3eeae98-23bf-412b-ab60-efcbb48e1534 lBoot0008-146b234d-4052-4e07-b326-11220f8e1fe8 SMBIOSEPS-c3eeae98-23bf-412b-ab60-efcbb48e1534 lBoot0009-146b234d-4052-4e07-b326-11220f8e1fe8 SMBIOSMEMSIZE-c3eeae98-23bf-412b-ab60-efcbb48e1534 lBoot000A-146b234d-4052-4e07-b326-11220f8e1fe8 Smst-2a3cfebd-27e8-4d0a-8b79-d688c2a3e1c0 lBoot000B-146b234d-4052-4e07-b326-11220f8e1fe8 SpeakerMuteAndVolume-68ff2659-86dd-425f-9a42-c9884ff9c2f2 lBoot000C-146b234d-4052-4e07-b326-11220f8e1fe8 SplashLogoPackage-e5bbf7be-2417-499b-97db-39f4896391bc lBoot000D-146b234d-4052-4e07-b326-11220f8e1fe8 System-e947fcf9-dd01-4965-b808-32a7b6815657 lBoot000E-146b234d-4052-4e07-b326-11220f8e1fe8 SystemSecure-3aec3e3f-5342-4e4b-b465-b9699b7376ba lBoot000F-146b234d-4052-4e07-b326-11220f8e1fe8 Time-470733de-df43-448b-8b45-4eeb0df8c812 lBoot0010-146b234d-4052-4e07-b326-11220f8e1fe8 Timeout-8be4df61-93ca-11d2-aa0d-00e098032b8c lBoot0011-146b234d-4052-4e07-b326-11220f8e1fe8 TpAcpiNvs-e6f014ab-cb0e-456e-8af7-7221edb702f7 lBoot0012-146b234d-4052-4e07-b326-11220f8e1fe8 TpmAcpiData-6403753b-abde-4da2-aa11-6983ef2a7a69 lBoot0013-146b234d-4052-4e07-b326-11220f8e1fe8 TpmLastOperation-753ab903-444c-41f8-a235-569e8341147e LBOP0000-2a4dc6b7-41f5-45dd-b46f-2dd334c1cf65 TpmNextOperation-753ab903-444c-41f8-a235-569e8341147e LBOP0001-2a4dc6b7-41f5-45dd-b46f-2dd334c1cf65 TpmOperationResult-753ab903-444c-41f8-a235-569e8341147e LBOP0002-2a4dc6b7-41f5-45dd-b46f-2dd334c1cf65 TpmSaveState-5e724c0c-5c03-4543-bcb6-c1e23de24136 LBOP0003-2a4dc6b7-41f5-45dd-b46f-2dd334c1cf65 TpmSetup-753ab903-444c-41f8-a235-569e8341147e LBOP0004-2a4dc6b7-41f5-45dd-b46f-2dd334c1cf65 UCR-14a22a97-8424-489e-9ead-dc09255658b5 LBOP0005-2a4dc6b7-41f5-45dd-b46f-2dd334c1cf65 UnlockIDCopy-eaec226f-c9a3-477a-a826-ddc716cdc0e3 LBOP0006-2a4dc6b7-41f5-45dd-b46f-2dd334c1cf65 WorkingSig-955b9041-133a-4bcf-90d1-97e1693c0e30 Additional information: System Information Manufacturer: LENOVO Product Name: 20BS0031US Version: ThinkPad X1 Carbon 3rd BIOS Information Vendor: LENOVO Version: N14ET56W (1.34 ) Release Date: 08/31/2021 At this point I am holding shim-signed at version 1.47,+15.8-1 but I suspect that eventually this will fail signature checks with upgraded kernels, etc. - - Nate - -- System Information: Debian Release: 13.6 APT prefers stable-updates APT policy: (500, 'stable-updates'), (500, 'stable-security'), (500, 'stable') Architecture: amd64 (x86_64) Kernel: Linux 6.12.95+deb13-amd64 (SMP w/4 CPU threads; PREEMPT) Kernel taint flags: TAINT_FIRMWARE_WORKAROUND Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8), LANGUAGE not set Shell: /bin/sh linked to /usr/bin/dash Init: systemd (via /run/systemd/system) LSM: AppArmor: enabled Versions of packages shim-signed depends on: ii grub-efi-amd64-bin 2.12-9+deb13u2 ii grub2-common 2.12-9+deb13u2 ii shim-helpers-amd64-signed 1+16.1+2~deb13u1 ii shim-signed-common 1.51~1+deb13u1+16.1-2~deb13u1 shim-signed recommends no packages. shim-signed suggests no packages. - -- debconf information: shim-signed/revoked-sig: * shim-signed/no-valid-sigs: -----BEGIN PGP SIGNATURE----- iGsEARECACsWIQSC1k9rDmfNQfaJu6b7LFEw1VqIGQUCamCtQA0cbjBuYkBuMG5i LnVzAAoJEPssUTDVWogZg/cAn21NqAN/CvJMHs2NC9zP9lGguwcbAJ0SRmHBFYOz UkaH9tQpN/UeLKiFYA== =ul3S -----END PGP SIGNATURE-----

