On Sat, 5 Sep 2026 23:16:33 +0200 Chris Hofstaedtler <[email protected]> wrote: > On Sat, Sep 05, 2026 at 09:22:20PM +0300, Grundik wrote: > > The systemd-boot-efi-amd64-signed package provides a signed systemd-boot EFI > > binary, but it does not include the certificate used to sign it. I cannot find > > any official source that provides this certificate, which seems rather odd. > > src:shim has it, and also https://dsa.debian.org/secure-boot-ca >
Thanks! Its also possible to extract the certificate from the systemd- boot EFI binary itself. But that would be way more convenient, if it were provided in package itself in a clear and obvious way. Maybe as a part of the docs, or something like that.

