Your message dated Tue, 19 May 2026 09:04:02 +0000
with message-id <[email protected]>
and subject line Bug#1137063: fixed in shim-signed 1.49
has caused the Debian Bug report #1137063,
regarding shim-signed_1.48+16.1-2_amd64.deb fails to install
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1137063: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1137063
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Package: shim-signed
Version: 1.47+15.8-1 (Actually 1.48+16.1-2)
Severity: serious
Justification: unsure
X-Debbugs-Cc: [email protected]
User: [email protected]
Usertags: amd64
Dear Maintainer,
Running apt update with tries to install shim-signed_1.48+16.1-2_amd64.deb but
fails with the following:
No valid UEFI Secure Boot signatures found
│
│ UEFI Secure Boot is enabled on your system, but the signed shim binary in
this package is not signed with a key that your system trusts. This is a FATAL
ERROR - your system will not currently boot with this
│ signed shim installed.
│
│ To fix this error, you probably need to update the trusted certificates list
(DB) on your system. See
│
│ https://wiki.debian.org/SecureBoot/CAChanges
│
│ for more information about how to do this.
mokutil --sb-state
SecureBoot disabled
Platform is in Setup Mode
mokutil --list-enrolled
#Only have
Subject: CN=Debian Secure Boot CA
Points to https://wiki.debian.org/SecureBoot/CAChanges
Which just says:
"More to come soon..."
-- System Information:
Debian Release: forky/sid
APT prefers unstable-debug
APT policy: (500, 'unstable-debug'), (500, 'unstable')
Architecture: amd64 (x86_64)
Foreign Architectures: i386
Kernel: Linux 6.19.11+deb14-amd64 (SMP w/12 CPU threads; PREEMPT)
Kernel taint flags: TAINT_PROPRIETARY_MODULE, TAINT_OOT_MODULE,
TAINT_UNSIGNED_MODULE
Locale: LANG=en_NZ.UTF-8, LC_CTYPE=en_NZ.UTF-8 (charmap=UTF-8),
LANGUAGE=en_NZ:en
Shell: /bin/sh linked to /usr/bin/dash
Init: systemd (via /run/systemd/system)
Versions of packages shim-signed depends on:
ii grub-efi-amd64-bin 2.14~git20250718.0e36779-2
ii grub2-common 2.14~git20250718.0e36779-2
ii shim-helpers-amd64-signed 1+16.1+2
iu shim-signed-common 1.48+16.1-2
shim-signed recommends no packages.
shim-signed suggests no packages.
-- debconf information:
* shim-signed/no-valid-sigs:
shim-signed/revoked-sig:
--- End Message ---
--- Begin Message ---
Source: shim-signed
Source-Version: 1.49
Done: Steve McIntyre <[email protected]>
We believe that the bug you reported is fixed in the latest version of
shim-signed, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Steve McIntyre <[email protected]> (supplier of updated shim-signed package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Tue, 19 May 2026 09:42:16 +0100
Source: shim-signed
Architecture: source
Version: 1.49
Distribution: unstable
Urgency: medium
Maintainer: Debian EFI Team <[email protected]>
Changed-By: Steve McIntyre <[email protected]>
Closes: 1137063
Changes:
shim-signed (1.49) unstable; urgency=medium
.
* Make mokutil parsing more robust. Closes: #1137063
+ Cope with "Platform is in Setup Mode" message
+ If we get any other unexpected output, print what we got for debugging.
Checksums-Sha1:
586f47f28554502b4c8fd8960281c6d8ccb5971d 1915 shim-signed_1.49.dsc
fabd44979fa6058a9231fa43f412ef8010b3976c 823984 shim-signed_1.49.tar.xz
69a845e01d21f57c3945683f820b17e140e3a77e 6069 shim-signed_1.49_source.buildinfo
Checksums-Sha256:
c3476328d1c0df6075986129999570ec4cdfa91d7e4f969194e1fd325a90111e 1915
shim-signed_1.49.dsc
5b34230d39771065527e869652ac428814af424ae02df479f619e5d672503303 823984
shim-signed_1.49.tar.xz
f6f9184f5a505faba8223084a952f146d43ea70194f690b1293437b37485e43f 6069
shim-signed_1.49_source.buildinfo
Files:
d2a8d67337593601a52468c477ba68b8 1915 utils optional shim-signed_1.49.dsc
8f4f4359e9a9f0bda151cd4c011795ce 823984 utils optional shim-signed_1.49.tar.xz
c8c234fcb87669a63e0c55690d92cd0e 6069 utils optional
shim-signed_1.49_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQJFBAEBCgAvFiEEzrtSMB1hfpEDkP4WWHl5VzRCaE4FAmoMI1kRHDkzc2FtQGRl
Ymlhbi5vcmcACgkQWHl5VzRCaE52Sw/+K57/rRS2mrgWaZeldtqPKRFzZvfe5igf
dN1kWwvI3pA01t/nKwvwE/KWAGrZAbF+Sf3wg4Ldy3xuH+vXIY83CQ4satka7Soa
OuntuP5sm6OaJEeDjQHXbatU4wiCHKHE2qkNnNM4e7JiqeJn6AwK1dDFNn7LeJ5b
9FwhpL5Wg4xhZE8LlYBDMIuOcLj+3k+d+wuvcube5Oz9GTY8OE20X0GXEyfG5Zi4
4NByTkZFcoz6EWsRHEtOn+WC2+fdJ9NVvKOsEYbIL04m5oVFYiTCp6d60sXXeg3z
KkjIjMEGm0utaoVo3gYKbfPGqxWeYOYstqYeNiQfqu0DzQ3gSJC3ni9GrG1Of45q
i+hEzGvKnM8wTMCt3rDr/XK61Be698jRYw8n7V1cuvuyADb3WXak0zgdtdHefdH7
dS0qo6OmIXeAMwRa24LBRDgN5soFqskCpmu0ziwQtHafPXUU5IpDOFZpKVw+2mWr
JNz7hZNukdEKTwtjvudlQpaIkIqEP0FiVqEvm54wu4EWPfOKiK+Q87ZrrEGB1j5b
7Cx+g2GHrDftjj7QzwS+fY3sz9x7K3M9U/ZremEaVUMAu8pyENSw/oNnfFq7wRyf
tx3Eib7fcT/gJc9lqj4XlINEO+VWH1fttsGYmSe57iU7EQX71mIn8ZG/f91c+8fT
QTja/E3oAiE=
=CW43
-----END PGP SIGNATURE-----
pgp16uffImP9h.pgp
Description: PGP signature
--- End Message ---