This is trying to mirror our insanely large MokListX to MokListXRT, which is so large due to COVID related travel restrictions preventing the generation of a new signing key, and having to revoke all binaries this way instead.
However, we do not actually need to mirror that list AFAIUI, because the kernel, which would consume the list, does not actually support revoking binaries by hash (and it can kexec kernels, but not the grubs we worry about). On other platforms, this just causes a warning followed by a 10s wait. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1928434 Title: shim-signed does not boot on EFI 2.40 by Apple To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/shim/+bug/1928434/+subscriptions -- ubuntu-bugs mailing list [email protected] https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs
