shim-signed (1.51~1+deb13u1) trixie; urgency=medium
* Signed versions of the 16.1-2~deb13u1 shim build for trixie
* Update build-dep to use 16.1-2~deb13u1
-- Steve McIntyre <93sam@debian.org> Mon, 22 Jun 2026 22:30:37 +0100
shim-signed (1.51) unstable; urgency=medium
* In preinst, don't look for the included binary. There's no point.
* More minor tweaks to the verify_combine_sigs script, and add an
explicit license
-- Steve McIntyre <93sam@debian.org> Sun, 21 Jun 2026 23:20:48 +0100
shim-signed (1.50) unstable; urgency=medium
* Fix up stupid omission in the previous package upload - the
changes in 1.49 did not take into account the "SecureBoot enabled"
case when adding a default error trap. Closes: #1137098, #1137101.
-- Steve McIntyre <93sam@debian.org> Tue, 19 May 2026 23:35:39 +0100
shim-signed (1.49) unstable; urgency=medium
* Make mokutil parsing more robust. Closes: #1137063
+ Cope with "Platform is in Setup Mode" message
+ If we get any other unexpected output, print what we got for debugging.
-- Steve McIntyre <93sam@debian.org> Tue, 19 May 2026 09:42:16 +0100
shim-signed (1.48) unstable; urgency=medium
* Add support for verifying and then combining signatures from
multiple signed shims.
+ Existing sbverify versions in Debian are buggy when verifying.
+ Switch to using a python script verify_combine_sigs to fill in
the gaps.
* In preinst, try to verify that the signed shim we're trying to
install will actually boot on this system - let's not break
systems on upgrade.
* We now include a dual-signed shim including the 2023 CA.
Closes: #1112197
* The shim included is now NX-capable. Closes: #1064102
-- Steve McIntyre <93sam@debian.org> Sun, 17 May 2026 22:47:06 +0100
shim-signed (1.47) unstable; urgency=medium
* update-secureboot-policy: do better checking around DKMS
If we have DKMS modules installed:
+ Check to see if a DKMS MOK key has been created and enrolled;
+ Check that all the DKMS modules are signed with that key;
If successful, don't tell users to disable Secure Boot.
Closes: #1108278.
Add dependencies on openssl and kmod for shim-signed-common,
needed for implementing these check.
-- Steve McIntyre <93sam@debian.org> Tue, 29 Jul 2025 18:40:14 +0100
shim-signed (1.46) unstable; urgency=medium
* No-change rebuild to upload source-only. Argh. :-/
-- Steve McIntyre <93sam@debian.org> Mon, 23 Jun 2025 11:55:58 +0100
shim-signed (1.45) unstable; urgency=medium
[ Luca Boccassi ]
* Add alternative dependencies on systemd-boot. Closes: #1086714
[ Carles Pina i Estany ]
* Add po-debconf Catalan translation. Closes: #1106345
-- Steve McIntyre <93sam@debian.org> Sun, 22 Jun 2025 23:47:17 +0100
shim-signed (1.44) unstable; urgency=medium
[ Fabian Grünbichler ]
* d/rules: import architecture.mk earlier. Closes: #1074744
* fix shim-helpers substvar handling
-- Steve McIntyre <93sam@debian.org> Wed, 03 Jul 2024 01:08:50 +0100
shim-signed (1.43) unstable; urgency=medium
* Fix broken usage of dpkg-query
-- Steve McIntyre <93sam@debian.org> Sat, 29 Jun 2024 13:00:23 +0100
shim-signed (1.42) unstable; urgency=medium
* Tweak versioning in runtime dependencies, using substvars
to make things more automatic in future.
-- Steve McIntyre <93sam@debian.org> Fri, 28 Jun 2024 00:40:31 +0100
shim-signed (1.41) unstable; urgency=medium
* Build against new signed binaries corresponding to 15.8-1
+ Closes: #1071215
* NOTE: Stop building packages for i386. The number of functioning
i386 Secure Boot machines is approximately zero at this point.
* Tweak packaging:
+ Switch from debian/compat to build-dep on debhelper-compat
(= 13)
-- Steve McIntyre <93sam@debian.org> Wed, 26 Jun 2024 21:04:27 +0100
shim-signed (1.40) unstable; urgency=medium
* Stop recommending secureboot-db, we don't have that package.
Closes: #1042964, #1041449, #932358
* Add Romanian translation for debconf templates, thanks to
Remus-Gabriel Chelu. Closes: #1039090
-- Steve McIntyre <93sam@debian.org> Fri, 04 Aug 2023 12:21:47 +0100
shim-signed (1.39) unstable; urgency=medium
* Build against new signed binaries corresponding to 15.7-1
+ This syncs up build-deps again. Closes: #1016280
+ We now have arm64 signed shims again \o/
Undo the hacky unsigned arm64 build
Closes: #1008942, #992073, #991478
Pulls multiple other bugfixes in for the signed version:
+ Make sbat_var.S parse right with buggy gcc/binutils
+ Enable NX support at build time, as required by policy for signing
new shim binaries.
+ Fixes argument handling bug with some firmware implementations.
Closes: #995940
* Update build-dep on shim-unsigned to use 15.7-1
* Block Debian grub binaries with sbat < 4 (see #1024617)
+ Update Depends on grub2-common to match.
* postinst/postrm: make config_item() more robust
* Add pt_BR translation, thanks to Paulo Henrique de Lima
Santana. Closes: #1026415
* Tweak dependencies
-- Steve McIntyre <93sam@debian.org> Thu, 09 Mar 2023 00:58:53 +0000
shim-signed (1.38) unstable; urgency=medium
* Tweak how we call grub-install; don't abort on error. Not ideal
behaviour either, but don't break upgrades. Copy the behaviour
from the grub packages here. Closes: #990984
* Update build-dep on shim-unsigned to use 15.4-7
-- Steve McIntyre <93sam@debian.org> Mon, 12 Jul 2021 12:46:52 +0100
shim-signed (1.37) unstable; urgency=medium
* Build against new signed binaries corresponding to 15.4-6
Pulls multiple bugfixes in for the signed version:
+ Add arm64 patch to tweak section layout and stop crashing
problems. Upstream issue #371. (#990082, #990190)
+ In insecure mode, don't abort if we can't create the MokListXRT
variable. Upstream issue #372. (#989962, #990158)
* Update build-dep on shim-unsigned to use 15.4-6
-- Steve McIntyre <93sam@debian.org> Tue, 29 Jun 2021 09:26:20 +0100
shim-signed (1.36) unstable; urgency=medium
* Add defensive code around calls to db_get. Don't fail if they
return errors. Closes: #988114
* Update build-dep on shim-unsigned to use 15.4-5
-- Steve McIntyre <93sam@debian.org> Thu, 06 May 2021 00:50:02 +0100
shim-signed (1.35) unstable; urgency=medium
* Add explicit dependency from shim-signed to shim-signed-common.
Also check if we have update-secureboot-policy available before we
try to call it. Closes: #988047, #988056
* If we're not running on an EFI system then exit cleanly in
postinst and postrm. We have nothing to do here. Closes: #988059
* Fix the old doc links for shim-signed. Closes: #988057
* Update build-dep on shim-unsigned
-- Steve McIntyre <93sam@debian.org> Tue, 04 May 2021 18:47:42 +0100
shim-signed (1.34) unstable; urgency=medium
* Build against new signed binaries corresponding to 15.4-2
Closes: #971129, #987991
* ***WARNING***: arm64 shim is no longer signed, due to major
toolchain problems. See NEWS.Debian for more
information. Separated out the binary package for arm64 to allow
for a different description, and tweaked the Makefile too.
* Update build-deps and Standards-Version
* Tweak Makefile setup - do our verification testing chained from
the "all" target, not "clean". Closes: #936002
* Don't include apport stuff in the Debian build, it's not useful.
* Tweak dh_install* usage for docs.
* Add Spanish translation for debconf templates, thanks to
Camaleón. Closes: #987339
* Multiple bugfixes in postinst and postrm handling:
+ Call grub-install using the correct grub target in postinst
+ Also call grub-install using the correct grub target in the
postrm, and clean up the shim binary from the ESP
+ In each case, also check and use the correct configured options
for grub-install
+ Move the postinst grub-install code from the -common package to
the arch-specific packages, to make sure it's always called when
needed.
+ Only run grub-install etc. if we're actually on an EFI-booted
system.
-- Steve McIntyre <93sam@debian.org> Mon, 03 May 2021 20:13:04 +0100
# Older entries have been removed from this changelog.
# To read the complete changelog use `apt changelog shim-signed-common`.
Generated by dwww version 1.16 on Sat Oct 3 04:50:29 CEST 2026.