[Bug 1936759] Re: shim-signed 1.48+15.4-0ubuntu5 does not secure boot

Jacques Williamson 1936759 at bugs.launchpad.net
Mon Jul 19 18:46:52 UTC 2021


$ sudo apt install shim-signed=1.50+15.4-0ubuntu7
... from proposed packages, followed by a reboot with secure boot enabled has the same result, stuck on UEFI vendor firmware logo.

Trying to capture additional logging for you next.

-- 
You received this bug notification because you are a member of Ubuntu
Foundations Bugs, which is subscribed to shim-signed in Ubuntu.
https://bugs.launchpad.net/bugs/1936759

Title:
  shim-signed 1.48+15.4-0ubuntu5 does not secure boot

Status in shim-signed package in Ubuntu:
  Incomplete

Bug description:
  shim-signed package installs with no error with apt upgrade, but then
  the system cannot boot afterwards with secure boot enabled. System
  hangs indefinitely on UEFI manufacturer logo screen (Dell in this
  case), not getting as far as grub. Disabling secure boot is a
  workaround.

  Rolling back to previous shim-signed version 1.46+15.4-0ubuntu1 fixes
  the problem (system can once again boot with secure boot enabled).

  Done this for now to allow secure boot to be enabled:
  $ sudo apt install shim-signed=1.46+15.4-0ubuntu1
  $ sudo apt-mark hold shim-signed

  Details of system where problem is observed:
  - Dell XPS 13 7390 laptop
  - Intel® Core™ i7-10510U CPU / 16GB RAM
  - BIOS/UEFI firmware version: v1.8.0 (latest)
  - Ubuntu hirsute 21.04 64bit (Linux only, single OS, not dual booting)
  - Kernel version: 5.11.0-22-generic
  - GRUB: 2.04-1ubuntu45

  Any questions / additional info, please ask.
  --- 
  ProblemType: Bug
  .proc.sys.kernel.moksbstate_disabled: Error: [Errno 2] No such file or directory: '/proc/sys/kernel/moksbstate_disabled'
  ApportVersion: 2.20.11-0ubuntu65.1
  Architecture: amd64
  CasperMD5CheckResult: unknown
  CurrentDesktop: ubuntu:GNOME
  DistroRelease: Ubuntu 21.04
  EFIBootMgr:
   BootCurrent: 0000
   Timeout: 0 seconds
   BootOrder: 0000,0001
   Boot0000* ubuntu	HD(2,GPT,cc31568c-2d13-40c3-8cfe-a0d889852837,0x800,0x32000)/File(\EFI\ubuntu\shimx64.efi)
   Boot0001* UEFI CT1000P1SSD8 1917E1FE1D9D 1	PciRoot(0x0)/Pci(0x1d,0x4)/Pci(0x0,0x0)/NVMe(0x1,00-00-00-00-00-00-00-00)/HD(2,GPT,cc31568c-2d13-40c3-8cfe-a0d889852837,0x800,0x32000)/File(\EFI\Boot\BootX64.efi)N.....YM....R,Y.
  EcryptfsInUse: Yes
  InstallationDate: Installed on 2020-01-26 (540 days ago)
  InstallationMedia: Ubuntu 19.10 "Eoan Ermine" - Release amd64 (20191017)
  Package: shim-signed 1.46+15.4-0ubuntu1
  PackageArchitecture: amd64
  ProcVersionSignature: Ubuntu 5.11.0-22.23-generic 5.11.21
  SecureBoot: 6   0   0   0   1
  Tags:  hirsute wayland-session
  Uname: Linux 5.11.0-22-generic x86_64
  UpgradeStatus: Upgraded to hirsute on 2021-05-29 (51 days ago)
  UserGroups: adm cdrom dip docker lpadmin lxd plugdev sambashare sudo
  _MarkForUpload: True

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/shim-signed/+bug/1936759/+subscriptions




More information about the foundations-bugs mailing list