[Bug 2017699] [NEW] System with SecureBoot enabled do not boot with shim-signed_1.40.9+15.7-0ubuntu1
TQ
2017699 at bugs.launchpad.net
Tue Apr 25 20:32:06 UTC 2023
Public bug reported:
when I try to make a bootable usb by command "/usr/sbin/grub-install
--target=x86_64-efi --efi-directory=$mnt/efi --boot-
directory=$mnt/efi/boot --removable --recheck" it always failed with
error "bad shim signature", it works before but failed after system
update shim-signed to version 1.40.9+15.7-0ubuntu1. Can anyone take a
look about the issue?
part of the log file like below:
/usr/sbin/grub-install: info: adding 62 padding fixup entries.
/usr/sbin/grub-install: info: writing 704 bytes of a fixup block starting at 0x10000.
/usr/sbin/grub-install: info: reading /usr/lib/grub/x86_64-efi/fshelp.mod.
/usr/sbin/grub-install: info: reading /usr/lib/grub/x86_64-efi/fat.mod.
/usr/sbin/grub-install: info: reading /usr/lib/grub/x86_64-efi/part_msdos.mod.
/usr/sbin/grub-install: info: reading /usr/lib/grub/x86_64-efi/search_fs_uuid.mod.
/usr/sbin/grub-install: info: reading /mnt/boot/grub/x86_64-efi/load.cfg.
/usr/sbin/grub-install: info: kernel_img=0x556b65dbede0, kernel_size=0x1c000.
/usr/sbin/grub-install: info: the core size is 0x213f8.
/usr/sbin/grub-install: info: writing 0x24000 bytes.
/usr/sbin/grub-install: info: copying `/usr/lib/grub/x86_64-efi-signed/gcdx64.efi.signed' -> `/mnt/EFI/BOOT/grubx64.efi'.
/usr/sbin/grub-install: info: copying `/usr/lib/shim/shimx64.efi.signed' -> `/mnt/EFI/BOOT/BOOTX64.EFI'.
/usr/sbin/grub-install: info: copying `/usr/lib/shim/mmx64.efi' -> `/mnt/EFI/BOOT/mmx64.efi'.
/usr/sbin/grub-install: info: copying `/usr/lib/shim/BOOTX64.CSV' -> `/mnt/EFI/BOOT/BOOTX64.CSV'.
/usr/sbin/grub-install: info: copying `/mnt/boot/grub/x86_64-efi/load.cfg' -> `/mnt/EFI/BOOT/grub.cfg'.
Installation finished. No error reported.
the sha256 of the efi file:
EFI/BOOT/grubx64.efi: cfb70ff2ce0d7b6741f2529d6112561229117d6fa19d21337cf7d7ace59dc1f8
EFI/BOOT/BOOTX64.EFI: 0585000d937228e4bf6bd4cbfd087440086c04b889b047882ab6b2cf2a35293b
EFI/BOOT/mmx64.efi: c4c3cd70c4a394af7311a917637aa9c7b46bd9e0b1e007c2b268d14ff31ce889
/usr/lib/grub/x86_64-efi-signed/grubx64.efi.signed: 61aa3de565a2a5d092399a79ffd6bce2200d449e3f116134329743f9b1ad3f4b
/usr/lib/grub/x86_64-efi-signed/gcdx64.efi.signed:
cfb70ff2ce0d7b6741f2529d6112561229117d6fa19d21337cf7d7ace59dc1f8
/usr/lib/shim/shimx64.efi.signed: 0585000d937228e4bf6bd4cbfd087440086c04b889b047882ab6b2cf2a35293b
/usr/lib/shim/mmx64.efi: c4c3cd70c4a394af7311a917637aa9c7b46bd9e0b1e007c2b268d14ff31ce889
** Affects: shim-signed (Ubuntu)
Importance: Undecided
Status: New
** Description changed:
when I try to make a bootable usb by command "/usr/sbin/grub-install
--target=x86_64-efi --efi-directory=$mnt/efi --boot-
directory=$mnt/efi/boot --removable --recheck" it always failed with
error "bad shim signature", it works before but failed after system
- update shim-signed to version 1.40.9+15.7-0ubuntu1?
+ update shim-signed to version 1.40.9+15.7-0ubuntu1. Can anyone take a
+ look about the issue?
--
You received this bug notification because you are a member of Ubuntu
Foundations Bugs, which is subscribed to shim-signed in Ubuntu.
https://bugs.launchpad.net/bugs/2017699
Title:
System with SecureBoot enabled do not boot with shim-
signed_1.40.9+15.7-0ubuntu1
Status in shim-signed package in Ubuntu:
New
Bug description:
when I try to make a bootable usb by command "/usr/sbin/grub-install
--target=x86_64-efi --efi-directory=$mnt/efi --boot-
directory=$mnt/efi/boot --removable --recheck" it always failed with
error "bad shim signature", it works before but failed after system
update shim-signed to version 1.40.9+15.7-0ubuntu1. Can anyone take a
look about the issue?
part of the log file like below:
/usr/sbin/grub-install: info: adding 62 padding fixup entries.
/usr/sbin/grub-install: info: writing 704 bytes of a fixup block starting at 0x10000.
/usr/sbin/grub-install: info: reading /usr/lib/grub/x86_64-efi/fshelp.mod.
/usr/sbin/grub-install: info: reading /usr/lib/grub/x86_64-efi/fat.mod.
/usr/sbin/grub-install: info: reading /usr/lib/grub/x86_64-efi/part_msdos.mod.
/usr/sbin/grub-install: info: reading /usr/lib/grub/x86_64-efi/search_fs_uuid.mod.
/usr/sbin/grub-install: info: reading /mnt/boot/grub/x86_64-efi/load.cfg.
/usr/sbin/grub-install: info: kernel_img=0x556b65dbede0, kernel_size=0x1c000.
/usr/sbin/grub-install: info: the core size is 0x213f8.
/usr/sbin/grub-install: info: writing 0x24000 bytes.
/usr/sbin/grub-install: info: copying `/usr/lib/grub/x86_64-efi-signed/gcdx64.efi.signed' -> `/mnt/EFI/BOOT/grubx64.efi'.
/usr/sbin/grub-install: info: copying `/usr/lib/shim/shimx64.efi.signed' -> `/mnt/EFI/BOOT/BOOTX64.EFI'.
/usr/sbin/grub-install: info: copying `/usr/lib/shim/mmx64.efi' -> `/mnt/EFI/BOOT/mmx64.efi'.
/usr/sbin/grub-install: info: copying `/usr/lib/shim/BOOTX64.CSV' -> `/mnt/EFI/BOOT/BOOTX64.CSV'.
/usr/sbin/grub-install: info: copying `/mnt/boot/grub/x86_64-efi/load.cfg' -> `/mnt/EFI/BOOT/grub.cfg'.
Installation finished. No error reported.
the sha256 of the efi file:
EFI/BOOT/grubx64.efi: cfb70ff2ce0d7b6741f2529d6112561229117d6fa19d21337cf7d7ace59dc1f8
EFI/BOOT/BOOTX64.EFI: 0585000d937228e4bf6bd4cbfd087440086c04b889b047882ab6b2cf2a35293b
EFI/BOOT/mmx64.efi: c4c3cd70c4a394af7311a917637aa9c7b46bd9e0b1e007c2b268d14ff31ce889
/usr/lib/grub/x86_64-efi-signed/grubx64.efi.signed: 61aa3de565a2a5d092399a79ffd6bce2200d449e3f116134329743f9b1ad3f4b
/usr/lib/grub/x86_64-efi-signed/gcdx64.efi.signed:
cfb70ff2ce0d7b6741f2529d6112561229117d6fa19d21337cf7d7ace59dc1f8
/usr/lib/shim/shimx64.efi.signed: 0585000d937228e4bf6bd4cbfd087440086c04b889b047882ab6b2cf2a35293b
/usr/lib/shim/mmx64.efi: c4c3cd70c4a394af7311a917637aa9c7b46bd9e0b1e007c2b268d14ff31ce889
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/shim-signed/+bug/2017699/+subscriptions
More information about the foundations-bugs
mailing list