-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 05 May 2024 11:33:57 +0100 Source: shim Binary: shim-helpers-amd64-signed-template shim-unsigned Architecture: amd64 Version: 15.8-1~deb11u1 Distribution: bullseye Urgency: medium Maintainer: amd64 / i386 Build Daemon (x86-csail-01) Changed-By: Steve McIntyre <93sam@debian.org> Description: shim-helpers-amd64-signed-template - boot loader to chain-load signed boot loaders (signing template) shim-unsigned - boot loader to chain-load signed boot loaders under Secure Boot Closes: 1046268 1069054 Changes: shim (15.8-1~deb11u1) bullseye; urgency=medium . * New upstream release fixing more bugs * Remove all our previous patches, no longer needed: + Make-sbat_var.S-parse-right-with-buggy-gcc-binutils.patch (now upstream) + Enable-NX.patch (we don't want NX just yet until the whole boot stack is NX-capable) + block-grub-sbat3-debian.patch (not needed now upstream grub SBAT is 4) * Cherry-pick 2 new patches from upstream for grub revocations: + 0001-sbat-Add-grub.peimage-2-to-latest-CVE-2024-2312.patch + 0002-sbat-Also-bump-latest-for-grub-4-and-to-todays-date.patch * Log if the build is nx-compatible or not * Force shim to use the latest revocations by default to block some older grub / peimage issues. This is: "shim,4\ngrub,4\ngrub.peimage,2\n" * Install a copy of the Debian CA certificate into /usr/share/shim. Closes: #1069054 * Clean up better after build. Closes: #1046268 Checksums-Sha1: 5d36786a09dd54cc48e5d251f5d50bf81036a953 15412 shim-helpers-amd64-signed-template_15.8-1~deb11u1_amd64.deb a296865d3d0d1aaf7ac6112e0b63482ff0ca0924 442556 shim-unsigned_15.8-1~deb11u1_amd64.deb 253f288b1870d0013415ba746cd4470eea809bd4 6820 shim_15.8-1~deb11u1_amd64-buildd.buildinfo Checksums-Sha256: 3346221cb9181e7a6962642ee8e52b17619f378d9de7e2456304c482a59f48fa 15412 shim-helpers-amd64-signed-template_15.8-1~deb11u1_amd64.deb 06cf3b610acaff5f68f8f09a1005730de9c3740ddb54aab2f87a69b5efe12745 442556 shim-unsigned_15.8-1~deb11u1_amd64.deb 07548b37c438ea0b73caba802384e209fb3a8d67a415610ae5eadff710c580e9 6820 shim_15.8-1~deb11u1_amd64-buildd.buildinfo Files: e77e9604f754902ce2a2d2eb506a8ecd 15412 admin optional shim-helpers-amd64-signed-template_15.8-1~deb11u1_amd64.deb a1c75bec2190855a253cf9ef6dbfec14 442556 admin optional shim-unsigned_15.8-1~deb11u1_amd64.deb e822f2cd810c68bdac9c1462c4e55045 6820 admin optional shim_15.8-1~deb11u1_amd64-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEvy6d65NNYPbL6IQIEQ1nooK/IAQFAmY7xpcACgkQEQ1nooK/ IAQPOg/+LeswO9rhHQJ5mxvlk4jU3msQGT/Yhf1OgdoGmlY4dAQR70rJ+DTXQ2nl O//YmpPNAbQfb9Pkml4hDXQZSiJjHrcF/FObSkI4FKjGT+b41y6R8aa8J6SyUFAJ gDrgo3Weo1cknM//1G0bK0x+pemuqqVBuTKfQLCaht/0lJL8cVY55qspoWfPCj+1 SHZA7c32qh+983LKCJEa3pUkLww8EiC/7dL4YyosH7hkvNbeSQ1fldozWDpuZ9v5 aEnd2nnZ4BFPlFTq2rwCqRB8+sLz0txQFdUocZ9BiwCml3xCiWbxB/H8tT0xW5kL EsA9Ov2NCjwlQi9mPZkDIkyOUSxZmD1IwQ13zpD3/4KHOf+PWzZW/OEVyqr6xgfh FD9yl+v+DwSc3gwELaLlcbToPs8UQnxX3WEeNFPnTgZUmubpbN175PwbScMoVk2b PTDlboU9VKkgcvGh1CQOpkhu9jOIFUy9ys3UrNPGX+GtxhAzTLbD5x8Ju4g1XZ6/ /QVoP2xKphovvbHBvjCJR+sfZq0GcKUkoXFAbss3mMwZhTCtqN3yGEuoi0vCfLZy EYigtJu0F6Hlk1iEbekkF5g8JWiU4OdlCXbDB2CRSx1HQff7tn3XJqLrO2UfwGcg v0QsoKUIW4EIthJ3vMvu4kXvx8CEpUweQL/OxXQvBu3iED3Mjg8= =X/LC -----END PGP SIGNATURE-----