#1082012 shim-signed-common: dialog suggests disabling Secure Boot even if MOK is available

#1082012#5
Date:
2024-09-17 13:06:02 UTC
From:
To:
shim-signed-common seems to be the origin (slightly hard to tell) of a
dialog during apt dist-upgrade that suggests UEFI Secure Boot must be
disabled to use 3rd party drivers.  It doesn't seem to check whether a
Machine Owner Key is installed in the UEFI trust database and/or
configured for DKMS.  It should check before misleading the user into
disabling a security feature.  (Especially considering the amount of
hoops someone had to jump through to set it up, and then take into
consideration someone tech-savvy might have set this up for their
tech-limited political refugee grandparent.)

Relevant config:

/etc/dkms/framework.conf:mok_signing_key=/root/.mok/mok.key
/etc/dkms/framework.conf:mok_certificate=/root/.mok/mok.der

Output of "mokutil --list-enrolled" (abbreviated):

[key 1]
SHA1 Fingerprint: 53:61:0c:f8:1f:bd:7e:0c:eb:67:91:3c:9e:f3:e7:94:a9:63:3e:cb
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            ed:54:a1:d5:af:87:48:94:8d:9f:89:32:ee:9c:7c:34
        Signature Algorithm: sha256WithRSAEncryption
        Issuer: CN=Debian Secure Boot CA
        Subject: CN=Debian Secure Boot CA
    [...snip...]

[key 2]
SHA1 Fingerprint: ...
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            ...
        Signature Algorithm: sha256WithRSAEncryption
        Issuer: CN=equinox/emailAddress=equinox@diac24.net
        Subject: CN=equinox/emailAddress=equinox@diac24.net