#1140760 trixie-pu: package shim-signed/1.51~1+deb13u1

#1140760#5
Date:
2026-06-25 23:11:13 UTC
From:
To:
Hey folks,

As mentioned in #1131861...

We've had new signed shim binaries back from Microsoft for some
time. I've been waiting on the fix for #1137247 (hang/crash
chainloading Windows from grub) in case that might have been shim bug,
but it's now been fixed in grub and we're good.

So, it's time to get a new shim-signed package into trixie. I've
backported the logic from 1.51 in unstable:

  * Add support for verifying and then combining signatures from
    multiple signed shims.
    + Existing sbverify versions in Debian are buggy when verifying.
    + Switch to using a python script verify_combine_sigs to fill in
      the gaps.
  * In preinst, try to verify that the signed shim we're trying to
    install will actually boot on this system - let's not break
    systems on upgrade.

and imported the signed shim binaries which resulted from the trixie
shim update in #1131861.

We need this new signed shim to allowe trixie to install and run on
newer systems which may ship with *only* the new 2023 UEFI CA included
in firmware.

See https://wiki.debian.org/SecureBoot/CAChanges for more background.

#1140760#12
Date:
2026-06-26 20:51:55 UTC
From:
To:
package release.debian.org
tags 1140760 = trixie pending
thanks

Hi,

The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian trixie.

Thanks for your contribution!

Upload details
==============

Package: shim-signed
Version: 1.51~1+deb13u1

Explanation: ensure Secure Boot compatibility with 2023 Microsoft UEFI CA; check for likely boot issues before installation; combine and verify multiple shim signatures; update signed shim binaries

#1140760#17
Date:
2026-06-26 20:51:55 UTC
From:
To:
package release.debian.org
tags 1140760 = trixie pending
thanks

Hi,

The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian trixie.

Thanks for your contribution!

Upload details
==============

Package: shim-signed
Version: 1.51~1+deb13u1

Explanation: ensure Secure Boot compatibility with 2023 Microsoft UEFI CA; check for likely boot issues before installation; combine and verify multiple shim signatures; update signed shim binaries