#1142417 shim-signed: After 13.6 upgrade secure boot fails on Lenovo M73

Package:
shim-signed
Source:
shim-signed
Description:
Secure Boot chain-loading bootloader (Microsoft-signed binary)
Submitter:
Nate Bargmann
Date:
2026-07-20 15:57:01 UTC
Severity:
normal
#1142417#5
Date:
2026-07-19 14:04:35 UTC
From:
To:
Dear Maintainer,

As requested, I am filing this bug as even after following the Wiki
instructions, my Lenovo M73 fails to boot in secure boot mode with the
current version of shim-signed in Stable.

Apparently the main keys updated correctly:

# mokutil --db | grep "Subject:.*Microsoft"
        Subject: C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Production PCA 2011
        Subject: C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Corporation UEFI CA 2011
        Subject: C=US, O=Microsoft Corporation, CN=Microsoft UEFI CA 2023
        Subject: C=US, O=Microsoft Corporation, CN=Microsoft Option ROM UEFI CA 2023

However, the KEK key did not:

#  mokutil --kek | grep Subject:.*Microsoft
        Subject: C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Corporation KEK CA 2011

My attempt to update it showed no update available:

# fwupdtool update
Loading…                 [*******************                    ]17:40:41.296 FuEngine             failed to add device /sys/devices/pci0000:00/0000:00:1f.2/ata2/host1/target1:0:0/1:0:0:0/block/sr0: failed to subclass open: failed to open /dev/sr0: No medium found
17:40:41.432 FuEngine             failed to add device /sys/devices/pci0000:00/0000:00:1f.2/ata2/host1/target1:0:0/1:0:0:0/block/sr0: failed to subclass open: failed to open /dev/sr0: No medium found
Loading…                 [************************************** ]
Devices with the latest available firmware version:
 • UEFI CA
 • UEFI dbx
Devices with no available firmware updates:
 • Option ROM UEFI CA
 • Trust - Lenovo Certificate
 • UEFI CA
 • Windows Production PCA
 • CT2000P310SSD8
 • KEK CA
 • System Firmware
 • WDS500G2B0A-00SM50

(Unfortunately, I did not save the original 'fwupdtool update' output
when the UEFI CA keys were updated)

So far I've not downgraded shim-signed to version 1.47 to enable secure
boot again but so far have secure boot disabled in the BIOS setup.

M73 system info:

# dmidecode
# dmidecode 3.6
Getting SMBIOS data from sysfs.
SMBIOS 2.8 present.
37 structures occupying 1720 bytes.
Table at 0x9DED2018.

Handle 0x0000, DMI type 0, 24 bytes
BIOS Information
	Vendor: LENOVO
	Version: FCKT97AUS
	Release Date: 01/07/2020
	Address: 0xF0000
	Runtime Size: 64 kB
	ROM Size: 4 MB
	Characteristics:
		PCI is supported
		BIOS is upgradeable
		BIOS shadowing is allowed
		Boot from CD is supported
		Selectable boot is supported
		BIOS ROM is socketed
		EDD is supported
		5.25"/1.2 MB floppy services are supported (int 13h)
		3.5"/720 kB floppy services are supported (int 13h)
		3.5"/2.88 MB floppy services are supported (int 13h)
		Print screen service is supported (int 5h)
		8042 keyboard services are supported (int 9h)
		Serial services are supported (int 14h)
		Printer services are supported (int 17h)
		ACPI is supported
		USB legacy is supported
		BIOS boot specification is supported
		Targeted content distribution is supported
		UEFI is supported
	BIOS Revision: 1.151

Handle 0x0001, DMI type 1, 27 bytes
System Information
	Manufacturer: LENOVO
	Product Name: 10B00005US
	Version: ThinkCentre M73
	Serial Number: MJ00D7ZZ
	UUID: 66e5795c-9a63-11e3-89c1-3d4e9daf1a00
	Wake-up Type: Power Switch
	SKU Number: LENOVO_MT_10B0
	Family:

Handle 0x0002, DMI type 2, 15 bytes
Base Board Information
	Manufacturer: LENOVO
	Product Name: 3098
	Version: 0B98401 PRO
	Serial Number: INVALID
	Asset Tag:
	Features:
		Board is a hosting board
		Board is replaceable
	Location In Chassis:
	Chassis Handle: 0x0003
	Type: Motherboard
	Contained Object Handles: 0

Handle 0x0003, DMI type 3, 25 bytes
Chassis Information
	Manufacturer: LENOVO
	Type: Desktop
	Lock: Not Present
	Version:
	Serial Number: MJ00D7ZZ
	Asset Tag:
	Boot-up State: Safe
	Power Supply State: Safe
	Thermal State: Safe
	Security Status: None
	OEM Information: 0x00000000
	Height: Unspecified
	Number Of Power Cords: 1
	Contained Elements: 1
		<OUT OF SPEC> (0)
	SKU Number:

Handle 0x0004, DMI type 9, 17 bytes
System Slot Information
	Designation: J6B2
	Type: PCI Express
	Data Bus Width: 16x or x16
	Current Usage: In Use
	Length: Long
	ID: 0
	Characteristics:
		3.3 V is provided
		Opening is shared
		PME signal is supported
	Bus Address: 0000:00:01.0

Handle 0x0005, DMI type 9, 17 bytes
System Slot Information
	Designation: J6B1
	Type: PCI Express
	Data Bus Width: 1x or x1
	Current Usage: In Use
	Length: Short
	ID: 1
	Characteristics:
		3.3 V is provided
		Opening is shared
		PME signal is supported
	Bus Address: 0000:00:1c.3

Handle 0x0006, DMI type 9, 17 bytes
System Slot Information
	Designation: J6D1
	Type: PCI Express
	Data Bus Width: 1x or x1
	Current Usage: In Use
	Length: Short
	ID: 2
	Characteristics:
		3.3 V is provided
		Opening is shared
		PME signal is supported
	Bus Address: 0000:00:1c.4

Handle 0x0007, DMI type 9, 17 bytes
System Slot Information
	Designation: J7B1
	Type: PCI Express
	Data Bus Width: 1x or x1
	Current Usage: In Use
	Length: Short
	ID: 3
	Characteristics:
		3.3 V is provided
		Opening is shared
		PME signal is supported
	Bus Address: 0000:00:1c.5

Handle 0x0008, DMI type 9, 17 bytes
System Slot Information
	Designation: J8B4
	Type: PCI Express
	Data Bus Width: 1x or x1
	Current Usage: In Use
	Length: Short
	ID: 4
	Characteristics:
		3.3 V is provided
		Opening is shared
		PME signal is supported
	Bus Address: 0000:00:1c.6

Handle 0x0009, DMI type 10, 12 bytes
On Board Device 1 Information
	Type: Video
	Status: Enabled
	Description:    Onboard Video
On Board Device 2 Information
	Type: Ethernet
	Status: Enabled
	Description:    Onboard Lan
On Board Device 3 Information
	Type: Sound
	Status: Enabled
	Description:    Onboard Audio
On Board Device 4 Information
	Type: SATA Controller
	Status: Enabled
	Description:    Onboard SATA

Handle 0x000A, DMI type 11, 5 bytes
OEM Strings
	String 1: LENOVO ThinkCentre Embedded Controller -[N/A]-
	String 2: LENOVO ThinkCentre BIOS Boot Block Revision 1.97

Handle 0x000B, DMI type 12, 5 bytes
System Configuration Options
	Option 1: scre++

Handle 0x000C, DMI type 24, 5 bytes
Hardware Security
	Power-On Password Status: Disabled
	Keyboard Password Status: Enabled
	Administrator Password Status: Disabled
	Front Panel Reset Status: Not Implemented

Handle 0x000D, DMI type 32, 20 bytes
System Boot Information
	Status: No errors detected

Handle 0x000E, DMI type 4, 42 bytes
Processor Information
	Socket Designation: SOCKET 0
	Type: Central Processor
	Family: Core i5
	Manufacturer: Intel
	ID: C3 06 03 00 FF FB EB BF
	Signature: Type 0, Family 6, Model 60, Stepping 3
	Flags:
		FPU (Floating-point unit on-chip)
		VME (Virtual mode extension)
		DE (Debugging extension)
		PSE (Page size extension)
		TSC (Time stamp counter)
		MSR (Model specific registers)
		PAE (Physical address extension)
		MCE (Machine check exception)
		CX8 (CMPXCHG8 instruction supported)
		APIC (On-chip APIC hardware supported)
		SEP (Fast system call)
		MTRR (Memory type range registers)
		PGE (Page global enable)
		MCA (Machine check architecture)
		CMOV (Conditional move instruction supported)
		PAT (Page attribute table)
		PSE-36 (36-bit page size extension)
		CLFSH (CLFLUSH instruction supported)
		DS (Debug store)
		ACPI (ACPI supported)
		MMX (MMX technology supported)
		FXSR (FXSAVE and FXSTOR instructions supported)
		SSE (Streaming SIMD extensions)
		SSE2 (Streaming SIMD extensions 2)
		SS (Self-snoop)
		HTT (Multi-threading)
		TM (Thermal monitor supported)
		PBE (Pending break enabled)
	Version: Intel(R) Core(TM) i5-4570 CPU @ 3.20GHz
	Voltage: 1.2 V
	External Clock: 100 MHz
	Max Speed: 3200 MHz
	Current Speed: 3200 MHz
	Status: Populated, Enabled
	Upgrade: Socket BGA1155
	L1 Cache Handle: 0x0010
	L2 Cache Handle: 0x000F
	L3 Cache Handle: 0x0011
	Serial Number: Not Specified
	Asset Tag: Fill By OEM
	Part Number: Fill By OEM
	Core Count: 4
	Core Enabled: 4
	Thread Count: 4
	Characteristics:
		64-bit capable

Handle 0x000F, DMI type 7, 19 bytes
Cache Information
	Socket Designation: CPU Internal L2
	Configuration: Enabled, Not Socketed, Level 2
	Operational Mode: Write Back
	Location: Internal
	Installed Size: 1 MB
	Maximum Size: 1 MB
	Supported SRAM Types:
		Unknown
	Installed SRAM Type: Unknown
	Speed: Unknown
	Error Correction Type: Single-bit ECC
	System Type: Unified
	Associativity: 8-way Set-associative

Handle 0x0010, DMI type 7, 19 bytes
Cache Information
	Socket Designation: CPU Internal L1
	Configuration: Enabled, Not Socketed, Level 1
	Operational Mode: Write Back
	Location: Internal
	Installed Size: 256 kB
	Maximum Size: 256 kB
	Supported SRAM Types:
		Unknown
	Installed SRAM Type: Unknown
	Speed: Unknown
	Error Correction Type: Single-bit ECC
	System Type: Other
	Associativity: 8-way Set-associative

Handle 0x0011, DMI type 7, 19 bytes
Cache Information
	Socket Designation: CPU Internal L3
	Configuration: Enabled, Not Socketed, Level 3
	Operational Mode: Write Back
	Location: Internal
	Installed Size: 6 MB
	Maximum Size: 6 MB
	Supported SRAM Types:
		Unknown
	Installed SRAM Type: Unknown
	Speed: Unknown
	Error Correction Type: Single-bit ECC
	System Type: Unified
	Associativity: 12-way Set-associative

Handle 0x0012, DMI type 16, 23 bytes
Physical Memory Array
	Location: System Board Or Motherboard
	Use: System Memory
	Error Correction Type: None
	Maximum Capacity: 16 GB
	Error Information Handle: Not Provided
	Number Of Devices: 2

Handle 0x0013, DMI type 17, 40 bytes
Memory Device
	Array Handle: 0x0012
	Error Information Handle: Not Provided
	Total Width: 64 bits
	Data Width: 64 bits
	Size: 8 GB
	Form Factor: DIMM
	Set: None
	Locator: ChannelA-DIMM0
	Bank Locator: BANK 0
	Type: DDR3
	Type Detail: Synchronous
	Speed: 1600 MT/s
	Manufacturer: Micron
	Serial Number: 10CD0955
	Asset Tag: 9876543210
	Part Number: 16KTF1G64AZ-1G6P1
	Rank: 2
	Configured Memory Speed: 1600 MT/s
	Minimum Voltage: 1.35 V
	Maximum Voltage: 1.5 V
	Configured Voltage: 1.5 V

Handle 0x0014, DMI type 15, 73 bytes
System Event Log
	Area Length: 4096 bytes
	Header Start Offset: 0x0000
	Header Length: 16 bytes
	Data Start Offset: 0x0010
	Access Method: Memory-mapped physical 32-bit address
	Access Address: 0xFFE6D000
	Status: Valid, Not Full
	Change Token: 0x00000001
	Header Format: Type 1
	Supported Log Type Descriptors: 25
	Descriptor 1: Single-bit ECC memory error
	Data Format 1: None
	Descriptor 2: Multi-bit ECC memory error
	Data Format 2: None
	Descriptor 3: Parity memory error
	Data Format 3: None
	Descriptor 4: Bus timeout
	Data Format 4: None
	Descriptor 5: I/O channel block
	Data Format 5: None
	Descriptor 6: Software NMI
	Data Format 6: None
	Descriptor 7: POST memory resize
	Data Format 7: None
	Descriptor 8: POST error
	Data Format 8: POST results bitmap
	Descriptor 9: PCI parity error
	Data Format 9: None
	Descriptor 10: PCI system error
	Data Format 10: None
	Descriptor 11: CPU failure
	Data Format 11: None
	Descriptor 12: EISA failsafe timer timeout
	Data Format 12: None
	Descriptor 13: Correctable memory log disabled
	Data Format 13: None
	Descriptor 14: Logging disabled
	Data Format 14: None
	Descriptor 15: System limit exceeded
	Data Format 15: None
	Descriptor 16: Asynchronous hardware timer expired
	Data Format 16: None
	Descriptor 17: System configuration information
	Data Format 17: None
	Descriptor 18: Hard disk information
	Data Format 18: None
	Descriptor 19: System reconfigured
	Data Format 19: None
	Descriptor 20: Uncorrectable CPU-complex error
	Data Format 20: None
	Descriptor 21: Log area reset/cleared
	Data Format 21: None
	Descriptor 22: System boot
	Data Format 22: None
	Descriptor 23: End of log
	Data Format 23: None
	Descriptor 24: OEM-specific
	Data Format 24: OEM-specific
	Descriptor 25: OEM-specific
	Data Format 25: OEM-specific

Handle 0x0015, DMI type 20, 35 bytes
Memory Device Mapped Address
	Starting Address: 0x00000000000
	Ending Address: 0x001FFFFFFFF
	Range Size: 8 GB
	Physical Device Handle: 0x0013
	Memory Array Mapped Address Handle: 0x0018
	Partition Row Position: Unknown
	Interleave Position: 1
	Interleaved Data Depth: 1

Handle 0x0016, DMI type 17, 40 bytes
Memory Device
	Array Handle: 0x0012
	Error Information Handle: Not Provided
	Total Width: 64 bits
	Data Width: 64 bits
	Size: 8 GB
	Form Factor: DIMM
	Set: None
	Locator: ChannelB-DIMM0
	Bank Locator: BANK 2
	Type: DDR3
	Type Detail: Synchronous
	Speed: 1600 MT/s
	Manufacturer: Micron
	Serial Number: 10CD0958
	Asset Tag: 9876543210
	Part Number: 16KTF1G64AZ-1G6P1
	Rank: 2
	Configured Memory Speed: 1600 MT/s
	Minimum Voltage: 1.35 V
	Maximum Voltage: 1.5 V
	Configured Voltage: 1.5 V

Handle 0x0017, DMI type 20, 35 bytes
Memory Device Mapped Address
	Starting Address: 0x00200000000
	Ending Address: 0x003FFFFFFFF
	Range Size: 8 GB
	Physical Device Handle: 0x0016
	Memory Array Mapped Address Handle: 0x0018
	Partition Row Position: Unknown
	Interleave Position: 2
	Interleaved Data Depth: 1

Handle 0x0018, DMI type 19, 31 bytes
Memory Array Mapped Address
	Starting Address: 0x00000000000
	Ending Address: 0x003FFFFFFFF
	Range Size: 16 GB
	Physical Array Handle: 0x0012
	Partition Width: 2

Handle 0x001C, DMI type 140, 19 bytes
OEM-specific Type
	Header and Data:
		8C 13 1C 00 4C 45 4E 4F 56 4F 0B 05 01 0F 00 00
		00 53 55

Handle 0x001D, DMI type 140, 23 bytes
OEM-specific Type
	Header and Data:
		8C 17 1D 00 4C 45 4E 4F 56 4F 0B 06 01 00 00 00
		00 00 00 00 00 00 00

Handle 0x001E, DMI type 131, 22 bytes
ThinkVantage Technologies
	Version: 1
	Diagnostics: Available

Handle 0x001F, DMI type 136, 6 bytes
OEM-specific Type
	Header and Data:
		88 06 1F 00 5A 5A

Handle 0x0020, DMI type 140, 85 bytes
OEM-specific Type
	Header and Data:
		8C 55 20 00 4C 45 4E 4F 56 4F 0B 00 01 3B 94 F7
		3D 84 37 39 80 FF 27 CB 4E 68 BC C1 DA 01 00 00
		00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
		00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
		00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
		00 00 00 00 00

Handle 0x0021, DMI type 140, 47 bytes
OEM-specific Type
	Header and Data:
		8C 2F 21 00 4C 45 4E 4F 56 4F 0B 01 01 09 00 3C
		D9 4D 88 4E E7 CA 0C 23 C7 DF 63 AE 6C 1A F5 00
		00 00 00 10 00 10 00 10 01 D0 00 20 01 00 01

Handle 0x0022, DMI type 140, 63 bytes
OEM-specific Type
	Header and Data:
		8C 3F 22 00 4C 45 4E 4F 56 4F 0B 02 01 00 00 00
		00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
		00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
		00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Handle 0x0023, DMI type 140, 17 bytes
OEM-specific Type
	Header and Data:
		8C 11 23 00 4C 45 4E 4F 56 4F 0B 03 01 00 00 00
		00

Handle 0x0024, DMI type 140, 19 bytes
OEM-specific Type
	Header and Data:
		8C 13 24 00 4C 45 4E 4F 56 4F 0B 04 01 B2 00 4D
		53 20 00

Handle 0x0025, DMI type 131, 64 bytes
OEM-specific Type
	Header and Data:
		83 40 25 00 35 00 00 00 00 00 00 00 00 00 00 00
		F8 00 5C 8C 00 00 00 00 01 20 00 00 00 00 09 00
		B6 05 15 00 00 00 00 00 C8 00 FF FF 00 00 00 00
		00 00 00 00 66 00 00 00 76 50 72 6F 00 00 00 00

Handle 0x0026, DMI type 13, 22 bytes
BIOS Language Information
	Language Description Format: Long
	Installable Languages: 3
		en|US|iso8859-1
		fr|FR|iso8859-1
		zh|CN|unicode
	Currently Installed Language: en|US|iso8859-1

Handle 0x0029, DMI type 127, 4 bytes
End Of Table


- -- System Information:
Debian Release: 13.6
  APT prefers stable-updates
  APT policy: (500, 'stable-updates'), (500, 'stable-security'), (500, 'stable')
Architecture: amd64 (x86_64)
Foreign Architectures: i386

Kernel: Linux 6.12.95+deb13-amd64 (SMP w/4 CPU threads; PREEMPT)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8), LANGUAGE not set
Shell: /bin/sh linked to /usr/bin/dash
Init: systemd (via /run/systemd/system)
LSM: AppArmor: enabled

Versions of packages shim-signed depends on:
ii  debconf [debconf-2.0]      1.5.91
ii  grub-efi-amd64-bin         2.12-9+deb13u2
ii  grub2-common               2.12-9+deb13u2
ii  mokutil                    0.7.2-1
ii  shim-helpers-amd64-signed  1+16.1+2~deb13u1
ii  shim-signed-common         1.51~1+deb13u1+16.1-2~deb13u1

shim-signed recommends no packages.

shim-signed suggests no packages.

- -- debconf information:
  shim-signed/revoked-sig:
  shim-signed/no-valid-sigs:
-----BEGIN PGP SIGNATURE-----

iGsEARECACsWIQSC1k9rDmfNQfaJu6b7LFEw1VqIGQUCalzZcw0cbjBuYkBuMG5i
LnVzAAoJEPssUTDVWogZs7UAn1Zv2ifNm92nAN4lNbaRUQJmiGd9AJ49i8llIw1Q
vp+7MJ5dmnSEZ5dQQg==
=UmFN
-----END PGP SIGNATURE-----

#1142417#10
Date:
2026-07-19 16:53:35 UTC
From:
To:
Hi Nate,

When you say "fails to boot", what exactly do you mean please? How far
does it get? Do you get any errors printed?

Checking too: your ThinkCentre M73 claims to have firmware from
2020. If I'm reading correctly, the page at

https://pcsupport.lenovo.com/us/en/products/desktops-and-all-in-ones/thinkcentre-m-series-desktops/thinkcentre-m73/10b6/downloads/driver-list/component?name=BIOS%2FUEFI&id=5AC6A815-321D-440E-8833-B07A93E0428C

suggests there is a 2022 update. I'd be tempted to try updating to
that to see if it helps.
-- 
Steve McIntyre, Cambridge, UK.                                steve@einval.com
  Armed with "Valor": "Centurion" represents quality of Discipline,
  Honor, Integrity and Loyalty. Now you don't have to be a Caesar to
  concord the digital world while feeling safe and proud.

#1142417#15
Date:
2026-07-19 16:52:41 UTC
From:
To:
Follow up info with commands listed in #1138983.

# mokutil --db --short
580a6f4cc4 Microsoft Windows Production PCA 2011
46def63b5c Microsoft Corporation UEFI CA 2011
d0b089ce2f Trust - Lenovo Certificate
9ae51eaa22 Trust - Lenovo Certificate
cb02597148 Lenovo UEFI CA 2014
b5eeb4a670 Microsoft UEFI CA 2023
3fb39e2b8b Microsoft Option ROM UEFI CA 2023


# mokutil --kek --short
31590bfd89 Microsoft Corporation KEK CA 2011


As suggested by Steve McIntyre, I will try the single-signed
shim-binaries.

- Nate

#1142417#20
Date:
2026-07-19 17:40:53 UTC
From:
To:
* On 2026 19 Jul 11:55 -0500, Steve McIntyre wrote:

Thanks for the prompt reply, Steve.

Yes.  The BIOS prints a white box with red border and lettering titled
"Secure Boot Violation".  The text is "Invalid signature detected.
Check Secure Boot Policy in Setup".  Then a "button" of "Ok" which just
repeats the cycle.  I have to use F12 to get to the boot menu and select
BIOS setup to disable secure boot at that point.

Here is my followup on testing the single-signed shims from the source
package.  Both of the single-signed shims from 2011 and 2023 boot
properly.  I then checked the journal to confirm secure boot is enabled.
Another test with the dual-signed shim resulted in the secure boot
failure.

I will check that out.  Thanks for looking that up.

- Nate

#1142417#25
Date:
2026-07-19 17:52:22 UTC
From:
To:
* On 2026 19 Jul 11:55 -0500, Steve McIntyre wrote:

As I look through the list, the 2022 update only references the M73 Tiny
while the 2020 update references the M73 tower (mine) and M73 small form
factor models.  Further, while the READMEs for the Tiny doesn't give any
model numbers, the older READMEs do explicitly state the model 10B0 in
the lists, which mine is.

I think I'm at the latest BIOS version available for this machine.

- Nate

#1142417#30
Date:
2026-07-19 17:54:01 UTC
From:
To:
ACK, thanks for the extra info - it's very helpful.

Could you also please add your machine details to the list at

https://wiki.debian.org/SecureBoot/BuggyFirmware

when you've done testing?

#1142417#35
Date:
2026-07-20 00:51:28 UTC
From:
To:
* On 2026 19 Jul 12:55 -0500, Steve McIntyre wrote:

I have updated that page.  I think I owe you an apology as while getting
the info for that update I discovered the BIOS version is dated 07 Jan
2020 and there have been two more updates since including the 06 Dec
2020 update on the Lenovo Web site.

I will get that update installed in the coming days and test and then
report back.

- Nate

#1142417#40
Date:
2026-07-20 15:55:37 UTC
From:
To:
I finally updated the firmware to the latest firmware, FCKT99AUS of
11/18/2020.  The dual-signed shim fails on it as well and I went back to
the 2023 single-signed shim and secure boot is working again.  I have
updated the Wiki for this version.

I did the fwupdate steps as the new keys were no longer installed.  As
before the primary keys did update but the KEK key did not.

I suspect this firmware will never support the dual-signed shim.  Are
there any plans to make a single-signed shim package available?  While I
can copy the single-signed shim over each time shim-signed is updated or
GRUB reinstalled, that might get a bit annoying a few years down the
road when I forget all of this!

That is the TL;DR

Lenovo, in its "wisdom" offers at least three different methods of
firmware updates.  I chose the ISO method and the instructions state to
write it to a CD and boot.  Mounting the ISO and looking at it revealed
that there were no DOS files in its root directory.  However, there is a
.img file that is a complete bootable DOS image with the firmware update
utility, but the instructions state nothing about it.  In short, I
wasted a CD-R.

I found instructions to copy the .img file out of the ISO file and wrote
it to USB media.  After a few attempts I saw that I was trying UEFI only
boot.  Once I enabled CSM and Legacy Boot the firmware update was
successful.

Of course, now I could no longer boot into Debian (the only OS
installed).  That led to writing the latest netinst image to the USB
stick and managing to boot it in UEFI mode.  After choosing Rescue Mode,
running efibootmgr in the chroot gave the error message "EFI variables
are not supported on this system"

A bit of searching later I discovered I had to mount the efivarfs using:

mount -t efivarfs efivarfs /sys/firmware/efi/efivars

Then efibootmgr listed the UEFI boot devices.

A bit more searching revealed that I needed to reinstall GRUB as:

grub-install /dev/sda --target=x86_64-efi --efi-directory=/boot/efi

Finally debian was listed in the boot order and I was able to
successfully boot into the installed system and test Secure Boot.

Hopefully, this might help someone running into a similar situation.

- Nate