-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 05 May 2024 11:33:57 +0100 Source: shim Binary: shim-helpers-i386-signed-template shim-unsigned Architecture: i386 Version: 15.8-1~deb11u1 Distribution: bullseye Urgency: medium Maintainer: i386 Build Daemon (x86-grnet-01) Changed-By: Steve McIntyre <93sam@debian.org> Description: shim-helpers-i386-signed-template - boot loader to chain-load signed boot loaders (signing template) shim-unsigned - boot loader to chain-load signed boot loaders under Secure Boot Closes: 1046268 1069054 Changes: shim (15.8-1~deb11u1) bullseye; urgency=medium . * New upstream release fixing more bugs * Remove all our previous patches, no longer needed: + Make-sbat_var.S-parse-right-with-buggy-gcc-binutils.patch (now upstream) + Enable-NX.patch (we don't want NX just yet until the whole boot stack is NX-capable) + block-grub-sbat3-debian.patch (not needed now upstream grub SBAT is 4) * Cherry-pick 2 new patches from upstream for grub revocations: + 0001-sbat-Add-grub.peimage-2-to-latest-CVE-2024-2312.patch + 0002-sbat-Also-bump-latest-for-grub-4-and-to-todays-date.patch * Log if the build is nx-compatible or not * Force shim to use the latest revocations by default to block some older grub / peimage issues. This is: "shim,4\ngrub,4\ngrub.peimage,2\n" * Install a copy of the Debian CA certificate into /usr/share/shim. Closes: #1069054 * Clean up better after build. Closes: #1046268 Checksums-Sha1: ecd2d026ae5435fe1e09a0a8f9d7bf1033448494 15404 shim-helpers-i386-signed-template_15.8-1~deb11u1_i386.deb 43e12b5c50e97cf0bd38bb23720c6bbdb9a4765a 400184 shim-unsigned_15.8-1~deb11u1_i386.deb fd302ef4b72aac8ec679edc865776c57bfbb19c8 6771 shim_15.8-1~deb11u1_i386-buildd.buildinfo Checksums-Sha256: 67b78b0d8cda319312e5dd5cd1ef4bb293f50cbb33f5f3e5ac71324ea66817bd 15404 shim-helpers-i386-signed-template_15.8-1~deb11u1_i386.deb de33b6d817836f4459fe88f74fb4949ecd16753d69c6ea72d8c581708e6aab5a 400184 shim-unsigned_15.8-1~deb11u1_i386.deb 43ba992b9777f63b5a2a6cf4a4ff81d2bbd40c0f03ad561610039148dcf1e7ef 6771 shim_15.8-1~deb11u1_i386-buildd.buildinfo Files: 4f2ff156f7e527908aaab75e99834e91 15404 admin optional shim-helpers-i386-signed-template_15.8-1~deb11u1_i386.deb 079bff385ce1c7ffe414dd485da0bebd 400184 admin optional shim-unsigned_15.8-1~deb11u1_i386.deb 4691206abebc70545c7df321c98ba568 6771 admin optional shim_15.8-1~deb11u1_i386-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEyTfXx8sBpQ0Lh3cUU9a0/LcaTpMFAmY7xk0ACgkQU9a0/Lca TpPDLg/9GSznf/JorSkFNEW+5ZjAJx1raoxHOckcFtP0SnNEHwHTzZbX8i8PRtxh aUpcn5QclHqxP81Fks1Tn/rKgSyVlnj5QGfVURtxX2Zw161jx6aC1En7XRrvm8jC +K00y8ftG7TA1uWGhCNdECfjCWzMJAUPxXM9B/5lW8AjqeslHvU7r9fvrVa7Gy65 YpSNYCPwUw2LAyiXqyuZ3VWxDWNXxF+7tcWnyG1whUwxOTwdU+NurxbisIbPXKBn KNkb6PgZFxJN6acH+ujXIAn3r261NSI6J/IoZEjupVBBNY4qf7/r7j2x5BXTPPgI rVVg35GyzCUhC5PTUpMW2bOzLBdG/pOMXa/bieUnHeUnjJcdjflOIgY5crSaXPfY uC0YaEper1TNeG/Bw/pySm3yi9on2i406pb20zUxD5Ss16LvaZ0aidNQ6r8MdS9d Evy47xDXme+M7Pj0JVTkLy7wBbGfNUDCwMGy+A4/53Q/+BwYPOXE27nJaPJ4rknL ngRw9OaoLGzBjPD/ysnVKx7rZzl0nTtkwKmKdDOiGMrxW3/mmG9o8fF5XwKqWFqS Sb0iAqJmO1QnMXxxB1wyD6DPMMFCoAeZPA5O21WBworb56ash83LTCc1OveIJOxJ wANzQ9tviR3J+lnjM68ormkTIC1yIfClUohXdSC2JH6U4hXzhss= =lsal -----END PGP SIGNATURE-----