shim-signed updates break self signed UEFI systems

Bug #1600224 reported by Tim Gardner
8
This bug affects 1 person
Affects Status Importance Assigned to Milestone
shim-signed (Ubuntu)
Confirmed
Low
Mathieu Trudel-Lapierre

Bug Description

Updating shim-signed on a self signed UEFI platform without Microsoft keys is rendered unbootable. An example is a QEMU instance that is self signed.

Isn't there a way to notify the platform owner that they should resign their UEFI utilities before rebooting ?

Adam Conrad (adconrad)
Changed in shim-signed (Ubuntu):
assignee: nobody → Mathieu Trudel-Lapierre (cyphermox)
Revision history for this message
Steve Langasek (vorlon) wrote :

The shim-signed package is the package that delivers the Microsoft-signed shim to the user's system. I certainly agree that we can be more proactive about detecting the case where your system will be rendered unbootable. However, it seems to me that the obvious workaround for this bug is to not install the shim-signed package on a system which doesn't need it (or to remove this package when configuring your self-signed Secure Boot keys).

Changed in shim-signed (Ubuntu):
importance: Undecided → Low
Revision history for this message
xzqjack (xzqjack) wrote :

Hi, i'm a newer to Ubuntu.I want to tell you about my experience about some mistake of shim-signed package and my way to figure out it.

Yesterday, some mistake about shim-signed occurred.The updater of Ubuntu got stuck and turned black. I have to force closing updater.But when i reboot the computer, i couldn't enter the Ubuntu graphical interfaces. When i input password and press login , scree flashed and ask for passward again. However, the "tty1" (press Ctrl+Alt+F1) worked fine.

Then i remove shim-signed and reinstall it.The install process ask me to disable UEFI secure boot. I choose No on first time and yes on second time. But both didn't work.

Finally, i entered BIOS and turn the secure boot item into "other operation system " from "Windows UEFI". And it workd fine.

I completely have no idea about that. I wish my experience could provide something useful to help improve shim-signed.

Changed in shim-signed (Ubuntu):
status: New → Confirmed
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.