ubuntu@ubuntu:~$ sudo file /boot/vmlinuz-*
/boot/vmlinuz-4.15.0-202-generic: gzip compressed data, max compression, from Unix
/boot/vmlinuz-5.4.0-137-generic: gzip compressed data, was "vmlinuz-5.4.0-137-generic.efi.signed", last modified: Thu Jan 12 19:14:50 2023, max compression, from Unix
/boot/vmlinuz-5.4.0-139-generic: gzip compressed data, was "vmlinuz-5.4.0-139-generic.efi.signed", last modified: Fri Jan 27 12:20:31 2023, max compression, from Unix
ubuntu@ubuntu:~$ sudo /usr/lib/shim/is-not-revoked /boot/vmlinuz-*
No signature table present
E: /boot/vmlinuz-4.15.0-202-generic: Could not find signing subject, sbverify output follows:
No signature table present
E: /boot/vmlinuz-5.4.0-137-generic: revoked key CN=Canonical Ltd. Secure Boot Signing (2017) used
This was implicitly verified when I verified bug 2004208: /bugs.launchpad .net/ubuntu/ +source/ shim-signed/ +bug/2004208/ comments/ 7
https:/
While I wasn't able to fully complete bionic verification there, I explicitly ran the test in the SRU template on bionic/arm64 to validate this one:
ubuntu@ubuntu:~$ sudo file /boot/vmlinuz-* 4.15.0- 202-generic: gzip compressed data, max compression, from Unix 5.4.0-137- generic: gzip compressed data, was "vmlinuz- 5.4.0-137- generic. efi.signed" , last modified: Thu Jan 12 19:14:50 2023, max compression, from Unix 5.4.0-139- generic: gzip compressed data, was "vmlinuz- 5.4.0-139- generic. efi.signed" , last modified: Fri Jan 27 12:20:31 2023, max compression, from Unix shim/is- not-revoked /boot/vmlinuz-* 4.15.0- 202-generic: Could not find signing subject, sbverify output follows: 5.4.0-137- generic: revoked key CN=Canonical Ltd. Secure Boot Signing (2017) used
/boot/vmlinuz-
/boot/vmlinuz-
/boot/vmlinuz-
ubuntu@ubuntu:~$ sudo /usr/lib/
No signature table present
E: /boot/vmlinuz-
No signature table present
E: /boot/vmlinuz-