Package: shim / 0.9+1474479173.6c180c6-1
Patch seriesview the series file
|second stage path | (download)||
2 1 + 1 - 0 !
chainload grubx64.efi, not grub.efi We qualify the second stage bootloader image with the architecture name, so we're forwards-compatible with any future 32-bit implementations. (Non-SB grub doesn't conflict, since the image will be named bootia32.efi anyway, not grub.efi.)
|sbsigntool not pesign | (download)||
4 2 + 2 - 0 !
sign mokmanager with sbsigntool instead of pesign Ubuntu infrastructure uses sbsigntool for all other EFI signing, so we use the same thing for signing MokManager with our ephemeral key. This also avoids an additional build dependency on libnss3-tools.