-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sun, 17 May 2026 22:47:06 +0100 Source: shim-signed Architecture: source Version: 1.48 Distribution: unstable Urgency: medium Maintainer: Debian EFI Team <debian-efi@lists.debian.org> Changed-By: Steve McIntyre <93sam@debian.org> Closes: 1064102 1112197 Changes: shim-signed (1.48) unstable; urgency=medium . * Add support for verifying and then combining signatures from multiple signed shims. + Existing sbverify versions in Debian are buggy when verifying. + Switch to using a python script verify_combine_sigs to fill in the gaps. * In preinst, try to verify that the signed shim we're trying to install will actually boot on this system - let's not break systems on upgrade. * We now include a dual-signed shim including the 2023 CA. Closes: #1112197 * The shim included is now NX-capable. Closes: #1064102 Checksums-Sha1: 07c44b7c30573429a76a13043871207cb1ff2a17 1915 shim-signed_1.48.dsc b9f75ff283a59562435c4b1d2a07b205235067fa 823812 shim-signed_1.48.tar.xz bd7440dc08887c7626ddd0022fcc06b4a31925d1 6069 shim-signed_1.48_source.buildinfo Checksums-Sha256: 2a445a17665bae50c88e66d1ff414f90156c0eae8042186a64b1433d09f3c8ff 1915 shim-signed_1.48.dsc bf6a380e29c8291539db6902d2794fa841b6b546f4bf760b10c5fa13c42880f6 823812 shim-signed_1.48.tar.xz 029173ff3681b8a5bb8ba4f8f1990b5822e26c89a679f602c8892387148f2d43 6069 shim-signed_1.48_source.buildinfo Files: 61c6adafdf38a6d44165b0598c2dbba7 1915 utils optional shim-signed_1.48.dsc 8d9812cf852b3d682e774c5d2a1f7b67 823812 utils optional shim-signed_1.48.tar.xz 41824bba1284a785951bc02d43a915d8 6069 utils optional shim-signed_1.48_source.buildinfo -----BEGIN PGP SIGNATURE----- iQJFBAEBCgAvFiEEzrtSMB1hfpEDkP4WWHl5VzRCaE4FAmoLESERHDkzc2FtQGRl Ymlhbi5vcmcACgkQWHl5VzRCaE69pg/+KTItRsIGRV1ySoIz0nGW8K917IEQJu/O m470oT74QODltetkUf8m95hAIZWkaDHVZov791J8yUV3QsnI9cBZ4pTVOqRkwQXo uNB9NWOVcQMG91UH9MgscCelQ1tLPzoO4dzqY7/zO0QRxnGZ1QjVOum7xq0gHwvW wnaW2YNY0FMU2Ya1aqKlI2WC4BuNJPwboQvy/hxfN2hVx5LGH396+Vnux6nqPaFt zRMBfF3RCmQmTOdnXeBNvP3NOLozS/L63o8//3he6Ne6t9WomEZJhRlnWXG628iC 4/2j3ihWijknP8W6PgrlZb0Ku7bAqwzLqkWn5E1o6RYJLa/RGcAnmKKKDd6PXNVx aHISSkt/ktMWdjRYca5IHwllzT6p6/p43SCBeKtrFXUSySr/OAFBKIopNiIZMus0 muCicmJ4vUNXr1FbCn/Gu4W5kR8bxF3+uajPetKcgJGCz0wquzFN4JonZZ+fClW9 UmEgcJlnIb3baklvVqlW0iENBXVj+yWxxbeEULYn6TKLfoiOEdEIeIk24ryqSTkn VBbs8vztl6gkXgYCufl5vqLWMD25VNvzjv9DM/QTM8Kcn9+03HlOuihXc3RIzoMN L951iRs+MCLPzY9V3dQiwinNMRH71gw6v5FBNxvrQDXf13QU/+GGEgQlCMrMEH5Z 6E+DvgpJf2c= =Ija/ -----END PGP SIGNATURE-----