Package: systemd-boot-efi-amd64-signed Version: systemd-boot-efi-amd64-signed Severity: wishlist X-Debbugs-Cc: [email protected], [email protected] User: [email protected] Usertags: amd64
Dear Maintainer, The systemd-boot-efi-amd64-signed package provides a signed systemd-boot EFI binary, but it does not include the certificate used to sign it. I cannot find any official source that provides this certificate, which seems rather odd. I understand that this boot loader is intended to be run via the Microsoft- signed shim. However, if a user controls their Secure Boot platform, shim is unnecessary. It is simpler to use the systemd-boot binary directly. It is inconvenient to manually sign the binary after every update, especially since Debian already provides a signed version. Therefore, it seems reasonable to add the Debian Secure Boot Signer certificate to the UEFI DB. However, the certificate does not appear to be provided anywhere. It could be even better to provide a Debian KEK certificate and use it to allow automatic updates to the UEFI DB. But at the very least, please provide the DB certificate in a reasonable and officially documented location. -- System Information: Debian Release: forky/sid APT prefers stable-updates APT policy: (500, 'stable-updates'), (500, 'stable-security'), (500, 'unstable'), (500, 'testing'), (500, 'stable'), (1, 'experimental') Architecture: amd64 (x86_64) Foreign Architectures: i386 Kernel: Linux 7.2-amd64 (SMP w/16 CPU threads; PREEMPT) Kernel taint flags: TAINT_USER, TAINT_OOT_MODULE Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8), LANGUAGE not set Shell: /bin/sh linked to /usr/bin/dash Init: systemd (via /run/systemd/system) LSM: AppArmor: enabled

