On Tue, 2023-05-30 at 22:00 -0400, Chris Murphy wrote:
> 
> On Fri, May 26, 2023, at 10:20 AM, Steve Grubb wrote:
> 
> > sbattach --detach signature  /boot/efi/EFI/BOOT/BOOTX64.EFI
> > openssl pkcs7 -inform DER -in signature -text -print_certs > shim-certs.txt
> > 
> >         Issuer: C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, 
> > CN=Microsoft Corporation UEFI CA 2011
> >         Validity
> >             Not Before: Sep  9 19:40:20 2021 GMT
> >             Not After : Sep  1 19:40:20 2022 GMT
> 
> 
> What version of shim do you have installed? What edition/spin are you using? 
> 
> I have shim-x64-15.6-2.x86_64 and it's reporting
> 
>             Not Before: Jun 27 21:22:45 2011 GMT
>             Not After : Jun 27 21:32:45 2026 GMT
> 
> A possible explanation is rpm-ostree derivatives may show a current version 
> grub and shim, but those are not copied to the EFI System partition. That's 
> the job of bootupd but I'm not sure if that's fully implemented yet in Fedora.

Yeah, that's likely it. There's a lot of discussion of this kinda thing
at:
https://github.com/fedora-silverblue/issue-tracker/issues/120
https://github.com/fedora-silverblue/issue-tracker/issues/355

and various other places linked from there...
-- 
Adam Williamson (he/him/his)
Fedora QA
Fedora Chat: @adamwill:fedora.im | Mastodon: @ad...@fosstodon.org
https://www.happyassassin.net



_______________________________________________
devel mailing list -- devel@lists.fedoraproject.org
To unsubscribe send an email to devel-le...@lists.fedoraproject.org
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/devel@lists.fedoraproject.org
Do not reply to spam, report it: 
https://pagure.io/fedora-infrastructure/new_issue

Reply via email to