On Tue, 2023-05-30 at 22:00 -0400, Chris Murphy wrote: > > On Fri, May 26, 2023, at 10:20 AM, Steve Grubb wrote: > > > sbattach --detach signature /boot/efi/EFI/BOOT/BOOTX64.EFI > > openssl pkcs7 -inform DER -in signature -text -print_certs > shim-certs.txt > > > > Issuer: C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, > > CN=Microsoft Corporation UEFI CA 2011 > > Validity > > Not Before: Sep 9 19:40:20 2021 GMT > > Not After : Sep 1 19:40:20 2022 GMT > > > What version of shim do you have installed? What edition/spin are you using? > > I have shim-x64-15.6-2.x86_64 and it's reporting > > Not Before: Jun 27 21:22:45 2011 GMT > Not After : Jun 27 21:32:45 2026 GMT > > A possible explanation is rpm-ostree derivatives may show a current version > grub and shim, but those are not copied to the EFI System partition. That's > the job of bootupd but I'm not sure if that's fully implemented yet in Fedora.
Yeah, that's likely it. There's a lot of discussion of this kinda thing at: https://github.com/fedora-silverblue/issue-tracker/issues/120 https://github.com/fedora-silverblue/issue-tracker/issues/355 and various other places linked from there... -- Adam Williamson (he/him/his) Fedora QA Fedora Chat: @adamwill:fedora.im | Mastodon: @ad...@fosstodon.org https://www.happyassassin.net _______________________________________________ devel mailing list -- devel@lists.fedoraproject.org To unsubscribe send an email to devel-le...@lists.fedoraproject.org Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/devel@lists.fedoraproject.org Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue