Your message dated Sun, 12 Jan 2025 15:28:16 +0000
with message-id <d3bda5b1067d7191130fbf199397ab4bbb4c6eb1.ca...@debian.org>
and subject line Re: systemd - EFI Secure Boot for systemd-boot
has caused the Debian Bug report #996202,
regarding systemd-boot: Sign systemd-boot with Debian Secure Boot CA
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact ow...@bugs.debian.org
immediately.)


-- 
996202: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=996202
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems
--- Begin Message ---
Package: systemd-boot
Severity: wishlist
X-Debbugs-Cc: gihun...@proton.me

Dear Maintainer,

Please, sign /usr/lib/systemd/boot/efi/systemd-bootx64.efi with Debian Secure 
Boot CA
(or maybe create systemd-bootx64.efi.signed) so that systemd-boot can be used 
with
UEFI Secure Boot and shim out of the box.

Debian provides systemd-boot but does not sign it with a Debian key.
To use systemd-boot with shim, one needs to enroll its hash with MokManager.
Although systemd-boot is not an official bootloader of Debian,
signing it would be handy to people using systemd-boot and Secure Boot with 
Debian.

Respectively,
Gihun Nam

-- System Information:
Debian Release: 11.6
  APT prefers stable-updates
  APT policy: (500, 'stable-updates'), (500, 'stable-security'), (500, 'stable')
Architecture: amd64 (x86_64)

Kernel: Linux 5.15.90.1-microsoft-standard-WSL2 (SMP w/8 CPU threads)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8), LANGUAGE not set
Shell: /bin/sh linked to /usr/bin/dash
Init: unable to detect

Versions of packages systemd-boot depends on:
ii  libc6              2.31-13+deb11u5
pn  libsystemd-shared  <none>
pn  systemd-boot-efi   <none>

Versions of packages systemd-boot recommends:
ii  efibootmgr  17-1

systemd-boot suggests no packages.

--- End Message ---
--- Begin Message ---
Thanks to Ansgar from FTP team and Philipp from DSA team, systemd-boot-
efi-amd64-signed and systemd-boot-efi-arm64-signed are now available in
unstable, so we can finally close this as completed. Woop woop!

https://ftp.debian.org/debian/pool/main/s/systemd-boot-efi-amd64-signed/
https://ftp.debian.org/debian/pool/main/s/systemd-boot-efi-arm64-signed/

$ sbverify --list systemd-bootx64.efi.signed 
signature 1
image signature issuers:
 - /CN=Debian Secure Boot CA
image signature certificates:
 - subject: /CN=Debian Secure Boot Signer 2024 - 20425036 - systemd-boot
   issuer:  /CN=Debian Secure Boot CA

Attachment: signature.asc
Description: This is a digitally signed message part


--- End Message ---

Reply via email to