Hi Nate,

On Sun, Jul 19, 2026 at 09:04:35AM -0500, Nate Bargmann wrote:
>Package: shim-signed
>Version: 1.51~1+deb13u1+16.1-2~deb13u1
>Severity: normal
>
>-----BEGIN PGP SIGNED MESSAGE-----
>Hash: SHA1
>
>Dear Maintainer,
>
>As requested, I am filing this bug as even after following the Wiki
>instructions, my Lenovo M73 fails to boot in secure boot mode with the
>current version of shim-signed in Stable.

:-( I'm sorry to hear that.

When you say "fails to boot", what exactly do you mean please? How far
does it get? Do you get any errors printed?

Checking too: your ThinkCentre M73 claims to have firmware from
2020. If I'm reading correctly, the page at

https://pcsupport.lenovo.com/us/en/products/desktops-and-all-in-ones/thinkcentre-m-series-desktops/thinkcentre-m73/10b6/downloads/driver-list/component?name=BIOS%2FUEFI&id=5AC6A815-321D-440E-8833-B07A93E0428C

suggests there is a 2022 update. I'd be tempted to try updating to
that to see if it helps.

>Apparently the main keys updated correctly:
>
># mokutil --db | grep "Subject:.*Microsoft"
>        Subject: C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, 
> CN=Microsoft Windows Production PCA 2011
>        Subject: C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, 
> CN=Microsoft Corporation UEFI CA 2011
>        Subject: C=US, O=Microsoft Corporation, CN=Microsoft UEFI CA 2023
>        Subject: C=US, O=Microsoft Corporation, CN=Microsoft Option ROM UEFI 
> CA 2023
>
>However, the KEK key did not:
>
>#  mokutil --kek | grep Subject:.*Microsoft
>        Subject: C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, 
> CN=Microsoft Corporation KEK CA 2011
>
>My attempt to update it showed no update available:
>
># fwupdtool update
>Loading…                 [*******************                    ]17:40:41.296 
>FuEngine             failed to add device 
>/sys/devices/pci0000:00/0000:00:1f.2/ata2/host1/target1:0:0/1:0:0:0/block/sr0: 
>failed to subclass open: failed to open /dev/sr0: No medium found
>17:40:41.432 FuEngine             failed to add device 
>/sys/devices/pci0000:00/0000:00:1f.2/ata2/host1/target1:0:0/1:0:0:0/block/sr0: 
>failed to subclass open: failed to open /dev/sr0: No medium found
>Loading…                 [************************************** ]
>Devices with the latest available firmware version:
> • UEFI CA
> • UEFI dbx
>Devices with no available firmware updates:
> • Option ROM UEFI CA
> • Trust - Lenovo Certificate
> • UEFI CA
> • Windows Production PCA
> • CT2000P310SSD8
> • KEK CA
> • System Firmware
> • WDS500G2B0A-00SM50
>
>(Unfortunately, I did not save the original 'fwupdtool update' output
>when the UEFI CA keys were updated)
>
>So far I've not downgraded shim-signed to version 1.47 to enable secure
>boot again but so far have secure boot disabled in the BIOS setup.
>
>M73 system info:
>
># dmidecode
># dmidecode 3.6
>Getting SMBIOS data from sysfs.
>SMBIOS 2.8 present.
>37 structures occupying 1720 bytes.
>Table at 0x9DED2018.
>
>Handle 0x0000, DMI type 0, 24 bytes
>BIOS Information
>       Vendor: LENOVO
>       Version: FCKT97AUS
>       Release Date: 01/07/2020
>       Address: 0xF0000
>       Runtime Size: 64 kB
>       ROM Size: 4 MB
>       Characteristics:
>               PCI is supported
>               BIOS is upgradeable
>               BIOS shadowing is allowed
>               Boot from CD is supported
>               Selectable boot is supported
>               BIOS ROM is socketed
>               EDD is supported
>               5.25"/1.2 MB floppy services are supported (int 13h)
>               3.5"/720 kB floppy services are supported (int 13h)
>               3.5"/2.88 MB floppy services are supported (int 13h)
>               Print screen service is supported (int 5h)
>               8042 keyboard services are supported (int 9h)
>               Serial services are supported (int 14h)
>               Printer services are supported (int 17h)
>               ACPI is supported
>               USB legacy is supported
>               BIOS boot specification is supported
>               Targeted content distribution is supported
>               UEFI is supported
>       BIOS Revision: 1.151
>
>Handle 0x0001, DMI type 1, 27 bytes
>System Information
>       Manufacturer: LENOVO
>       Product Name: 10B00005US
>       Version: ThinkCentre M73
>       Serial Number: MJ00D7ZZ
>       UUID: 66e5795c-9a63-11e3-89c1-3d4e9daf1a00
>       Wake-up Type: Power Switch
>       SKU Number: LENOVO_MT_10B0
>       Family:
>
>Handle 0x0002, DMI type 2, 15 bytes
>Base Board Information
>       Manufacturer: LENOVO
>       Product Name: 3098
>       Version: 0B98401 PRO
>       Serial Number: INVALID
>       Asset Tag:
>       Features:
>               Board is a hosting board
>               Board is replaceable
>       Location In Chassis:
>       Chassis Handle: 0x0003
>       Type: Motherboard
>       Contained Object Handles: 0
>
>Handle 0x0003, DMI type 3, 25 bytes
>Chassis Information
>       Manufacturer: LENOVO
>       Type: Desktop
>       Lock: Not Present
>       Version:
>       Serial Number: MJ00D7ZZ
>       Asset Tag:
>       Boot-up State: Safe
>       Power Supply State: Safe
>       Thermal State: Safe
>       Security Status: None
>       OEM Information: 0x00000000
>       Height: Unspecified
>       Number Of Power Cords: 1
>       Contained Elements: 1
>               <OUT OF SPEC> (0)
>       SKU Number:
>
>Handle 0x0004, DMI type 9, 17 bytes
>System Slot Information
>       Designation: J6B2
>       Type: PCI Express
>       Data Bus Width: 16x or x16
>       Current Usage: In Use
>       Length: Long
>       ID: 0
>       Characteristics:
>               3.3 V is provided
>               Opening is shared
>               PME signal is supported
>       Bus Address: 0000:00:01.0
>
>Handle 0x0005, DMI type 9, 17 bytes
>System Slot Information
>       Designation: J6B1
>       Type: PCI Express
>       Data Bus Width: 1x or x1
>       Current Usage: In Use
>       Length: Short
>       ID: 1
>       Characteristics:
>               3.3 V is provided
>               Opening is shared
>               PME signal is supported
>       Bus Address: 0000:00:1c.3
>
>Handle 0x0006, DMI type 9, 17 bytes
>System Slot Information
>       Designation: J6D1
>       Type: PCI Express
>       Data Bus Width: 1x or x1
>       Current Usage: In Use
>       Length: Short
>       ID: 2
>       Characteristics:
>               3.3 V is provided
>               Opening is shared
>               PME signal is supported
>       Bus Address: 0000:00:1c.4
>
>Handle 0x0007, DMI type 9, 17 bytes
>System Slot Information
>       Designation: J7B1
>       Type: PCI Express
>       Data Bus Width: 1x or x1
>       Current Usage: In Use
>       Length: Short
>       ID: 3
>       Characteristics:
>               3.3 V is provided
>               Opening is shared
>               PME signal is supported
>       Bus Address: 0000:00:1c.5
>
>Handle 0x0008, DMI type 9, 17 bytes
>System Slot Information
>       Designation: J8B4
>       Type: PCI Express
>       Data Bus Width: 1x or x1
>       Current Usage: In Use
>       Length: Short
>       ID: 4
>       Characteristics:
>               3.3 V is provided
>               Opening is shared
>               PME signal is supported
>       Bus Address: 0000:00:1c.6
>
>Handle 0x0009, DMI type 10, 12 bytes
>On Board Device 1 Information
>       Type: Video
>       Status: Enabled
>       Description:    Onboard Video
>On Board Device 2 Information
>       Type: Ethernet
>       Status: Enabled
>       Description:    Onboard Lan
>On Board Device 3 Information
>       Type: Sound
>       Status: Enabled
>       Description:    Onboard Audio
>On Board Device 4 Information
>       Type: SATA Controller
>       Status: Enabled
>       Description:    Onboard SATA
>
>Handle 0x000A, DMI type 11, 5 bytes
>OEM Strings
>       String 1: LENOVO ThinkCentre Embedded Controller -[N/A]-
>       String 2: LENOVO ThinkCentre BIOS Boot Block Revision 1.97
>
>Handle 0x000B, DMI type 12, 5 bytes
>System Configuration Options
>       Option 1: scre++
>
>Handle 0x000C, DMI type 24, 5 bytes
>Hardware Security
>       Power-On Password Status: Disabled
>       Keyboard Password Status: Enabled
>       Administrator Password Status: Disabled
>       Front Panel Reset Status: Not Implemented
>
>Handle 0x000D, DMI type 32, 20 bytes
>System Boot Information
>       Status: No errors detected
>
>Handle 0x000E, DMI type 4, 42 bytes
>Processor Information
>       Socket Designation: SOCKET 0
>       Type: Central Processor
>       Family: Core i5
>       Manufacturer: Intel
>       ID: C3 06 03 00 FF FB EB BF
>       Signature: Type 0, Family 6, Model 60, Stepping 3
>       Flags:
>               FPU (Floating-point unit on-chip)
>               VME (Virtual mode extension)
>               DE (Debugging extension)
>               PSE (Page size extension)
>               TSC (Time stamp counter)
>               MSR (Model specific registers)
>               PAE (Physical address extension)
>               MCE (Machine check exception)
>               CX8 (CMPXCHG8 instruction supported)
>               APIC (On-chip APIC hardware supported)
>               SEP (Fast system call)
>               MTRR (Memory type range registers)
>               PGE (Page global enable)
>               MCA (Machine check architecture)
>               CMOV (Conditional move instruction supported)
>               PAT (Page attribute table)
>               PSE-36 (36-bit page size extension)
>               CLFSH (CLFLUSH instruction supported)
>               DS (Debug store)
>               ACPI (ACPI supported)
>               MMX (MMX technology supported)
>               FXSR (FXSAVE and FXSTOR instructions supported)
>               SSE (Streaming SIMD extensions)
>               SSE2 (Streaming SIMD extensions 2)
>               SS (Self-snoop)
>               HTT (Multi-threading)
>               TM (Thermal monitor supported)
>               PBE (Pending break enabled)
>       Version: Intel(R) Core(TM) i5-4570 CPU @ 3.20GHz
>       Voltage: 1.2 V
>       External Clock: 100 MHz
>       Max Speed: 3200 MHz
>       Current Speed: 3200 MHz
>       Status: Populated, Enabled
>       Upgrade: Socket BGA1155
>       L1 Cache Handle: 0x0010
>       L2 Cache Handle: 0x000F
>       L3 Cache Handle: 0x0011
>       Serial Number: Not Specified
>       Asset Tag: Fill By OEM
>       Part Number: Fill By OEM
>       Core Count: 4
>       Core Enabled: 4
>       Thread Count: 4
>       Characteristics:
>               64-bit capable
>
>Handle 0x000F, DMI type 7, 19 bytes
>Cache Information
>       Socket Designation: CPU Internal L2
>       Configuration: Enabled, Not Socketed, Level 2
>       Operational Mode: Write Back
>       Location: Internal
>       Installed Size: 1 MB
>       Maximum Size: 1 MB
>       Supported SRAM Types:
>               Unknown
>       Installed SRAM Type: Unknown
>       Speed: Unknown
>       Error Correction Type: Single-bit ECC
>       System Type: Unified
>       Associativity: 8-way Set-associative
>
>Handle 0x0010, DMI type 7, 19 bytes
>Cache Information
>       Socket Designation: CPU Internal L1
>       Configuration: Enabled, Not Socketed, Level 1
>       Operational Mode: Write Back
>       Location: Internal
>       Installed Size: 256 kB
>       Maximum Size: 256 kB
>       Supported SRAM Types:
>               Unknown
>       Installed SRAM Type: Unknown
>       Speed: Unknown
>       Error Correction Type: Single-bit ECC
>       System Type: Other
>       Associativity: 8-way Set-associative
>
>Handle 0x0011, DMI type 7, 19 bytes
>Cache Information
>       Socket Designation: CPU Internal L3
>       Configuration: Enabled, Not Socketed, Level 3
>       Operational Mode: Write Back
>       Location: Internal
>       Installed Size: 6 MB
>       Maximum Size: 6 MB
>       Supported SRAM Types:
>               Unknown
>       Installed SRAM Type: Unknown
>       Speed: Unknown
>       Error Correction Type: Single-bit ECC
>       System Type: Unified
>       Associativity: 12-way Set-associative
>
>Handle 0x0012, DMI type 16, 23 bytes
>Physical Memory Array
>       Location: System Board Or Motherboard
>       Use: System Memory
>       Error Correction Type: None
>       Maximum Capacity: 16 GB
>       Error Information Handle: Not Provided
>       Number Of Devices: 2
>
>Handle 0x0013, DMI type 17, 40 bytes
>Memory Device
>       Array Handle: 0x0012
>       Error Information Handle: Not Provided
>       Total Width: 64 bits
>       Data Width: 64 bits
>       Size: 8 GB
>       Form Factor: DIMM
>       Set: None
>       Locator: ChannelA-DIMM0
>       Bank Locator: BANK 0
>       Type: DDR3
>       Type Detail: Synchronous
>       Speed: 1600 MT/s
>       Manufacturer: Micron
>       Serial Number: 10CD0955
>       Asset Tag: 9876543210
>       Part Number: 16KTF1G64AZ-1G6P1
>       Rank: 2
>       Configured Memory Speed: 1600 MT/s
>       Minimum Voltage: 1.35 V
>       Maximum Voltage: 1.5 V
>       Configured Voltage: 1.5 V
>
>Handle 0x0014, DMI type 15, 73 bytes
>System Event Log
>       Area Length: 4096 bytes
>       Header Start Offset: 0x0000
>       Header Length: 16 bytes
>       Data Start Offset: 0x0010
>       Access Method: Memory-mapped physical 32-bit address
>       Access Address: 0xFFE6D000
>       Status: Valid, Not Full
>       Change Token: 0x00000001
>       Header Format: Type 1
>       Supported Log Type Descriptors: 25
>       Descriptor 1: Single-bit ECC memory error
>       Data Format 1: None
>       Descriptor 2: Multi-bit ECC memory error
>       Data Format 2: None
>       Descriptor 3: Parity memory error
>       Data Format 3: None
>       Descriptor 4: Bus timeout
>       Data Format 4: None
>       Descriptor 5: I/O channel block
>       Data Format 5: None
>       Descriptor 6: Software NMI
>       Data Format 6: None
>       Descriptor 7: POST memory resize
>       Data Format 7: None
>       Descriptor 8: POST error
>       Data Format 8: POST results bitmap
>       Descriptor 9: PCI parity error
>       Data Format 9: None
>       Descriptor 10: PCI system error
>       Data Format 10: None
>       Descriptor 11: CPU failure
>       Data Format 11: None
>       Descriptor 12: EISA failsafe timer timeout
>       Data Format 12: None
>       Descriptor 13: Correctable memory log disabled
>       Data Format 13: None
>       Descriptor 14: Logging disabled
>       Data Format 14: None
>       Descriptor 15: System limit exceeded
>       Data Format 15: None
>       Descriptor 16: Asynchronous hardware timer expired
>       Data Format 16: None
>       Descriptor 17: System configuration information
>       Data Format 17: None
>       Descriptor 18: Hard disk information
>       Data Format 18: None
>       Descriptor 19: System reconfigured
>       Data Format 19: None
>       Descriptor 20: Uncorrectable CPU-complex error
>       Data Format 20: None
>       Descriptor 21: Log area reset/cleared
>       Data Format 21: None
>       Descriptor 22: System boot
>       Data Format 22: None
>       Descriptor 23: End of log
>       Data Format 23: None
>       Descriptor 24: OEM-specific
>       Data Format 24: OEM-specific
>       Descriptor 25: OEM-specific
>       Data Format 25: OEM-specific
>
>Handle 0x0015, DMI type 20, 35 bytes
>Memory Device Mapped Address
>       Starting Address: 0x00000000000
>       Ending Address: 0x001FFFFFFFF
>       Range Size: 8 GB
>       Physical Device Handle: 0x0013
>       Memory Array Mapped Address Handle: 0x0018
>       Partition Row Position: Unknown
>       Interleave Position: 1
>       Interleaved Data Depth: 1
>
>Handle 0x0016, DMI type 17, 40 bytes
>Memory Device
>       Array Handle: 0x0012
>       Error Information Handle: Not Provided
>       Total Width: 64 bits
>       Data Width: 64 bits
>       Size: 8 GB
>       Form Factor: DIMM
>       Set: None
>       Locator: ChannelB-DIMM0
>       Bank Locator: BANK 2
>       Type: DDR3
>       Type Detail: Synchronous
>       Speed: 1600 MT/s
>       Manufacturer: Micron
>       Serial Number: 10CD0958
>       Asset Tag: 9876543210
>       Part Number: 16KTF1G64AZ-1G6P1
>       Rank: 2
>       Configured Memory Speed: 1600 MT/s
>       Minimum Voltage: 1.35 V
>       Maximum Voltage: 1.5 V
>       Configured Voltage: 1.5 V
>
>Handle 0x0017, DMI type 20, 35 bytes
>Memory Device Mapped Address
>       Starting Address: 0x00200000000
>       Ending Address: 0x003FFFFFFFF
>       Range Size: 8 GB
>       Physical Device Handle: 0x0016
>       Memory Array Mapped Address Handle: 0x0018
>       Partition Row Position: Unknown
>       Interleave Position: 2
>       Interleaved Data Depth: 1
>
>Handle 0x0018, DMI type 19, 31 bytes
>Memory Array Mapped Address
>       Starting Address: 0x00000000000
>       Ending Address: 0x003FFFFFFFF
>       Range Size: 16 GB
>       Physical Array Handle: 0x0012
>       Partition Width: 2
>
>Handle 0x001C, DMI type 140, 19 bytes
>OEM-specific Type
>       Header and Data:
>               8C 13 1C 00 4C 45 4E 4F 56 4F 0B 05 01 0F 00 00
>               00 53 55
>
>Handle 0x001D, DMI type 140, 23 bytes
>OEM-specific Type
>       Header and Data:
>               8C 17 1D 00 4C 45 4E 4F 56 4F 0B 06 01 00 00 00
>               00 00 00 00 00 00 00
>
>Handle 0x001E, DMI type 131, 22 bytes
>ThinkVantage Technologies
>       Version: 1
>       Diagnostics: Available
>
>Handle 0x001F, DMI type 136, 6 bytes
>OEM-specific Type
>       Header and Data:
>               88 06 1F 00 5A 5A
>
>Handle 0x0020, DMI type 140, 85 bytes
>OEM-specific Type
>       Header and Data:
>               8C 55 20 00 4C 45 4E 4F 56 4F 0B 00 01 3B 94 F7
>               3D 84 37 39 80 FF 27 CB 4E 68 BC C1 DA 01 00 00
>               00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
>               00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
>               00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
>               00 00 00 00 00
>
>Handle 0x0021, DMI type 140, 47 bytes
>OEM-specific Type
>       Header and Data:
>               8C 2F 21 00 4C 45 4E 4F 56 4F 0B 01 01 09 00 3C
>               D9 4D 88 4E E7 CA 0C 23 C7 DF 63 AE 6C 1A F5 00
>               00 00 00 10 00 10 00 10 01 D0 00 20 01 00 01
>
>Handle 0x0022, DMI type 140, 63 bytes
>OEM-specific Type
>       Header and Data:
>               8C 3F 22 00 4C 45 4E 4F 56 4F 0B 02 01 00 00 00
>               00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
>               00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
>               00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
>
>Handle 0x0023, DMI type 140, 17 bytes
>OEM-specific Type
>       Header and Data:
>               8C 11 23 00 4C 45 4E 4F 56 4F 0B 03 01 00 00 00
>               00
>
>Handle 0x0024, DMI type 140, 19 bytes
>OEM-specific Type
>       Header and Data:
>               8C 13 24 00 4C 45 4E 4F 56 4F 0B 04 01 B2 00 4D
>               53 20 00
>
>Handle 0x0025, DMI type 131, 64 bytes
>OEM-specific Type
>       Header and Data:
>               83 40 25 00 35 00 00 00 00 00 00 00 00 00 00 00
>               F8 00 5C 8C 00 00 00 00 01 20 00 00 00 00 09 00
>               B6 05 15 00 00 00 00 00 C8 00 FF FF 00 00 00 00
>               00 00 00 00 66 00 00 00 76 50 72 6F 00 00 00 00
>
>Handle 0x0026, DMI type 13, 22 bytes
>BIOS Language Information
>       Language Description Format: Long
>       Installable Languages: 3
>               en|US|iso8859-1
>               fr|FR|iso8859-1
>               zh|CN|unicode
>       Currently Installed Language: en|US|iso8859-1
>
>Handle 0x0029, DMI type 127, 4 bytes
>End Of Table
>
>
>- -- System Information:
>Debian Release: 13.6
>  APT prefers stable-updates
>  APT policy: (500, 'stable-updates'), (500, 'stable-security'), (500, 
> 'stable')
>Architecture: amd64 (x86_64)
>Foreign Architectures: i386
>
>Kernel: Linux 6.12.95+deb13-amd64 (SMP w/4 CPU threads; PREEMPT)
>Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8), LANGUAGE not 
>set
>Shell: /bin/sh linked to /usr/bin/dash
>Init: systemd (via /run/systemd/system)
>LSM: AppArmor: enabled
>
>Versions of packages shim-signed depends on:
>ii  debconf [debconf-2.0]      1.5.91
>ii  grub-efi-amd64-bin         2.12-9+deb13u2
>ii  grub2-common               2.12-9+deb13u2
>ii  mokutil                    0.7.2-1
>ii  shim-helpers-amd64-signed  1+16.1+2~deb13u1
>ii  shim-signed-common         1.51~1+deb13u1+16.1-2~deb13u1
>
>shim-signed recommends no packages.
>
>shim-signed suggests no packages.
>
>- -- debconf information:
>  shim-signed/revoked-sig:
>  shim-signed/no-valid-sigs:
>
>-----BEGIN PGP SIGNATURE-----
>
>iGsEARECACsWIQSC1k9rDmfNQfaJu6b7LFEw1VqIGQUCalzZcw0cbjBuYkBuMG5i
>LnVzAAoJEPssUTDVWogZs7UAn1Zv2ifNm92nAN4lNbaRUQJmiGd9AJ49i8llIw1Q
>vp+7MJ5dmnSEZ5dQQg==
>=UmFN
>-----END PGP SIGNATURE-----
-- 
Steve McIntyre, Cambridge, UK.                                [email protected]
  Armed with "Valor": "Centurion" represents quality of Discipline,
  Honor, Integrity and Loyalty. Now you don't have to be a Caesar to
  concord the digital world while feeling safe and proud.

Reply via email to