Hi Nate, On Sun, Jul 19, 2026 at 09:04:35AM -0500, Nate Bargmann wrote: >Package: shim-signed >Version: 1.51~1+deb13u1+16.1-2~deb13u1 >Severity: normal > >-----BEGIN PGP SIGNED MESSAGE----- >Hash: SHA1 > >Dear Maintainer, > >As requested, I am filing this bug as even after following the Wiki >instructions, my Lenovo M73 fails to boot in secure boot mode with the >current version of shim-signed in Stable.
:-( I'm sorry to hear that. When you say "fails to boot", what exactly do you mean please? How far does it get? Do you get any errors printed? Checking too: your ThinkCentre M73 claims to have firmware from 2020. If I'm reading correctly, the page at https://pcsupport.lenovo.com/us/en/products/desktops-and-all-in-ones/thinkcentre-m-series-desktops/thinkcentre-m73/10b6/downloads/driver-list/component?name=BIOS%2FUEFI&id=5AC6A815-321D-440E-8833-B07A93E0428C suggests there is a 2022 update. I'd be tempted to try updating to that to see if it helps. >Apparently the main keys updated correctly: > ># mokutil --db | grep "Subject:.*Microsoft" > Subject: C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, > CN=Microsoft Windows Production PCA 2011 > Subject: C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, > CN=Microsoft Corporation UEFI CA 2011 > Subject: C=US, O=Microsoft Corporation, CN=Microsoft UEFI CA 2023 > Subject: C=US, O=Microsoft Corporation, CN=Microsoft Option ROM UEFI > CA 2023 > >However, the KEK key did not: > ># mokutil --kek | grep Subject:.*Microsoft > Subject: C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, > CN=Microsoft Corporation KEK CA 2011 > >My attempt to update it showed no update available: > ># fwupdtool update >Loading… [******************* ]17:40:41.296 >FuEngine failed to add device >/sys/devices/pci0000:00/0000:00:1f.2/ata2/host1/target1:0:0/1:0:0:0/block/sr0: >failed to subclass open: failed to open /dev/sr0: No medium found >17:40:41.432 FuEngine failed to add device >/sys/devices/pci0000:00/0000:00:1f.2/ata2/host1/target1:0:0/1:0:0:0/block/sr0: >failed to subclass open: failed to open /dev/sr0: No medium found >Loading… [************************************** ] >Devices with the latest available firmware version: > • UEFI CA > • UEFI dbx >Devices with no available firmware updates: > • Option ROM UEFI CA > • Trust - Lenovo Certificate > • UEFI CA > • Windows Production PCA > • CT2000P310SSD8 > • KEK CA > • System Firmware > • WDS500G2B0A-00SM50 > >(Unfortunately, I did not save the original 'fwupdtool update' output >when the UEFI CA keys were updated) > >So far I've not downgraded shim-signed to version 1.47 to enable secure >boot again but so far have secure boot disabled in the BIOS setup. > >M73 system info: > ># dmidecode ># dmidecode 3.6 >Getting SMBIOS data from sysfs. >SMBIOS 2.8 present. >37 structures occupying 1720 bytes. >Table at 0x9DED2018. > >Handle 0x0000, DMI type 0, 24 bytes >BIOS Information > Vendor: LENOVO > Version: FCKT97AUS > Release Date: 01/07/2020 > Address: 0xF0000 > Runtime Size: 64 kB > ROM Size: 4 MB > Characteristics: > PCI is supported > BIOS is upgradeable > BIOS shadowing is allowed > Boot from CD is supported > Selectable boot is supported > BIOS ROM is socketed > EDD is supported > 5.25"/1.2 MB floppy services are supported (int 13h) > 3.5"/720 kB floppy services are supported (int 13h) > 3.5"/2.88 MB floppy services are supported (int 13h) > Print screen service is supported (int 5h) > 8042 keyboard services are supported (int 9h) > Serial services are supported (int 14h) > Printer services are supported (int 17h) > ACPI is supported > USB legacy is supported > BIOS boot specification is supported > Targeted content distribution is supported > UEFI is supported > BIOS Revision: 1.151 > >Handle 0x0001, DMI type 1, 27 bytes >System Information > Manufacturer: LENOVO > Product Name: 10B00005US > Version: ThinkCentre M73 > Serial Number: MJ00D7ZZ > UUID: 66e5795c-9a63-11e3-89c1-3d4e9daf1a00 > Wake-up Type: Power Switch > SKU Number: LENOVO_MT_10B0 > Family: > >Handle 0x0002, DMI type 2, 15 bytes >Base Board Information > Manufacturer: LENOVO > Product Name: 3098 > Version: 0B98401 PRO > Serial Number: INVALID > Asset Tag: > Features: > Board is a hosting board > Board is replaceable > Location In Chassis: > Chassis Handle: 0x0003 > Type: Motherboard > Contained Object Handles: 0 > >Handle 0x0003, DMI type 3, 25 bytes >Chassis Information > Manufacturer: LENOVO > Type: Desktop > Lock: Not Present > Version: > Serial Number: MJ00D7ZZ > Asset Tag: > Boot-up State: Safe > Power Supply State: Safe > Thermal State: Safe > Security Status: None > OEM Information: 0x00000000 > Height: Unspecified > Number Of Power Cords: 1 > Contained Elements: 1 > <OUT OF SPEC> (0) > SKU Number: > >Handle 0x0004, DMI type 9, 17 bytes >System Slot Information > Designation: J6B2 > Type: PCI Express > Data Bus Width: 16x or x16 > Current Usage: In Use > Length: Long > ID: 0 > Characteristics: > 3.3 V is provided > Opening is shared > PME signal is supported > Bus Address: 0000:00:01.0 > >Handle 0x0005, DMI type 9, 17 bytes >System Slot Information > Designation: J6B1 > Type: PCI Express > Data Bus Width: 1x or x1 > Current Usage: In Use > Length: Short > ID: 1 > Characteristics: > 3.3 V is provided > Opening is shared > PME signal is supported > Bus Address: 0000:00:1c.3 > >Handle 0x0006, DMI type 9, 17 bytes >System Slot Information > Designation: J6D1 > Type: PCI Express > Data Bus Width: 1x or x1 > Current Usage: In Use > Length: Short > ID: 2 > Characteristics: > 3.3 V is provided > Opening is shared > PME signal is supported > Bus Address: 0000:00:1c.4 > >Handle 0x0007, DMI type 9, 17 bytes >System Slot Information > Designation: J7B1 > Type: PCI Express > Data Bus Width: 1x or x1 > Current Usage: In Use > Length: Short > ID: 3 > Characteristics: > 3.3 V is provided > Opening is shared > PME signal is supported > Bus Address: 0000:00:1c.5 > >Handle 0x0008, DMI type 9, 17 bytes >System Slot Information > Designation: J8B4 > Type: PCI Express > Data Bus Width: 1x or x1 > Current Usage: In Use > Length: Short > ID: 4 > Characteristics: > 3.3 V is provided > Opening is shared > PME signal is supported > Bus Address: 0000:00:1c.6 > >Handle 0x0009, DMI type 10, 12 bytes >On Board Device 1 Information > Type: Video > Status: Enabled > Description: Onboard Video >On Board Device 2 Information > Type: Ethernet > Status: Enabled > Description: Onboard Lan >On Board Device 3 Information > Type: Sound > Status: Enabled > Description: Onboard Audio >On Board Device 4 Information > Type: SATA Controller > Status: Enabled > Description: Onboard SATA > >Handle 0x000A, DMI type 11, 5 bytes >OEM Strings > String 1: LENOVO ThinkCentre Embedded Controller -[N/A]- > String 2: LENOVO ThinkCentre BIOS Boot Block Revision 1.97 > >Handle 0x000B, DMI type 12, 5 bytes >System Configuration Options > Option 1: scre++ > >Handle 0x000C, DMI type 24, 5 bytes >Hardware Security > Power-On Password Status: Disabled > Keyboard Password Status: Enabled > Administrator Password Status: Disabled > Front Panel Reset Status: Not Implemented > >Handle 0x000D, DMI type 32, 20 bytes >System Boot Information > Status: No errors detected > >Handle 0x000E, DMI type 4, 42 bytes >Processor Information > Socket Designation: SOCKET 0 > Type: Central Processor > Family: Core i5 > Manufacturer: Intel > ID: C3 06 03 00 FF FB EB BF > Signature: Type 0, Family 6, Model 60, Stepping 3 > Flags: > FPU (Floating-point unit on-chip) > VME (Virtual mode extension) > DE (Debugging extension) > PSE (Page size extension) > TSC (Time stamp counter) > MSR (Model specific registers) > PAE (Physical address extension) > MCE (Machine check exception) > CX8 (CMPXCHG8 instruction supported) > APIC (On-chip APIC hardware supported) > SEP (Fast system call) > MTRR (Memory type range registers) > PGE (Page global enable) > MCA (Machine check architecture) > CMOV (Conditional move instruction supported) > PAT (Page attribute table) > PSE-36 (36-bit page size extension) > CLFSH (CLFLUSH instruction supported) > DS (Debug store) > ACPI (ACPI supported) > MMX (MMX technology supported) > FXSR (FXSAVE and FXSTOR instructions supported) > SSE (Streaming SIMD extensions) > SSE2 (Streaming SIMD extensions 2) > SS (Self-snoop) > HTT (Multi-threading) > TM (Thermal monitor supported) > PBE (Pending break enabled) > Version: Intel(R) Core(TM) i5-4570 CPU @ 3.20GHz > Voltage: 1.2 V > External Clock: 100 MHz > Max Speed: 3200 MHz > Current Speed: 3200 MHz > Status: Populated, Enabled > Upgrade: Socket BGA1155 > L1 Cache Handle: 0x0010 > L2 Cache Handle: 0x000F > L3 Cache Handle: 0x0011 > Serial Number: Not Specified > Asset Tag: Fill By OEM > Part Number: Fill By OEM > Core Count: 4 > Core Enabled: 4 > Thread Count: 4 > Characteristics: > 64-bit capable > >Handle 0x000F, DMI type 7, 19 bytes >Cache Information > Socket Designation: CPU Internal L2 > Configuration: Enabled, Not Socketed, Level 2 > Operational Mode: Write Back > Location: Internal > Installed Size: 1 MB > Maximum Size: 1 MB > Supported SRAM Types: > Unknown > Installed SRAM Type: Unknown > Speed: Unknown > Error Correction Type: Single-bit ECC > System Type: Unified > Associativity: 8-way Set-associative > >Handle 0x0010, DMI type 7, 19 bytes >Cache Information > Socket Designation: CPU Internal L1 > Configuration: Enabled, Not Socketed, Level 1 > Operational Mode: Write Back > Location: Internal > Installed Size: 256 kB > Maximum Size: 256 kB > Supported SRAM Types: > Unknown > Installed SRAM Type: Unknown > Speed: Unknown > Error Correction Type: Single-bit ECC > System Type: Other > Associativity: 8-way Set-associative > >Handle 0x0011, DMI type 7, 19 bytes >Cache Information > Socket Designation: CPU Internal L3 > Configuration: Enabled, Not Socketed, Level 3 > Operational Mode: Write Back > Location: Internal > Installed Size: 6 MB > Maximum Size: 6 MB > Supported SRAM Types: > Unknown > Installed SRAM Type: Unknown > Speed: Unknown > Error Correction Type: Single-bit ECC > System Type: Unified > Associativity: 12-way Set-associative > >Handle 0x0012, DMI type 16, 23 bytes >Physical Memory Array > Location: System Board Or Motherboard > Use: System Memory > Error Correction Type: None > Maximum Capacity: 16 GB > Error Information Handle: Not Provided > Number Of Devices: 2 > >Handle 0x0013, DMI type 17, 40 bytes >Memory Device > Array Handle: 0x0012 > Error Information Handle: Not Provided > Total Width: 64 bits > Data Width: 64 bits > Size: 8 GB > Form Factor: DIMM > Set: None > Locator: ChannelA-DIMM0 > Bank Locator: BANK 0 > Type: DDR3 > Type Detail: Synchronous > Speed: 1600 MT/s > Manufacturer: Micron > Serial Number: 10CD0955 > Asset Tag: 9876543210 > Part Number: 16KTF1G64AZ-1G6P1 > Rank: 2 > Configured Memory Speed: 1600 MT/s > Minimum Voltage: 1.35 V > Maximum Voltage: 1.5 V > Configured Voltage: 1.5 V > >Handle 0x0014, DMI type 15, 73 bytes >System Event Log > Area Length: 4096 bytes > Header Start Offset: 0x0000 > Header Length: 16 bytes > Data Start Offset: 0x0010 > Access Method: Memory-mapped physical 32-bit address > Access Address: 0xFFE6D000 > Status: Valid, Not Full > Change Token: 0x00000001 > Header Format: Type 1 > Supported Log Type Descriptors: 25 > Descriptor 1: Single-bit ECC memory error > Data Format 1: None > Descriptor 2: Multi-bit ECC memory error > Data Format 2: None > Descriptor 3: Parity memory error > Data Format 3: None > Descriptor 4: Bus timeout > Data Format 4: None > Descriptor 5: I/O channel block > Data Format 5: None > Descriptor 6: Software NMI > Data Format 6: None > Descriptor 7: POST memory resize > Data Format 7: None > Descriptor 8: POST error > Data Format 8: POST results bitmap > Descriptor 9: PCI parity error > Data Format 9: None > Descriptor 10: PCI system error > Data Format 10: None > Descriptor 11: CPU failure > Data Format 11: None > Descriptor 12: EISA failsafe timer timeout > Data Format 12: None > Descriptor 13: Correctable memory log disabled > Data Format 13: None > Descriptor 14: Logging disabled > Data Format 14: None > Descriptor 15: System limit exceeded > Data Format 15: None > Descriptor 16: Asynchronous hardware timer expired > Data Format 16: None > Descriptor 17: System configuration information > Data Format 17: None > Descriptor 18: Hard disk information > Data Format 18: None > Descriptor 19: System reconfigured > Data Format 19: None > Descriptor 20: Uncorrectable CPU-complex error > Data Format 20: None > Descriptor 21: Log area reset/cleared > Data Format 21: None > Descriptor 22: System boot > Data Format 22: None > Descriptor 23: End of log > Data Format 23: None > Descriptor 24: OEM-specific > Data Format 24: OEM-specific > Descriptor 25: OEM-specific > Data Format 25: OEM-specific > >Handle 0x0015, DMI type 20, 35 bytes >Memory Device Mapped Address > Starting Address: 0x00000000000 > Ending Address: 0x001FFFFFFFF > Range Size: 8 GB > Physical Device Handle: 0x0013 > Memory Array Mapped Address Handle: 0x0018 > Partition Row Position: Unknown > Interleave Position: 1 > Interleaved Data Depth: 1 > >Handle 0x0016, DMI type 17, 40 bytes >Memory Device > Array Handle: 0x0012 > Error Information Handle: Not Provided > Total Width: 64 bits > Data Width: 64 bits > Size: 8 GB > Form Factor: DIMM > Set: None > Locator: ChannelB-DIMM0 > Bank Locator: BANK 2 > Type: DDR3 > Type Detail: Synchronous > Speed: 1600 MT/s > Manufacturer: Micron > Serial Number: 10CD0958 > Asset Tag: 9876543210 > Part Number: 16KTF1G64AZ-1G6P1 > Rank: 2 > Configured Memory Speed: 1600 MT/s > Minimum Voltage: 1.35 V > Maximum Voltage: 1.5 V > Configured Voltage: 1.5 V > >Handle 0x0017, DMI type 20, 35 bytes >Memory Device Mapped Address > Starting Address: 0x00200000000 > Ending Address: 0x003FFFFFFFF > Range Size: 8 GB > Physical Device Handle: 0x0016 > Memory Array Mapped Address Handle: 0x0018 > Partition Row Position: Unknown > Interleave Position: 2 > Interleaved Data Depth: 1 > >Handle 0x0018, DMI type 19, 31 bytes >Memory Array Mapped Address > Starting Address: 0x00000000000 > Ending Address: 0x003FFFFFFFF > Range Size: 16 GB > Physical Array Handle: 0x0012 > Partition Width: 2 > >Handle 0x001C, DMI type 140, 19 bytes >OEM-specific Type > Header and Data: > 8C 13 1C 00 4C 45 4E 4F 56 4F 0B 05 01 0F 00 00 > 00 53 55 > >Handle 0x001D, DMI type 140, 23 bytes >OEM-specific Type > Header and Data: > 8C 17 1D 00 4C 45 4E 4F 56 4F 0B 06 01 00 00 00 > 00 00 00 00 00 00 00 > >Handle 0x001E, DMI type 131, 22 bytes >ThinkVantage Technologies > Version: 1 > Diagnostics: Available > >Handle 0x001F, DMI type 136, 6 bytes >OEM-specific Type > Header and Data: > 88 06 1F 00 5A 5A > >Handle 0x0020, DMI type 140, 85 bytes >OEM-specific Type > Header and Data: > 8C 55 20 00 4C 45 4E 4F 56 4F 0B 00 01 3B 94 F7 > 3D 84 37 39 80 FF 27 CB 4E 68 BC C1 DA 01 00 00 > 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 > 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 > 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 > 00 00 00 00 00 > >Handle 0x0021, DMI type 140, 47 bytes >OEM-specific Type > Header and Data: > 8C 2F 21 00 4C 45 4E 4F 56 4F 0B 01 01 09 00 3C > D9 4D 88 4E E7 CA 0C 23 C7 DF 63 AE 6C 1A F5 00 > 00 00 00 10 00 10 00 10 01 D0 00 20 01 00 01 > >Handle 0x0022, DMI type 140, 63 bytes >OEM-specific Type > Header and Data: > 8C 3F 22 00 4C 45 4E 4F 56 4F 0B 02 01 00 00 00 > 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 > 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 > 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 > >Handle 0x0023, DMI type 140, 17 bytes >OEM-specific Type > Header and Data: > 8C 11 23 00 4C 45 4E 4F 56 4F 0B 03 01 00 00 00 > 00 > >Handle 0x0024, DMI type 140, 19 bytes >OEM-specific Type > Header and Data: > 8C 13 24 00 4C 45 4E 4F 56 4F 0B 04 01 B2 00 4D > 53 20 00 > >Handle 0x0025, DMI type 131, 64 bytes >OEM-specific Type > Header and Data: > 83 40 25 00 35 00 00 00 00 00 00 00 00 00 00 00 > F8 00 5C 8C 00 00 00 00 01 20 00 00 00 00 09 00 > B6 05 15 00 00 00 00 00 C8 00 FF FF 00 00 00 00 > 00 00 00 00 66 00 00 00 76 50 72 6F 00 00 00 00 > >Handle 0x0026, DMI type 13, 22 bytes >BIOS Language Information > Language Description Format: Long > Installable Languages: 3 > en|US|iso8859-1 > fr|FR|iso8859-1 > zh|CN|unicode > Currently Installed Language: en|US|iso8859-1 > >Handle 0x0029, DMI type 127, 4 bytes >End Of Table > > >- -- System Information: >Debian Release: 13.6 > APT prefers stable-updates > APT policy: (500, 'stable-updates'), (500, 'stable-security'), (500, > 'stable') >Architecture: amd64 (x86_64) >Foreign Architectures: i386 > >Kernel: Linux 6.12.95+deb13-amd64 (SMP w/4 CPU threads; PREEMPT) >Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8), LANGUAGE not >set >Shell: /bin/sh linked to /usr/bin/dash >Init: systemd (via /run/systemd/system) >LSM: AppArmor: enabled > >Versions of packages shim-signed depends on: >ii debconf [debconf-2.0] 1.5.91 >ii grub-efi-amd64-bin 2.12-9+deb13u2 >ii grub2-common 2.12-9+deb13u2 >ii mokutil 0.7.2-1 >ii shim-helpers-amd64-signed 1+16.1+2~deb13u1 >ii shim-signed-common 1.51~1+deb13u1+16.1-2~deb13u1 > >shim-signed recommends no packages. > >shim-signed suggests no packages. > >- -- debconf information: > shim-signed/revoked-sig: > shim-signed/no-valid-sigs: > >-----BEGIN PGP SIGNATURE----- > >iGsEARECACsWIQSC1k9rDmfNQfaJu6b7LFEw1VqIGQUCalzZcw0cbjBuYkBuMG5i >LnVzAAoJEPssUTDVWogZs7UAn1Zv2ifNm92nAN4lNbaRUQJmiGd9AJ49i8llIw1Q >vp+7MJ5dmnSEZ5dQQg== >=UmFN >-----END PGP SIGNATURE----- -- Steve McIntyre, Cambridge, UK. [email protected] Armed with "Valor": "Centurion" represents quality of Discipline, Honor, Integrity and Loyalty. Now you don't have to be a Caesar to concord the digital world while feeling safe and proud.

