* On 2026 19 Jul 11:55 -0500, Steve McIntyre wrote:
> Hi Nate,

Thanks for the prompt reply, Steve.

> On Sun, Jul 19, 2026 at 09:04:35AM -0500, Nate Bargmann wrote:
> >Package: shim-signed
> >Version: 1.51~1+deb13u1+16.1-2~deb13u1
> >Severity: normal
> >
> >-----BEGIN PGP SIGNED MESSAGE-----
> >Hash: SHA1
> >
> >Dear Maintainer,
> >
> >As requested, I am filing this bug as even after following the Wiki
> >instructions, my Lenovo M73 fails to boot in secure boot mode with the
> >current version of shim-signed in Stable.
> 
> :-( I'm sorry to hear that.
> 
> When you say "fails to boot", what exactly do you mean please? How far
> does it get? Do you get any errors printed?

Yes.  The BIOS prints a white box with red border and lettering titled
"Secure Boot Violation".  The text is "Invalid signature detected.
Check Secure Boot Policy in Setup".  Then a "button" of "Ok" which just
repeats the cycle.  I have to use F12 to get to the boot menu and select
BIOS setup to disable secure boot at that point.

Here is my followup on testing the single-signed shims from the source
package.  Both of the single-signed shims from 2011 and 2023 boot
properly.  I then checked the journal to confirm secure boot is enabled.
Another test with the dual-signed shim resulted in the secure boot
failure.

> Checking too: your ThinkCentre M73 claims to have firmware from
> 2020. If I'm reading correctly, the page at
> 
> https://pcsupport.lenovo.com/us/en/products/desktops-and-all-in-ones/thinkcentre-m-series-desktops/thinkcentre-m73/10b6/downloads/driver-list/component?name=BIOS%2FUEFI&id=5AC6A815-321D-440E-8833-B07A93E0428C
> 
> suggests there is a 2022 update. I'd be tempted to try updating to
> that to see if it helps.

I will check that out.  Thanks for looking that up.

- Nate

-- 
"The optimist proclaims that we live in the best of all
possible worlds.  The pessimist fears this is true."
Web: https://www.n0nb.us
Projects: https://github.com/N0NB
GPG fingerprint: 82D6 4F6B 0E67 CD41 F689 BBA6 FB2C 5130 D55A 8819

Attachment: signature.asc
Description: PGP signature

Reply via email to