| Server IP : 54.37.205.81 / Your IP : 216.73.216.76 Web Server : nginx/1.22.1 System : Linux vps-249481fa 6.1.0-50-cloud-amd64 #1 SMP PREEMPT_DYNAMIC Debian 6.1.176-1 (2026-07-02) x86_64 User : debian ( 1000) PHP Version : 8.2.32 Disable Function : NONE MySQL : OFF | cURL : ON | WGET : ON | Perl : ON | Python : OFF | Sudo : ON | Pkexec : OFF Directory : /var/lib/dpkg/info/ |
Upload File : |
#! /bin/sh
set -e
type=$1
. /usr/share/debconf/confmodule
# Only change LC_ALL after loading debconf to ensure any debconf templates
# are properly localized.
export LC_ALL=C
# Select the right target architecture for grub-install
ARCH=$(dpkg --print-architecture)
case ${ARCH} in
amd64)
EFI_ARCH="x64";;
i386)
EFI_ARCH="ia32";;
arm64)
EFI_ARCH="aa64";;
*)
echo "Unsupported dpkg architecture ${ARCH} in $0. ABORT"
exit 1
;;
esac
SHIM="/usr/lib/shim/shim${EFI_ARCH}.efi.signed"
SHIM_SIGS=" 46:de:f6:3b:5c:e6:1c:f8:ba:0d:e2:e6:63:9c:10:19:d0:ed:14:f3 b5:ee:b4:a6:70:60:48:07:3f:0e:d2:96:e7:f5:80:a7:90:b5:9e:aa"
# Known error possibilities
ERR_NONE=0
ERR_NO_VALID_SIG=1
ERR_REVOKED=2
# Set the default error - no sigs found yet
SB_BOOT_ERROR=$ERR_NO_VALID_SIG
case "$type" in
install|upgrade)
echo "shim-signed: checking if we can safely install $SHIM"
if ! type mokutil > /dev/null 2>&1; then
echo " Mokutil is not installed, assuming things will be OK."
SB_BOOT_ERROR=$ERR_NONE
else
# Check that we can safely boot this shim.
# We don't care if the platform is in setup mode.
SB_STATE=$(mokutil --sb-state 2>&1 | grep -v \
-e "Platform is in Setup Mode" \
-e "SecureBoot validation is disabled in shim")
# If SB is not enabled (etc.) then this shim is fine
case "${SB_STATE}" in
"SecureBoot disabled"|"This system doesn't support Secure Boot")
echo " ${SB_STATE}; shim installation is safe."
SB_BOOT_ERROR=$ERR_NONE
;;
"EFI variables are not supported on this system"|"Cannot determine secure boot state")
echo " ${SB_STATE}; assuming shim installation is safe."
SB_BOOT_ERROR=$ERR_NONE
;;
"SecureBoot enabled")
echo " ${SB_STATE}; need to check for signatures."
SB_BOOT_ERROR=$ERR_NO_VALID_SIG
;;
*)
echo "Unexpected output from mokutil:"
echo '"""'
echo "${SB_STATE}"
echo '"""'
echo "Please report this as a bug agsinst shim-signed, including the above information."
exit 1
;;
esac
fi
if [ $SB_BOOT_ERROR != $ERR_NONE ]; then
echo "Checking shim signatures on $SHIM:"
# Secure Boot is enabled - we need to check that our shim
# is signed by a key in the DB list.
# Check against all the keys in the DB list
for dbkey in $(mokutil --db | awk '/^SHA1 Fingerprint:/ {print $3}'); do
for sig in ${SHIM_SIGS}; do
if [ "$dbkey" = "$sig" ]; then
echo "- signed by DB key $dbkey, should boot OK"
SB_BOOT_ERROR=$ERR_NONE
fi
done
done
# Next, check against the blacklisted keys in DBX - any
# blacklisted sig will block boot of a shim signed with
# that sig.
for dbxkey in $(mokutil --dbx | awk '/^SHA1 Fingerprint:/ {print $3}'); do
for sig in ${SHIM_SIGS}; do
if [ "$dbxkey" = "$sig" ]; then
echo "- signed by DBX key $dbxkey, will be blocked from booting"
SB_BOOT_ERROR=$ERR_REVOKED
fi
done
done
fi
if [ $SB_BOOT_ERROR != $ERR_NONE ]; then
if [ $SB_BOOT_ERROR = $ERR_NO_VALID_SIG ]; then
TEMPLATENAME=shim-signed/no-valid-sigs
elif [ $SB_BOOT_ERROR = $ERR_REVOKED ]; then
TEMPLATENAME=shim-signed/revoked-sig
fi
db_version 2.0
db_fset "$TEMPLATENAME" seen false
db_reset "$TEMPLATENAME"
db_input critical "$TEMPLATENAME" || true
db_go
db_stop
exit 1
fi
esac
# Automatically added by dh_installdeb/13.11.4
dpkg-maintscript-helper symlink_to_dir /usr/share/doc/shim-signed shim-signed-common 1.36\~ shim-signed -- "$@"
# End automatically added section
exit 0