Bug#1146806: systemd-boot-efi-amd64-signed: Missing certificate for signed systemd-boot binary
Grundik
grundik at ololo.cc
Sat Sep 5 19:22:20 BST 2026
Package: systemd-boot-efi-amd64-signed
Version: systemd-boot-efi-amd64-signed
Severity: wishlist
X-Debbugs-Cc: debian-amd64 at lists.debian.org, grundik at ololo.cc
User: debian-amd64 at lists.debian.org
Usertags: amd64
Dear Maintainer,
The systemd-boot-efi-amd64-signed package provides a signed systemd-boot EFI
binary, but it does not include the certificate used to sign it. I cannot find
any official source that provides this certificate, which seems rather odd.
I understand that this boot loader is intended to be run via the Microsoft-
signed shim. However, if a user controls their Secure Boot platform, shim is
unnecessary. It is simpler to use the systemd-boot binary directly.
It is inconvenient to manually sign the binary after every update, especially
since Debian already provides a signed version. Therefore, it seems reasonable
to add the Debian Secure Boot Signer certificate to the UEFI DB. However, the
certificate does not appear to be provided anywhere.
It could be even better to provide a Debian KEK certificate and use it to allow
automatic updates to the UEFI DB. But at the very least, please provide the DB
certificate in a reasonable and officially documented location.
-- System Information:
Debian Release: forky/sid
APT prefers stable-updates
APT policy: (500, 'stable-updates'), (500, 'stable-security'), (500, 'unstable'), (500, 'testing'), (500, 'stable'), (1, 'experimental')
Architecture: amd64 (x86_64)
Foreign Architectures: i386
Kernel: Linux 7.2-amd64 (SMP w/16 CPU threads; PREEMPT)
Kernel taint flags: TAINT_USER, TAINT_OOT_MODULE
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8), LANGUAGE not set
Shell: /bin/sh linked to /usr/bin/dash
Init: systemd (via /run/systemd/system)
LSM: AppArmor: enabled
More information about the Pkg-systemd-maintainers
mailing list