Bug#1146806: systemd-boot-efi-amd64-signed: Missing certificate for signed systemd-boot binary
Grundik
grundik at ololo.cc
Sun Sep 6 02:52:43 BST 2026
On Sat, 5 Sep 2026 23:16:33 +0200 Chris Hofstaedtler <zeha at debian.org>
wrote:
> On Sat, Sep 05, 2026 at 09:22:20PM +0300, Grundik wrote:
> > The systemd-boot-efi-amd64-signed package provides a signed
systemd-boot EFI
> > binary, but it does not include the certificate used to sign it. I
cannot find
> > any official source that provides this certificate, which seems
rather odd.
>
> src:shim has it, and also https://dsa.debian.org/secure-boot-ca
>
Thanks! Its also possible to extract the certificate from the systemd-
boot EFI binary itself.
But that would be way more convenient, if it were provided in package
itself in a clear and obvious way. Maybe as a part of the docs, or
something like that.
More information about the Pkg-systemd-maintainers
mailing list