Comment 8 for bug 1792497

Revision history for this message
Steve Langasek (vorlon) wrote :

And in fact, I see that trusty-updates currently has shim 13-0ubuntu2, but the newest version in cosmic/bionic is 15+1533136590.3beb971-0ubuntu1 which has not yet been SRUed to trusty because there are updates needed for other packages before it can land.

And the version of gnu-efi in bionic has changed in bionic-updates since shim 13-0ubuntu2 was built. There have also been updates to the toolchain in bionic since that binary was built. So I don't believe there is any possibility of a no-change rebuild of shim in bionic or cosmic resulting in a matching binary that passes signature checks.