Bug 872272

Summary: Shim is not currently signed.
Product: [Fedora] Fedora Reporter: Peter Jones <pjones>
Component: shimAssignee: Peter Jones <pjones>
Status: CLOSED CURRENTRELEASE QA Contact: Fedora Extras Quality Assurance <extras-qa>
Severity: urgent Docs Contact:
Priority: unspecified    
Version: 18CC: awilliam, fweimer, info, jwboyer, mjg59, pjones, robatino
Target Milestone: ---   
Target Release: ---   
Hardware: x86_64   
OS: Linux   
Whiteboard: AcceptedNTH RejectedBlocker
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2012-12-20 05:33:13 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 752664    

Description Peter Jones 2012-11-01 17:10:47 UTC
Description of problem: shim is not currently signed by the UEFI signing service.  That means new machines won't boot.

Comment 1 Adam Williamson 2012-11-01 18:28:26 UTC
Discussed at 2012-11-01 blocker review meeting: http://meetbot.fedoraproject.org/fedora-qa/2012-11-01/f18beta-blocker-review-6.5.2012-11-01-17.49.log.txt . Agreed this is rejected as a blocker as far as the blocker process goes: it is a conditional violation of "The installer must boot (if appropriate) and run on all primary architectures, with all system firmware types that are common on those architectures, from default live image, DVD, and boot.iso install media when written to an optical disc and when written to a USB stick with at least one of the officially supported methods" in the case of an SB machine with SB enabled, but we don't believe those are yet prevalent enough to block a Beta release for. However, it's accepted as NTH, as it would be great to have the Beta SB testable OOTB.

Note that SB support is also a feature for F18, so FESCo could delay the release for this under the feature process. The feature process is separate from the blocker process by policy.

Comment 2 Jaroslav Reznik 2012-12-03 13:49:21 UTC
*** Bug 882947 has been marked as a duplicate of this bug. ***

Comment 3 Fedora Update System 2012-12-18 03:22:35 UTC
shim-signed-0.2-3.2.fc18 has been submitted as an update for Fedora 18.
https://admin.fedoraproject.org/updates/shim-signed-0.2-3.2.fc18

Comment 4 Fedora Update System 2012-12-18 21:28:25 UTC
Package shim-signed-0.2-3.2.fc18:
* should fix your issue,
* was pushed to the Fedora 18 testing repository,
* should be available at your local mirror within two days.
Update it with:
# su -c 'yum update --enablerepo=updates-testing shim-signed-0.2-3.2.fc18'
as soon as you are able to.
Please go to the following url:
https://admin.fedoraproject.org/updates/FEDORA-2012-20583/shim-signed-0.2-3.2.fc18
then log in and leave karma (feedback).

Comment 5 Fedora Update System 2012-12-20 05:33:17 UTC
shim-signed-0.2-3.2.fc18 has been pushed to the Fedora 18 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 6 Adam Williamson 2013-01-04 03:04:07 UTC
*** Bug 890840 has been marked as a duplicate of this bug. ***