This program provides the means to enroll and erase the machine owner
keys (MOK) stored in the database of shim.


Install Howto

  1. Update the package index:
    # sudo apt-get update
  2. Install mokutil deb package:
    # sudo apt-get install mokutil




2019-04-12 - Simon Quigley <>
mokutil (0.3.0+1538710437.fb6250f-1) unstable; urgency=medium
* Upload to Debian (Closes: #925471).
* Adopt the package; thanks to Steve Langasek for your work!
* Update Vcs-* to reflect the move to Salsa.
2018-10-10 - Steve Langasek <>
mokutil (0.3.0+1538710437.fb6250f-0ubuntu2) cosmic; urgency=medium
* debian/patches/int-signedness.patch: Fix compile failure on
platforms where int != unsigned int.
2018-10-09 - Mathieu Trudel-Lapierre <>
mokutil (0.3.0+1538710437.fb6250f-0ubuntu1) cosmic; urgency=medium
* New upstream snapshot. (LP: #1797011)
- Add support for --export to export arbitrary firmware keyrings.
- Improved output for --sb-state.
- Fix help for --timeout
- Various bugfixes.
2018-08-29 - Mathieu Trudel-Lapierre <>
mokutil (0.3.0+1531796165.cca7219-0ubuntu1) cosmic; urgency=medium
* New upstream snapshot.
2018-02-05 - Dimitri John Ledkov <>
mokutil (0.3.0-0ubuntu5) bionic; urgency=high
* No change rebuild against openssl1.1.
2016-11-04 - Mathieu Trudel-Lapierre <>
mokutil (0.3.0-0ubuntu4) zesty; urgency=medium
* Rebuild against efivar 30-1ubuntu1.
* debian/patches/efivar-30-support.patch: port to efivar 30; where the API
for efi_set_variable() requires a mode to be specified.
2016-03-25 - Mario Limonciello <>
mokutil (0.3.0-0ubuntu3) xenial; urgency=medium
* Fix toggles working inconsistently by backporting 2 more commits
from upstream.
2016-03-26 - Mario Limonciello <>
mokutil (0.3.0-0ubuntu2) xenial; urgency=medium
* Backport buffer overflow patch from upstream (LP: #1562006)
* update debian/changelog for OpenSSL exception upstream.
2016-03-22 - Mario Limonciello <>
mokutil (0.3.0-0ubuntu1) xenial; urgency=medium
* New upstream version.
- Now uses efivar which supports immutable attributes (LP: #1560764)
* B-D on libefivar-dev, dh-autoreconf
* debian/rules: use autoreconf
* Backport cdb4b6f3 from upstream to fix i386 builds.
2016-03-15 - Mathieu Trudel-Lapierre <>
mokutil (0.2.0-1ubuntu1) xenial; urgency=medium
* debian/control: Build on i386, ia64, arm, and arm64 too.

