shim-helpers-i386-signed-template - boot loader to chain-load signed boot loaders (signing template)

Property Value
Distribution Debian 10 (Buster)
Repository Debian Main i386
Package filename shim-helpers-i386-signed-template_15+1533136590.3beb971-7_i386.deb
Package name shim-helpers-i386-signed-template
Package version 15+1533136590.3beb971
Package release 7
Package architecture i386
Package type deb
Category admin
Homepage -
License -
Maintainer Debian EFI team <>
Download size 10.60 KB
Installed size 42.00 KB
This package contains template files for shim-helpers-i386-signed.
This is only needed for Secure Boot signing.


Type URL
Binary Package shim-helpers-i386-signed-template_15+1533136590.3beb971-7_i386.deb
Source Package shim

Install Howto

  1. Update the package index:
    # sudo apt-get update
  2. Install shim-helpers-i386-signed-template deb package:
    # sudo apt-get install shim-helpers-i386-signed-template




2019-05-08 - Steve McIntyre <>
shim (15+1533136590.3beb971-7) unstable; urgency=medium
[ Ansgar Burchardt ]
* debian/control: Update Vcs-* fields
[ Steve McIntyre ]
* Backport needed crash fixes:
+ VLogError(): Avoid NULL pointer dereferences in (V)Sprint calls
+ Fix OBJ_create() to tolerate a NULL sn and ln
* Build using gcc-7 to get better control of reproducibility during the
lifetime of Buster.
* Build in a dbx list to blacklist binaries that we know to not be
secure. Build-depend on a new (bug-fixed) version of pesign to
generate that list at build time, using a list of known bad hashes.
* Initial list of known bad hashes is just my personal test binary.
2019-03-23 - Steve McIntyre <>
shim (15+1533136590.3beb971-6) unstable; urgency=medium
[ Steve McIntyre ]
* Add Provides: and Breaks: to shim-helpers-$arch-signed to fix
clashes with the old shim-signed package for fbx64.efi.signed and
mmx64.efi.signed. Closes: #924619
[ Helmut Grohne ]
* Fix FTCBFS: Set CROSS_COMPILE. (Closes: #922152)
2019-03-12 - Steve McIntyre <>
shim (15+1533136590.3beb971-5) unstable; urgency=medium
[ Ansgar Burchardt ]
* Correct maintainer address in signing template
[ Steve McIntyre ]
* Remove Rules-Requires-Root in the signing template. We manually install
things owned by root. There might be better ways to do this, but this
will do for now.
2019-03-09 - Steve McIntyre <>
shim (15+1533136590.3beb971-4) unstable; urgency=medium
[ Steve McIntyre ]
* No-change sourceful upload to get rebuilds (and hence build logs) from
the buildds. Hoping to get this version signed by Microsoft, so let's
make our setup as clean as possible.
2019-03-08 - Steve McIntyre <>
shim (15+1533136590.3beb971-3) unstable; urgency=medium
[ Philipp Hahn ]
* debian/rules: fixing permissions no longer required
* debian/rules: Disable ephemeral key on Debian.
* Rename binary package to 'shim-unsigned'
* Add template for signing {mm,fb}$ARCH.efi. (Closes: #922228)
[ Luca Boccassi ]
* Override lintian error about template rules file.
* Include /usr/share/dpkg/ instead of shelling out.
* Add uname.patch to avoid embedding the kernel architecture in the
binary and to use a fixed string instead.
[ Steve McIntyre ]
* Change maintenance address to be the EFI team
* Add me and vorlon to the Uploaders list
* Rename the helper binary packages to shim-helpers-$arch.
* Update the signing-template JSON metadata to match new practice:
+ Move all the data under a new top-level "packages" key
+ Add an empty "trusted_certs" key - the helper binaries do not do any
further verification with an embedded key.
2019-02-11 - Steve Langasek <>
shim (15+1533136590.3beb971-2) unstable; urgency=medium
* Update debian/watch.
* Update VCS to point to salsa.
* Fix debian/rules syntax for arm64 build.
* Enable build for i386.
* Ensure DEB_HOST_ARCH is set even if not present in the environment.
* Update Standards-Version.
* Update debian/copyright (drop reference to file no longer in source)

