| Index | index by Group | index by Distribution | index by Vendor | index by creation date | index by Name | Mirrors | Help | Search |
| Name: shim | Distribution: openSUSE Tumbleweed |
| Version: 16.1 | Vendor: openSUSE |
| Release: 2.1 | Build date: Wed Dec 10 15:23:59 2025 |
| Group: System/Boot | Build host: reproducible |
| Size: 2172336 | Source RPM: shim-leap-16.1-2.1.src.rpm |
| Packager: http://bugs.opensuse.org | |
| Summary: UEFI shim loader | |
shim is a trivial EFI application that, when run, attempts to open and execute another application.
BSD-2-Clause
* Wed Dec 10 2025 Joey Lee <jlee@suse.com>
- shim-leap.spec: Always put openSUSE Secure Boot CA to target array
Unlike shim.spec, shim-leap.spec does not have #needssslcertforbuild
because our shim.efi is already signed by openSUSE key in
openSUSE:Factory:secure-boot/shim. It causes that the _projectcert.crt
can not be found by shim-leap which means the openSUSE CA can not be
added to the target certificates array in pretrans Lua script.
I can not directly add '# needssslcertforbuild' to shim-leap.spec
because it will causes that shim.efi be signed by openSUSE key again.
Let's always put openSUSE Secure Boot CA to target certificates array
because the shim.efi already has openSUSE signature. (bsc#1254679)
* Mon Dec 08 2025 Joey Lee <jlee@suse.com>
- Update shim version to 16.1:
shim-16.1-lp156.4.1.aarch64.rpm
shim-16.1-lp156.4.1.x86_64.rpm
RPMs are coming from openSUSE secure-boot shim 15.6:
https://build.opensuse.org/projects/openSUSE:Factory:secure-boot/packages/shim/repositories/15.6/binaries
- Version: 16.1, "Aug 14 2025"
- Include the bug fixes for bsc#1205588
- Add a pretrans script to verify that the necessary certificate is
in the UEFI db.
- Add DER format certificate files for the pretrans script to verify
that the necessary certificate is in the UEFI db
- openSUSE Secure Boot CA, 2013-2035
openSUSE_Secure_Boot_CA_2013.crt
- SUSE Linux Enterprise Secure Boot CA, 2013-2035
SUSE_Linux_Enterprise_Secure_Boot_CA_2013.crt
- Microsoft Corporation UEFI CA 2011, 2011-2026
Microsoft_Corporation_UEFI_CA_2011.crt
- Microsoft UEFI CA 2023, 2023-2038
Microsoft_UEFI_CA_2023.crt
* Wed Feb 19 2025 Ana Guerrero <ana.guerrero@suse.com>
- Only copy uncompressed directories.
* Fri Sep 20 2024 Dominique Leuenberger <dleuenberger@suse.com>
- RelEng emergency fix: fix source number to install shim-install.
* Mon Sep 02 2024 Dennis Tseng <dennis.tseng@suse.com>
- Update shim version for aarch64 to shim-15.8-lp155.8.8.aarch64.rpm
coming from openSUSE secure-boot 15.5
+ To avoid failure check by robot, SOURCEs in spec file are redefined.
+ Version: 15.8, "Jan 23 2024"
+ Include the bug fixes for bsc#1215099,bsc#1215098,bsc#1215100,bsc#1215101,
bsc#1215102, and bsc#1215103.
* Tue Jul 23 2024 Dennis Tseng <dennis.tseng@suse.com>
- Update to shim to 15.8-shim-15.8-lp155.8.2.x86_64.rpm from
openSUSE secure-boot 15.5
+ Version: 15.8, "Jan 23 2024"
+ Align the outside shim-install with the one in RPM file.
This is because all important fixes in outside shim-install are
also fixed in shim-install of RPM file. For consistency purposes,
the outside shim-install is updated in this version.
+ Include the bug fixes for bsc#1215099,bsc#1215098,bsc#1215100,bsc#1215101,
bsc#1215102, and bsc#1215103.
* Thu Mar 14 2024 Gary Ching-Pang Lin <glin@suse.com>
- Update shim-install to set the SRK algorithm for grub2 TPM2
key protector (bsc#1213945)
+ 92d0f4305df73 Set the SRK algorithm for the TPM2 protector
- Build with update-bootloader-rpm-macros and
fde-tpm-helper-rpm-macros and update the %post and %posttrans
macros correctly
* Wed Jun 07 2023 Gary Ching-Pang Lin <glin@suse.com>
- Update shim-install to support FDE
+ Read GRUB_CRYPTODISK_PASSWORD and GRUB_TPM2_SEALED_KEY to
create the proper cryptomount command for grub.cfg
+ Save the PCR snapshot if grub2 supports the command
+ Support 'no_grub_install' to skip grub2-install
+ Detect the OS ID of openSUSE Leap
* Thu May 25 2023 Gary Ching-Pang Lin <glin@suse.com>
- Remove the sym-links in /usr/lib64/efi for the newer distro
versions since we don't use them anymore
* Wed Jul 21 2021 jlee@suse.com
- Update to shim to 15.4-lp152.4.17.1 from openSUSE Leap 15.2
+ Version: 15.4, "Thu Jul 15 2021"
+ Updated openSUSE x86 signature
+ Include the fixes for bsc#1187696, bsc#1185261, bsc#1185441,
bsc#1187071, bsc#1185621, bsc#1185261, bsc#1185232, bsc#1185261,
bsc#1187260, bsc#1185232.
- Remove shim-install because the shim-install is updated in Leap
15.2 RPM.
/etc/uefi /etc/uefi/certs /etc/uefi/certs/4659838C-shim-opensuse.crt /usr/sbin/shim-install /usr/share/doc/packages/shim /usr/share/doc/packages/shim/COPYRIGHT /usr/share/doc/packages/shim/README /usr/share/efi /usr/share/efi/aarch64 /usr/share/efi/aarch64/MokManager.efi /usr/share/efi/aarch64/fallback.efi /usr/share/efi/aarch64/shim-opensuse.der /usr/share/efi/aarch64/shim-opensuse.efi /usr/share/efi/aarch64/shim.efi
Generated by rpm2html 1.8.1
Fabrice Bellet, Thu Dec 18 23:18:06 2025