Index index by Group index by Distribution index by Vendor index by creation date index by Name Mirrors Help Search

shim-16.1-2.1 RPM for x86_64

From OpenSuSE Tumbleweed for x86_64

Name: shim Distribution: openSUSE Tumbleweed
Version: 16.1 Vendor: openSUSE
Release: 2.1 Build date: Wed Dec 10 15:23:59 2025
Group: System/Boot Build host: reproducible
Size: 2109568 Source RPM: shim-leap-16.1-2.1.src.rpm
Packager: https://bugs.opensuse.org
Summary: UEFI shim loader
shim is a trivial EFI application that, when run, attempts to open and
execute another application.

Provides

Requires

License

BSD-2-Clause

Changelog

* Wed Dec 10 2025 Joey Lee <jlee@suse.com>
  - shim-leap.spec: Always put openSUSE Secure Boot CA to target array
    Unlike shim.spec, shim-leap.spec does not have #needssslcertforbuild
    because our shim.efi is already signed by openSUSE key in
    openSUSE:Factory:secure-boot/shim. It causes that the _projectcert.crt
    can not be found by shim-leap which means the openSUSE CA can not be
    added to the target certificates array in pretrans Lua script.
    I can not directly add '# needssslcertforbuild' to shim-leap.spec
    because it will causes that shim.efi be signed by openSUSE key again.
    Let's always put openSUSE Secure Boot CA to target certificates array
    because the shim.efi already has openSUSE signature. (bsc#1254679)
* Mon Dec 08 2025 Joey Lee <jlee@suse.com>
  - Update shim version to 16.1:
      shim-16.1-lp156.4.1.aarch64.rpm
      shim-16.1-lp156.4.1.x86_64.rpm
      RPMs are coming from openSUSE secure-boot shim 15.6:
      https://build.opensuse.org/projects/openSUSE:Factory:secure-boot/packages/shim/repositories/15.6/binaries
    - Version: 16.1, "Aug 14 2025"
    - Include the bug fixes for bsc#1205588
  - Add a pretrans script to verify that the necessary certificate is
    in the UEFI db.
  - Add DER format certificate files for the pretrans script to verify
    that the necessary certificate is in the UEFI db
    - openSUSE Secure Boot CA, 2013-2035
      openSUSE_Secure_Boot_CA_2013.crt
    - SUSE Linux Enterprise Secure Boot CA, 2013-2035
      SUSE_Linux_Enterprise_Secure_Boot_CA_2013.crt
    - Microsoft Corporation UEFI CA 2011, 2011-2026
      Microsoft_Corporation_UEFI_CA_2011.crt
    - Microsoft UEFI CA 2023, 2023-2038
      Microsoft_UEFI_CA_2023.crt
* Wed Feb 19 2025 Ana Guerrero <ana.guerrero@suse.com>
  - Only copy uncompressed directories.
* Fri Sep 20 2024 Dominique Leuenberger <dleuenberger@suse.com>
  - RelEng emergency fix: fix source number to install shim-install.
* Mon Sep 02 2024 Dennis Tseng <dennis.tseng@suse.com>
  - Update shim version for aarch64 to shim-15.8-lp155.8.8.aarch64.rpm
    coming from openSUSE secure-boot 15.5
    + To avoid failure check by robot, SOURCEs in spec file are redefined.
    + Version: 15.8, "Jan 23 2024"
    + Include the bug fixes for bsc#1215099,bsc#1215098,bsc#1215100,bsc#1215101,
      bsc#1215102, and bsc#1215103.
* Tue Jul 23 2024 Dennis Tseng <dennis.tseng@suse.com>
  - Update to shim to 15.8-shim-15.8-lp155.8.2.x86_64.rpm from
    openSUSE secure-boot 15.5
    + Version: 15.8, "Jan 23 2024"
    + Align the outside shim-install with the one in RPM file.
      This is because all important fixes in outside shim-install are
      also fixed in shim-install of RPM file. For consistency purposes,
      the outside shim-install is updated in this version.
    + Include the bug fixes for bsc#1215099,bsc#1215098,bsc#1215100,bsc#1215101,
      bsc#1215102, and bsc#1215103.
* Thu Mar 14 2024 Gary Ching-Pang Lin <glin@suse.com>
  - Update shim-install to set the SRK algorithm for grub2 TPM2
    key protector (bsc#1213945)
    + 92d0f4305df73 Set the SRK algorithm for the TPM2 protector
  - Build with update-bootloader-rpm-macros and
    fde-tpm-helper-rpm-macros and update the %post and %posttrans
    macros correctly
* Wed Jun 07 2023 Gary Ching-Pang Lin <glin@suse.com>
  - Update shim-install to support FDE
    + Read GRUB_CRYPTODISK_PASSWORD and GRUB_TPM2_SEALED_KEY to
      create the proper cryptomount command for grub.cfg
    + Save the PCR snapshot if grub2 supports the command
    + Support 'no_grub_install' to skip grub2-install
    + Detect the OS ID of openSUSE Leap
* Thu May 25 2023 Gary Ching-Pang Lin <glin@suse.com>
  - Remove the sym-links in /usr/lib64/efi for the newer distro
    versions since we don't use them anymore
* Wed Jul 21 2021 jlee@suse.com
  - Update to shim to 15.4-lp152.4.17.1 from openSUSE Leap 15.2
    + Version: 15.4, "Thu Jul 15 2021"
    + Updated openSUSE x86 signature
    + Include the fixes for bsc#1187696, bsc#1185261, bsc#1185441,
      bsc#1187071, bsc#1185621, bsc#1185261, bsc#1185232, bsc#1185261,
      bsc#1187260, bsc#1185232.
  - Remove shim-install because the shim-install is updated in Leap
    15.2 RPM.

Files

/etc/uefi
/etc/uefi/certs
/etc/uefi/certs/4659838C-shim-opensuse.crt
/usr/sbin/shim-install
/usr/share/doc/packages/shim
/usr/share/doc/packages/shim/COPYRIGHT
/usr/share/doc/packages/shim/README
/usr/share/efi
/usr/share/efi/x86_64
/usr/share/efi/x86_64/MokManager.efi
/usr/share/efi/x86_64/fallback.efi
/usr/share/efi/x86_64/shim-opensuse.der
/usr/share/efi/x86_64/shim-opensuse.efi
/usr/share/efi/x86_64/shim.efi


Generated by rpm2html 1.8.1

Fabrice Bellet, Tue Dec 23 23:19:34 2025