SEARCH
NEW RPMS
DIRECTORIES
ABOUT
FAQ
VARIOUS
BLOG

 
 
Changelog for shim-x64-15-11.sl7.x86_64.rpm :
Tue Sep 29 14:00:00 2020 Scientific Linux Auto Patch Process
- Replaced Source: securebootca.cer
--> Use the FNAL SL signing certificate

Wed Sep 16 14:00:00 2020 Peter Jones - 15-11
- Fix incorrect allocation size in set_second_stage()
Resolves: rhbz#1875486

Fri Aug 21 14:00:00 2020 Peter Jones - 15-10.el7
- 15-9.el7 was built in the wrong tag.
Related: rhbz#1868820

Mon Aug 17 14:00:00 2020 Peter Jones - 15-9.el7
- Add mokutil code to consume data from /sys/firmware/efi/mok-variables/
as well as attempting to consume numbered mok variables from efivarfs when
mok-variables aren\'t present.
Resolves: rhbz#1868820

Fri Jul 31 14:00:00 2020 Peter Jones - 15-8.el7
- Update to fix hang on some systems.
Resolves: rhbz#1862045

Tue Jul 28 14:00:00 2020 Peter Jones - 15-7
- New signing keys
Related: CVE-2020-10713
Related: CVE-2020-14308
Related: CVE-2020-14309
Related: CVE-2020-14310
Related: CVE-2020-14311

Thu Mar 21 13:00:00 2019 Peter Jones - 15-2
- Fix MoK mirroring issue which breaks kdump without intervention
Related: rhbz#1649270

Fri Jul 20 14:00:00 2018 Peter Jones - 15-1
- Update to shim version 15
Resolves: rhbz#1589962

Wed Jul 11 14:00:00 2018 Peter Jones - 12-3
- Fix broken file owner/modes
Resolves: rhbz#1595677

Sat Jun 23 14:00:00 2018 Peter Jones - 12-2
- Fix /boot/efi/... permissions to match the filesystem\'s requirements
Related: rhbz#1512749
- Minor .spec cleanups
Related: rhbz#1512749

Mon May 1 14:00:00 2017 Peter Jones - 12-1
- Update to 12-1 to work around a signtool.exe bug
Resolves: rhbz#1445393

Mon Apr 24 14:00:00 2017 Peter Jones - 11-4
- Another shot at better obsoletes.
Related: rhbz#1310764

Mon Apr 24 14:00:00 2017 Peter Jones - 11-3
- Fix Obsoletes
Related: rhbz#1310764

Thu Apr 13 14:00:00 2017 Peter Jones - 11-2
- Make sure Aarch64 still has shim.efi as well
Related: rhbz#1310766

Wed Apr 12 14:00:00 2017 Peter Jones - 11-1
- Rebuild with signed shim
Related: rhbz#1310766

Mon Apr 3 14:00:00 2017 Peter Jones - 11-0.1
- Update to 11-0.1 to match shim-11-1
Related: rhbz#1310766
- Fix regression in PE loader
Related: rhbz#1310766
- Fix case where BDS invokes us wrong and we exec shim again as a result
Related: rhbz#1310766

Mon Mar 27 14:00:00 2017 Peter Jones - 10-0.1
- Support ia32
Resolves: rhbz#1310766
- Handle various different load option implementation differences
- TPM 1 and TPM 2 support.
- Update to OpenSSL 1.0.2k

Mon Jul 20 14:00:00 2015 Peter Jones - 0.9-2
- Apparently I\'m
*never
* going to learn to build this in the right target
the first time through.
Related: rhbz#1100048

Mon Jun 29 14:00:00 2015 Peter Jones - 0.9-0.1
- Bump version for 0.9
Also use mokutil-0.3.0
Related: rhbz#1100048

Tue Jun 23 14:00:00 2015 Peter Jones - 0.7-14.1
- Fix mokutil_version usage.
Related: rhbz#1100048

Mon Jun 22 14:00:00 2015 Peter Jones - 0.7-14
- Pull in aarch64 build so they can compose that tree.
(-14 to match -unsigned)
Related: rhbz#1100048

Wed Feb 25 13:00:00 2015 Peter Jones - 0.7-12
- Fix some minor build bugs on Aarch64
Related: rhbz#1190191

Tue Feb 24 13:00:00 2015 Peter Jones - 0.7-11
- Fix section loading on Aarch64
Related: rhbz#1190191

Wed Dec 17 13:00:00 2014 Peter Jones - 0.7-10
- Rebuild for Aarch64 to get \\EFI\\BOOT\\BOOTAA64.EFI named right.
(I managed to fix the inputs but not the outputs in -9.)
Related: rhbz#1100048

Wed Dec 17 13:00:00 2014 Peter Jones - 0.7-9
- Rebuild for Aarch64 to get \\EFI\\BOOT\\BOOTAA64.EFI named right.
Related: rhbz#1100048

Tue Oct 21 14:00:00 2014 Peter Jones - 0.7-8
- Build for aarch64 as well
Related: rhbz#1100048
- out-of-bounds memory read flaw in DHCPv6 packet processing
Resolves: CVE-2014-3675
- heap-based buffer overflow flaw in IPv6 address parsing
Resolves: CVE-2014-3676
- memory corruption flaw when processing Machine Owner Keys (MOKs)
Resolves: CVE-2014-3677

Tue Sep 23 14:00:00 2014 Peter Jones - 0.7-7
- Make sure we use the right keys on Aarch64.
(It\'s only a demo at this stage.)
Related: rhbz#1100048

Tue Sep 23 14:00:00 2014 Peter Jones - 0.7-6
- Add ARM Aarch64.
Related: rhbz#1100048

Thu Feb 27 13:00:00 2014 Peter Jones - 0.7-5.2
- Get the right signatures on shim-redhat.efi
Related: rhbz#1064449

Thu Feb 27 13:00:00 2014 Peter Jones - 0.7-5.1
- Update for signed shim for RHEL 7
Resolves: rhbz#1064449

Thu Nov 21 13:00:00 2013 Peter Jones - 0.7-5
- Fix shim-unsigned deps.
Related: rhbz#1032583

Thu Nov 21 13:00:00 2013 Peter Jones - 0.7-4
- Make dhcp4 work better.
Related: rhbz#1032583

Thu Nov 14 13:00:00 2013 Peter Jones - 0.7-3
- Make lockdown include UEFI and other KEK/DB entries.
Related: rhbz#1030492

Fri Nov 8 13:00:00 2013 Peter Jones - 0.7-2
- Handle SetupMode better in lockdown as well
Related: rhbz#996863

Wed Nov 6 13:00:00 2013 Peter Jones - 0.7-1
- Don\'t treat SetupMode variable\'s presence as meaning we\'re in SetupMode.
Related: rhbz#996863

Wed Nov 6 13:00:00 2013 Peter Jones - 0.6-3
- Use the correct CA and signer certificates.
Related: rhbz#996863

Thu Oct 31 13:00:00 2013 Peter Jones - 0.6-1
- Update to 0.6-1
Resolves: rhbz#1008379

Wed Aug 7 14:00:00 2013 Peter Jones - 0.4-3.2
- Depend on newer pesign.
Related: rhbz#989442

Tue Aug 6 14:00:00 2013 Peter Jones - 0.4-3.1
- Rebuild with newer pesign
Related: rhbz#989442

Tue Aug 6 14:00:00 2013 Peter Jones - 0.4-3
- Update for RHEL signing with early test keys.
Related: rhbz#989442

Thu Jun 20 14:00:00 2013 Peter Jones - 0.4-1
- Provide a fallback for uninitialized Boot#### and BootOrder
Resolves: rhbz#963359
- Move all signing from shim-unsigned to here
- properly compare our generated hash from shim-unsigned with the hash of
the signed binary (as opposed to doing it manually)

Fri May 31 14:00:00 2013 Peter Jones - 0.2-4.4
- Re-sign to get alignments that match the new specification.
Resolves: rhbz#963361

Thu Feb 14 13:00:00 2013 Fedora Release Engineering - 0.2-4.3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_Rebuild

Wed Jan 2 13:00:00 2013 Peter Jones - 0.2-3.3
- Add obsoletes and provides for earlier shim-signed packages, to cover
the package update cases where previous versions were installed.
Related: rhbz#888026

Mon Dec 17 13:00:00 2012 Peter Jones - 0.2-3.2
- Make the shim-unsigned dep be on the subpackage.

Sun Dec 16 13:00:00 2012 Peter Jones - 0.2-3.1
- Rebuild to provide \"shim\" package directly instead of just as a Provides:

Sat Dec 15 13:00:00 2012 Peter Jones - 0.2-3
- Also provide shim-fedora.efi, signed only by the fedora signer.
- Fix the fedora signature on the result to actually be correct.
- Update for shim-unsigned 0.2-3

Mon Dec 3 13:00:00 2012 Peter Jones - 0.2-2
- Initial build


 
ICM