ELA-1817-1 shim new certificates

new signing certificate from Freexian

2026-09-02
Packageshim
Version16.1-2~deb11u1 (bullseye)


In order to support Secure Boot in bullseye ELTS, the shim needs to have the Freexian public certificate used to sign Linux kernels and other packages. This update adds that certificate to the shim alongside the Debian public CA, which allows to boot both old (signed by Debian) and new (signed by Freexian) packages.

The respective shim-signed package has also been updated to reflect this change.

In order to be able to boot future kernel security updates on setups where Secure Boot is enabled, these shim packages need to be upgraded, otherwise the old versions will not be able to verify the new signatures and the bootloader will refuse to load those kernel versions.

This revision also updates the shim to version 16.1, which includes revocations for old grub2 versions. As such, it is important to have the latest grub2 updates installed.



For Debian 11 bullseye, these problems have been fixed in version 16.1-2~deb11u1.

We recommend that you upgrade your shim packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.