From 661d3ea1dc23ebe589593dd9cc772a1d436c417b Mon Sep 17 00:00:00 2001 From: Mathieu Trudel-Lapierre Date: Tue, 29 Aug 2017 13:57:47 -0400 Subject: [PATCH] Set ENABLE_SHIM_CERT, to keep using ephemeral self-signed certs built at compile-time for MokManager and fallback. --- debian/changelog | 2 ++ debian/rules | 1 + 2 files changed, 3 insertions(+) diff --git a/debian/changelog b/debian/changelog index 56ba2c4..79d7966 100644 --- a/debian/changelog +++ b/debian/changelog @@ -7,6 +7,8 @@ shim (12+1503074702.5202f80-0ubuntu1) UNRELEASED; urgency=medium MAKELEVEL. - Define an EFI_ARCH variable, and use that for paths to shim. This makes it possible to build a shim for other architectures than amd64. + - Set ENABLE_SHIM_CERT, to keep using ephemeral self-signed certs built + at compile-time for MokManager and fallback. * debian/patches/second-stage-path: dropped; the default loader path now includes an arch suffix. * debian/patches/sbsigntool-no-pesign: refreshed. diff --git a/debian/rules b/debian/rules index b03e2ee..b5f2136 100755 --- a/debian/rules +++ b/debian/rules @@ -23,6 +23,7 @@ override_dh_auto_build: dh_auto_build -- \ MAKELEVEL=0 \ EFI_PATH=/usr/lib \ + ENABLE_SHIM_CERT=1 \ VENDOR_CERT_FILE=$(cert) override_dh_fixperms: