Skip to content

Update Secure Boot page: AlmaLinux 8 shim 16.1 is dual-signed#810

Merged
andrewlukoshko merged 2 commits into
masterfrom
almalinux-8-dual-signed-shim
Jun 12, 2026
Merged

Update Secure Boot page: AlmaLinux 8 shim 16.1 is dual-signed#810
andrewlukoshko merged 2 commits into
masterfrom
almalinux-8-dual-signed-shim

Conversation

@andrewlukoshko

Copy link
Copy Markdown
Member

Follow-up to #809.

AlmaLinux 8 now ships shim-16.1-2.el8.alma.1 (x86_64): the x86_64 binaries are dual-signed with the Microsoft 2011 and 2023 UEFI CAs, and aarch64 is signed with the 2023 CA only — the same signature layout as AlmaLinux 9 and 10, following RHEL. Verified against the actual binaries from the stable repos.

Changes to /documentation/secure-boot-2023-certificates:

  • TL;DR: dual-signed shim now covers AlmaLinux 8, 9 and 10
  • Status table: AlmaLinux 8 row updated to shim-16.1-2.el8.alma.1 (was shim-15.8-4.el8_9.alma.2, 2011-only)
  • Status bullets simplified to x86_64 (all releases) and aarch64 (all releases) — the AlmaLinux 8-specific caveats are obsolete
  • Step 2 (fwupd): kept a note that AlmaLinux 8 ships fwupd 1.7.8, which cannot deliver the db/KEK certificate updates — EL8 users should use a vendor firmware update or the manual method

AlmaLinux 8 now ships shim-16.1-2.el8.alma.1: x86_64 binaries are
dual-signed with the Microsoft 2011 and 2023 UEFI CAs, aarch64 is
signed with the 2023 CA only — same as AlmaLinux 9 and 10, following
RHEL. Simplify the status section accordingly and note that fwupd on
AlmaLinux 8 (1.7.8) cannot deliver the db/KEK certificate updates.
- Use fwupdmgr --version | grep fwupd (works on AlmaLinux 8 too)
  and state the expected minimum/current versions
- Scope the fwupd step title to AlmaLinux 9 and later
- Point AlmaLinux 8 users to the alternative enrollment from the
  fwupd note
- Mention older AlmaLinux/fwupd releases in the manual enrollment
  intro
@andrewlukoshko andrewlukoshko merged commit b8c41bf into master Jun 12, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants