ubuntu server 20.04.5 cannot be installed after enable secure boot

Bug #1990326 reported by shangsong
14
This bug affects 2 people
Affects Status Importance Assigned to Milestone
debian-installer (Ubuntu)
Invalid
Undecided
Unassigned
Focal
Fix Released
Critical
Unassigned
shim (Ubuntu)
Invalid
Undecided
Unassigned
Focal
Invalid
Undecided
Unassigned

Bug Description

Reproduce steps
1. Enable secure boot in the UEFI.
2. Fresh install ubuntu server 20.04.5 lts and latest daily build, but it fail with "An unauthorized EFI image is detected, please enroll this EFI image or disable secure boot ...."

Others:
1. Both ubuntu server 18.04.6 and 22.04 can be normal installed.

It seem the key of 20.04.x has been added into the latest UEFI Revocation List File(Release Date: August 12, 2022.https://uefi.org/revocationlistfile/archive).

Revision history for this message
shangsong (shangsong2) wrote :
affects: subiquity (Ubuntu) → shim (Ubuntu)
Revision history for this message
Seth Arnold (seth-arnold) wrote : Bug is not a security issue

Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privilege boundaries nor directly cause loss of data/privacy. Please feel free to report any other bugs you may find.

information type: Private Security → Public
Steve Langasek (vorlon)
Changed in debian-installer (Ubuntu):
status: New → Invalid
Changed in shim (Ubuntu):
status: New → Invalid
Steve Langasek (vorlon)
Changed in debian-installer (Ubuntu Focal):
importance: Undecided → Critical
Revision history for this message
Steve Langasek (vorlon) wrote :

This is an unfortunate bug caused by the fact that our point release process does not account for the need to update the debian-installer source package to get updated boot assets for the images, and as a result the 20.04.5 point release images despite being built in August 2022 were built with an older shim version from February 2021 that we knew was going to be revoked.

Discussions are in progress for a .6 point release to correct this error.

Steve Langasek (vorlon)
Changed in shim (Ubuntu Focal):
status: New → Invalid
tags: added: rls-kk-incoming
Revision history for this message
Launchpad Janitor (janitor) wrote :

Status changed to 'Confirmed' because the bug affects multiple users.

Changed in debian-installer (Ubuntu Focal):
status: New → Confirmed
Adrian Huang (ahuang12)
information type: Public → Public Security
Graham Inggs (ginggs)
information type: Public Security → Public
Revision history for this message
Timo Aaltonen (tjaalton) wrote : Please test proposed package

Hello shangsong, or anyone else affected,

Accepted debian-installer into focal-proposed. The package will build now and be available at https://launchpad.net/ubuntu/+source/debian-installer/20101020ubuntu614.4 in a few hours, and then in the -proposed repository.

Please help us by testing this new package. See https://wiki.ubuntu.com/Testing/EnableProposed for documentation on how to enable and use -proposed. Your feedback will aid us getting this update out to other Ubuntu users.

If this package fixes the bug for you, please add a comment to this bug, mentioning the version of the package you tested, what testing has been performed on the package and change the tag from verification-needed-focal to verification-done-focal. If it does not fix the bug for you, please add a comment stating that, and change the tag to verification-failed-focal. In either case, without details of your testing we will not be able to proceed.

Further information regarding the verification process can be found at https://wiki.ubuntu.com/QATeam/PerformingSRUVerification . Thank you in advance for helping!

N.B. The updated package will be released to -updates after the bug(s) fixed by this package have been verified and the package has been in -proposed for a minimum of 7 days.

Changed in debian-installer (Ubuntu Focal):
status: Confirmed → Fix Committed
tags: added: verification-needed verification-needed-focal
Revision history for this message
shangsong (shangsong2) wrote :

Hi Timo,
  First, as i known, ubuntu 20.04 use subiquity as server installation program, not debian-installer.
  Second, the failure occur at the begining of installation.
Therefore, how to use the debian-installer to fix the issue, could you provide the detail method for verification, thanks.

Revision history for this message
Steve Langasek (vorlon) wrote :

Verifying the fix requires testing against a focal daily image built with -proposed enabled, which we don't do by default. I've now built some daily images with -proposed enabled, which you can find here:

   https://cdimage.ubuntu.com/ubuntu-server/focal/daily-live/20221101/

Revision history for this message
shangsong (shangsong2) wrote :

The following release can fix the issue, thanks.
  https://cdimage.ubuntu.com/ubuntu-server/focal/daily-live/20221101/

Steve Langasek (vorlon)
tags: added: verification-done-focal
removed: verification-needed verification-needed-focal
Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package debian-installer - 20101020ubuntu614.4

---------------
debian-installer (20101020ubuntu614.4) focal; urgency=medium

  * No-change rebuild against shim-signed 1.40.7+15.4-0ubuntu9 and
    grub2-signed 1.167.2+2.04-1ubuntu44.2. LP: #1990326.

 -- Steve Langasek <email address hidden> Fri, 23 Sep 2022 14:20:08 -0700

Changed in debian-installer (Ubuntu Focal):
status: Fix Committed → Fix Released
Revision history for this message
Łukasz Zemczak (sil2100) wrote : Update Released

The verification of the Stable Release Update for debian-installer has completed successfully and the package is now being released to -updates. Subsequently, the Ubuntu Stable Release Updates Team is being unsubscribed and will not receive messages about this bug report. In the event that you encounter a regression using the package from -updates please report a new bug using ubuntu-bug and tag the bug report regression-update so we can easily find any regressions.

To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.