�PNG  IHDR22?�� pHYs  �� OiCCPPhotoshop ICC profilexڝSgTS�=���BK���KoR RB���&*! J�!��Q�EEȠ�����Q, � ��!���������{�kּ������>���� �H3Q5� �B�������.@� $p�d!s�#�~<<+"��x� �M��0���B�\���t�8K�@z�B�@F���&S�`�cb�P-`'������{[�!�� e�Dh;��V�EX0fK�9�-0IWfH���� � 0Q��){`�##x��F�W<�+��*x��<�$9E�[-qWW.(�I+6aa�@.�y�2�4���������x����6��_-��"bb���ϫp@�t~��,/��;�m��%�h^ �u��f�@����W�p�~<�5�j>{�-�]c�K'Xt����o��(�h���w��?�G�%�fI�q^D$.Tʳ?�D��*�A��,���� �`6�B$��BB d�r`)��B(�Ͱ*`/�@4�Qh��p.�U�=p�a��(�� A�a!ڈb�X#����!�H�$ ɈQ"K�5H1R�T UH�=r9�\F��;�2����G1���Q=� �C��7�F� �dt1�����r�=�6��Ыhڏ>C�0��3�l0.��B�8, �c˱"� ���V����cϱw�E� 6wB aAHXLXN�H� $4� 7 �Q�'"��K�&���b21�XH,#��/{�C�7$�C2'��I��T��F�nR#�,��4H#���dk�9�, +ȅ����3��!�[ �b@q��S�(R�jJ��4�e�2AU��Rݨ�T5�ZB���R�Q��4u�9̓IK�����hh�i��t�ݕN��W���G���w ��Ljg(�gw��L�Ӌ�T071���oUX*�*|�� �J�&�*/T����ު U�U�T��^S}�FU3S� Ԗ�U��P�SSg�;���g�oT?�~Y��Y�L�OC�Q��_�� c�x,!k ��u�5�&���|v*�����=���9C3J3W�R�f?�q��tN �(���~���)�)�4L�1e\k����X�H�Q�G�6������E�Y��A�J'\'Gg����S�Sݧ �M=:��.�k���Dw�n��^��Lo��y���}/�T�m���G X� $� �<�5qo</���QC]�@C�a�a�ᄑ��<��F�F�i�\�$�m�mƣ&&!&KM�M�RM��)�;L;L���͢�֙5�=1�2��כ߷`ZxZ,����eI��Z�Yn�Z9Y�XUZ]�F���%ֻ�����N�N���gð�ɶ�����ۮ�m�}agbg�Ů��}�}��= ���Z~s�r:V:ޚΜ�?}����/gX���3��)�i�S��Ggg�s�󈋉K��.�>.���Ƚ�Jt�q]�z���������ۯ�6�i�ܟ�4�)�Y3s���C�Q��? ��0k߬~OCO�g��#/c/�W�װ��w��a�>�>r��>�<7�2�Y_�7��ȷ�O�o�_��C#�d�z����%g��A�[��z|!��?:�e����A���AA�������!h�쐭!��Α�i�P~���a�a��~ '���W�?�p�X�1�5w��Cs�D�D�Dޛg1O9�-J5*>�.j<�7�4�?�.fY��X�XIlK9.*�6nl������� �{�/�]py�����.,:�@L�N8��A*��%�w%� y��g"/�6ш�C\*N�H*Mz�쑼5y$�3�,幄'���L Lݛ:��v m2=:�1����qB�!M��g�g�fvˬe����n��/��k���Y- �B��TZ(�*�geWf�͉�9���+��̳�ې7�����ᒶ��KW-X潬j9�������(�x��oʿ�ܔ���Ĺd�f�f���-�[����n �ڴ �V����E�/��(ۻ��C���<��e����;?T�T�T�T6��ݵa��n��{��4���[���>ɾ�UUM�f�e�I���?�������m]�Nmq����#�׹���=TR��+�G�����w- 6 U����#pDy��� �� :�v�{���vg/jB��F�S��[b[�O�>����z�G��499�?r����C�d�&����ˮ/~�����јѡ�򗓿m|������������x31^�V���w�w��O�| (�h���SЧ��������c3-� cHRMz%������u0�`:�o�_�F5IDATx��ytUս�?�;���fN$$��@B�!�k��� -*�gE���j�O�kQ�ʠ`U�B_ �AÐ0%�Ȕ�@r3ޛ;߳��$�@��v����^�s����������$��ߢ !�W��5�̱'-٘������4�>�Rƫ$�G��0U�H}�_ _� #��k�MJ/=�9Du *ڲ�k�PQ;0��j|�*�$�^컂脛y���>�z×� B��� ��(�:$�ʔ_�6��C!B����MVx��a��ζyY����j��ƋY2�9�F�{r��r�딟F��Q��hY6��� x��[l��RC��������nt@��;P��3��� F�w��7��:�P���ɋ'���mj���Bƪ�$�Q�L��y��߷g��\���z����v5�p�v$�v櫻�`6~K �Y�X����,�:��"�o�e0II"(��,������l_�C���/4�+f�E�!q��:����u����c��樼.UE�@� �]K�W���$-�h]�JG���Dz)�`��.�A/ ���mᏣc�3jK� �!�>���$�Q�!�_�? \�C2(E �M$Z I{�U���s�ǣ���=��@Բe ޻��W�����@ �w����}�9v,)��.}*|"�s��di���,���G�]W�AC�������|<����[��ߕ������K�*�G nߴ!��‹��J�!��6(L�a)��Am��������;adf��:�xm��nh�;֦I��(���o�C~ډa?�=��s����h��E������xp����)���_���t��W�����´;8���`dz=(��@@�+,�;�`�fhl��XȌ�3,uI�~z(J����� �ZX�A����H'�À�㜦�82|��a�n�z2��I���� ���EY�h�ε<�0�q�{��C��v�˅��?"@��χ�x�WS+��N�~�KQ�J�8ل�� _.W��� !TU{�����,��"�� �;�������HI S� ��))�o�1�H�D� ���� (� ;����"Ҕ��,���� �F=���O��&�Ph>�`���y��߲ &S��P�<��'��1s�1cĂ�N����2)����@�u��tv��<�+�-&�����h��[!FSG���' � z z0��<����8d&�����E0�,��<��"!P�b4��� �{S�����X����.�囤���T��hEF��X�q0"-<����h���]�Py*����F⩍��@v�˂�Y08�� .q��a��s����(!<̫1�3�L�H��7sYW�`��qtu�\7��?�@�Y�� %Ka�x�GZ�*W�P��y�����N0r9��Z�c�%���q,��k�����!!,��>���IB��� �x1�Xu�Y���v-���ֺ��N������JP��a�2`�e5��w��u;�6�i���̃��(K���ťa��(l51��JL��O'%���]���ٖ뿉!��{*�p+f ���i8��D�ȑ���ܩ�M��V��ӟz��x�7Z�1i}�^͜���6e����x��)u�d�ˏ�V�eG�\�X1�����=n�U'�~Y����L�\,�(d!x ,�:�TW8� M`r���@��r+v�Q0��>^;˴�VbF��('����� �*O��i��j�Ӆ����^�S3&� ���{������.ی�� N;��NU%d0�Ce\r"�C�b��&t7N�7��� �ȪD�[%l�۪�$��'m?�A9tI�9>��NVL ��� 6v~M�����ъ�B���0����9$&=ώm��W�0���L���&��E���f�f��'+�9��hv��7,���M��6�D�&�^� �����8 D֮�����o��k^z��O��hP�8q�5d*��YVq3�{��������#LX4�?��jP=3�~�؅c�ݰ�̱�ұ��8̲��2�G�����j��έ�9��w7���U�X�w�85C��?!I&���o&����L���I#�^�eV�,�^t5�k� �xs˛\��U�8��."���{���ǵ�l4��ݼ�;��r"���G�/~���gJV�N糦��ZZ^k+NN�D��I$�=OE�z����|*�*{��%k���G��>�`9��b;�s���8,�qs��c��.b��q�%�>r��n�R�Ƨ�%�,�A��le#�8���}; 21�0�b�&�QX�f���q�00����$>�h�N�'�a3��A���/�r ��L5�8�GԲ'�����w;��c#�q1���h$*��V^�k��QĽ�b:i������� ����H F#�_���,��]g����Ը����`RUU���� ��"�qD���>-��ϤI�~��3�̴�����NZ[[555�eeek7�m����YF#[��Đ��R��i��L�H�r ��@��J-�Pŝ��_|�-��6y��ks�V�U~��6���w.����(��0A� 4��f��� /���C�xŊ�ٳ����z=6�����rg���mKo��o�/����a�g���?'9%9��P��斓��~���L{�� �H��{AW��B��$����v�1b�&Mb�ر��ر#�0`�`xMBp! )Z�Nmo�mZ�g�}�eذaWTVV ���'99��C5��&�&+5�bT>|8��PUUETT����&���t��~TE%��'������b�tEGG;RSS�S�N�v��ѯ��t����u1@�ޚ"f��͈���r'L�Ph��m��ƌ�74o��`�x�q�P���NRSS�X,�����l&&&��MFFA!-��`��ҷ�n��Yuu�����x<I�LB%����KԒ50�!�3�bz�����ʸKL���;---�l6[��`��������Ȏ;�����egg4��!D�T��jWujyZ��������K����%����p�^���X,6��sV=�ܖ����6�3�X ���4ҿ��A2�&����_k�;d�� �VfOIEND�B`�#!/bin/sh set -e if test $# = 0 \ && test x"$SHIM_NOTRIGGER" = x \ && test x"$DPKG_MAINTSCRIPT_PACKAGE" != x \ && dpkg-trigger --check-supported 2>/dev/null then if dpkg-trigger --no-await shim-secureboot-policy; then if test x"$SHIM_TRIGGER_DEBUG" != x; then echo "shim: wrapper deferring policy update (trigger activated)" fi exit 0 fi fi if [ "$(id -u)" -ne 0 ]; then echo "$0: Permission denied" exit 1 fi do_enroll=0 do_toggle=0 efivars=/sys/firmware/efi/efivars secureboot_var=SecureBoot-8be4df61-93ca-11d2-aa0d-00e098032b8c moksbstatert_var=MokSBStateRT-605dab50-e046-4300-abb6-3dd810dd8b23 SB_KEY="/var/lib/shim-signed/mok/MOK.der" SB_PRIV="/var/lib/shim-signed/mok/MOK.priv" OLD_DKMS_LIST="/var/lib/shim-signed/dkms-list" NEW_DKMS_LIST="${OLD_DKMS_LIST}.new" touch $OLD_DKMS_LIST dkms_list=$(find /var/lib/dkms -maxdepth 1 -type d -print 2>/dev/null \ | LC_ALL=C sort) dkms_modules=$(echo "$dkms_list" | wc -l) . /usr/share/debconf/confmodule update_dkms_list() { echo "$dkms_list" > $NEW_DKMS_LIST } save_dkms_list() { mv "$NEW_DKMS_LIST" "$OLD_DKMS_LIST" } clear_new_dkms_list() { rm "$NEW_DKMS_LIST" } new_dkms_module() { # handle nvidia module specially because it changed path if ! grep -q "/var/lib/dkms/nvidia" "$OLD_DKMS_LIST" && grep -q "/var/lib/dkms/nvidia" "$NEW_DKMS_LIST" ; then # nvidia module is newly added return 0 fi # return 0 if there is any other new module env LC_ALL=C comm -1 -3 $OLD_DKMS_LIST $NEW_DKMS_LIST | grep -q -v "/var/lib/dkms/nvidia" } show_dkms_list_changes() { diff -u $OLD_DKMS_LIST $NEW_DKMS_LIST >&2 } validate_password() { db_capb if [ "$key" != "$again" ]; then db_fset shim/error/secureboot_key_mismatch seen false db_input critical shim/error/secureboot_key_mismatch || true STATE=$(($STATE - 2)) else length=$((`echo "$key" | wc -c` - 1)) if [ $length -lt 8 ] || [ $length -gt 16 ]; then db_fset shim/error/bad_secureboot_key seen false db_input critical shim/error/bad_secureboot_key || true STATE=$(($STATE - 2)) elif [ $length -ne 0 ]; then return 0 fi fi return 1 } clear_passwords() { # Always clear secureboot key. db_set shim/secureboot_key '' db_fset shim/secureboot_key seen false db_set shim/secureboot_key_again '' db_fset shim/secureboot_key_again seen false } toggle_validation() { local key="$1" local again="$2" echo "Enabling shim validation." printf '%s\n%s\n' "$key" "$again" | mokutil --enable-validation >/dev/null || true mokutil --timeout -1 >/dev/null || true } enroll_mok() { local key="$1" local again="$2" echo "Adding '$SB_KEY' to shim:" printf '%s\n%s\n' "$key" "$again" | mokutil --import "$SB_KEY" >/dev/null || true mokutil --timeout -1 >/dev/null || true } do_it() { STATE=1 db_settitle shim/title/secureboot while true; do case "$STATE" in 1) db_capb db_fset shim/secureboot_explanation seen false db_input critical shim/secureboot_explanation || true ;; 2) if [ "$do_toggle" -eq 1 ]; then # Force no backtracking here; otherwise the GNOME backend # might allow it due to displaying the explanation just before. # Fixes LP: #1767091 db_capb # Allow the user to skip toggling Secure Boot. db_fset shim/enable_secureboot seen false db_input critical shim/enable_secureboot || true db_go db_get shim/enable_secureboot if [ "$RET" = "false" ]; then break fi fi ;; 3) db_input critical shim/secureboot_key || true seen_key=$RET db_input critical shim/secureboot_key_again || true ;; 4) db_get shim/secureboot_key key="$RET" db_get shim/secureboot_key_again again="$RET" if [ -z "$key$again" ] && echo "$seen_key" | grep -q ^30; then echo "Running in non-interactive mode, doing nothing." >&2 if new_dkms_module; then show_dkms_list_changes clear_new_dkms_list exit 1 else exit 0 fi fi if validate_password; then if [ $do_toggle -eq 1 ]; then toggle_validation "$key" "$again" fi if [ $do_enroll -eq 1 ]; then enroll_mok "$key" "$again" fi save_dkms_list fi clear_passwords ;; *) break ;; esac if db_go; then STATE=$(($STATE + 1)) else STATE=$(($STATE - 1)) fi db_capb backup done db_capb } validate_actions() { # Validate any queued actions before we go try to do them. local moksbstatert=0 if ! [ -d $efivars ]; then echo "$efivars not found, aborting." >&2 exit 0 fi if ! [ -f $efivars/$secureboot_var ] \ || [ "$(od -An -t u1 $efivars/$secureboot_var | awk '{ print $NF }')" -ne 1 ] then echo "Secure Boot not enabled on this system." >&2 exit 0 fi if [ $dkms_modules -lt 2 ]; then echo "No DKMS modules installed." >&2 exit 0 fi if [ -f /proc/sys/kernel/moksbstate_disabled ]; then moksbstatert=$(cat /proc/sys/kernel/moksbstate_disabled 2>/dev/null || echo 0) elif [ -f $efivars/$moksbstatert_var ]; then # MokSBStateRT set to 1 means validation is disabled moksbstatert=$(od -An -t u1 $efivars/$moksbstatert_var | \ awk '{ print $NF; }') fi # We were asked to enroll a key. This only makes sense if validation # is enabled. if [ $do_enroll -eq 1 ] && [ $moksbstatert -eq 1 ]; then do_toggle=1 fi } create_mok() { if [ -e "$SB_KEY" ]; then return fi echo "Generating a new Secure Boot signing key:" openssl req -config /usr/lib/shim/mok/openssl.cnf \ -subj "/CN=`hostname -s | cut -b1-31` Secure Boot Module Signature key" \ -new -x509 -newkey rsa:2048 \ -nodes -days 36500 -outform DER \ -keyout "$SB_PRIV" \ -out "$SB_KEY" } update_dkms_list case "$1" in '--enable'|'--disable') echo "Please run mokutil directly to change shim validation behavior." exit 0 ;; '--new-key') create_mok exit 0 ;; '--enroll-key') if [ -e "$SB_KEY" ]; then if mokutil --test-key "$SB_KEY" | \ grep -qc 'is not'; then do_enroll=1 fi else echo "No MOK found." exit 1 fi ;; *) echo "update-secureboot-policy: toggle UEFI Secure Boot in shim" echo echo "\t--new-key\tCreate a new MOK." echo "\t--enroll-key\tEnroll the new MOK for this system in shim." echo "\t--help\t\tThis help text." exit 0 esac validate_actions if [ $(($do_toggle + $do_enroll)) -lt 1 ]; then echo "Nothing to do." exit 0 fi do_it exit 0