# Rocky 9.3, shim-x64, 15.8-2.el9

**URL:** <https://forums.rockylinux.org/t/rocky-9-3-shim-x64-15-8-2-el9/13570>\
**Category:** Rocky Linux Help & Support\
**Created:** [April 12, 2024, 1:21pm UTC](https://forums.rockylinux.org/t/rocky-9-3-shim-x64-15-8-2-el9/13570 "2024-04-12T13:21:07Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![gerry666uk](https://avatars.discourse-cdn.com/v4/letter/g/dbc845/32.png) [@gerry666uk](https://forums.rockylinux.org/u/gerry666uk)\
**Post date:** [April 12, 2024, 1:21pm UTC](https://forums.rockylinux.org/t/rocky-9-3-shim-x64-15-8-2-el9/13570/1 "2024-04-12T13:21:07Z")

</div>

Regarding the Rocky specific updates Apr 2024, will there be a new bootable ISO on the downloads page, e.g. Rocky 9.3 with the new shim and grub?

---

<div class="post-metadata">

**Author:** ![label](https://avatars.discourse-cdn.com/v4/letter/l/c5a1d2/32.png) [@label](https://forums.rockylinux.org/u/label)\
**Post date:** [April 12, 2024, 8:38pm UTC](https://forums.rockylinux.org/t/rocky-9-3-shim-x64-15-8-2-el9/13570/2 "2024-04-12T20:38:36Z")

</div>

There are currently no plans to make new ISO’s at this time. If it is found to be required, then we will do so.

The 8.10 and 9.4 betas are currently our focus (which will inevitably come with the updated versions of those packages). If there is found to be a need to recreate the 8.9 and 9.3 ISO’s before the general release of 8.10/9.4, we will create them. We also appreciate any feedback on issues using the current ISO’s, especially if something has gone wrong before then.

---

<div class="post-metadata">

**Author:** ![gerry666uk](https://avatars.discourse-cdn.com/v4/letter/g/dbc845/32.png) [@gerry666uk](https://forums.rockylinux.org/u/gerry666uk)\
**Post date:** [April 12, 2024, 9:45pm UTC](https://forums.rockylinux.org/t/rocky-9-3-shim-x64-15-8-2-el9/13570/3 "2024-04-12T21:45:15Z")

</div>

Anyone doing a clean install from tomorrow will end up with the old shim, grub etc. Do we know when 9.4 will be available? If it’s any day now, it won’t really matter…

---

<div class="post-metadata">

**Author:** ![gerry666uk](https://avatars.discourse-cdn.com/v4/letter/g/dbc845/32.png) [@gerry666uk](https://forums.rockylinux.org/u/gerry666uk)\
**Post date:** [April 13, 2024, 8:03am UTC](https://forums.rockylinux.org/t/rocky-9-3-shim-x64-15-8-2-el9/13570/4 "2024-04-13T08:03:50Z")

</div>

I’ve tested the new shim in the context of updating an installed system, but I want to test using bootable media, for example booting from an optical drive on real hardware, because shim works slightly differently from bootable media. I want to simultate a new user trying to install from nothing.

It’s not really practical to create a huge new 9.3 iso when 9.4 is not far off, so maybe I could create a bootable image using files from the installed system, but I don’t know how, maybe dracut (or something)?

---

<div class="post-metadata">

**Author:** ![jlehtone](https://avatars.discourse-cdn.com/v4/letter/j/e9a140/32.png) [@jlehtone](https://forums.rockylinux.org/u/jlehtone)\
**Post date:** [April 13, 2024, 8:09am UTC](https://forums.rockylinux.org/t/rocky-9-3-shim-x64-15-8-2-el9/13570/5 "2024-04-13T08:09:09Z")

</div>

> [@gerry666uk](#):
>
> Do we know when 9.4 will be available? If it’s any day now, it won’t really matter…

Logically, Rocky 9.4 will not be released _before_ RHEL 9.4 is out, and RHEL 9.4 is not out yet.

---

<div class="post-metadata">

**Author:** ![iwalker](https://sea2.discourse-cdn.com/flex020/user_avatar/forums.rockylinux.org/iwalker/32/2599_2.png) [@iwalker](https://forums.rockylinux.org/u/iwalker)\
**Post date:** [April 13, 2024, 8:09am UTC](https://forums.rockylinux.org/t/rocky-9-3-shim-x64-15-8-2-el9/13570/6 "2024-04-13T08:09:10Z")

</div>

> [@gerry666uk](#):
>
> Anyone doing a clean install from tomorrow will end up with the old shim, grub etc.

I must be missing something or not understanding, but why would that be a problem? You install 9.3 and then just run `dnf update` and you get the new shim/grub etc.

---

<div class="post-metadata">

**Author:** ![gerry666uk](https://avatars.discourse-cdn.com/v4/letter/g/dbc845/32.png) [@gerry666uk](https://forums.rockylinux.org/u/gerry666uk)\
**Post date:** [April 13, 2024, 8:22am UTC](https://forums.rockylinux.org/t/rocky-9-3-shim-x64-15-8-2-el9/13570/7 "2024-04-13T08:22:49Z")

</div>

> [@iwalker](#):
>
> You install 9.3 and then just run `dnf update`

Yes, it’s not a big problem when you already have a working system, but I want to simulate a new user installing onto bare metal to test the shim in the context of bootable media.

---

<div class="post-metadata">

**Author:** ![label](https://avatars.discourse-cdn.com/v4/letter/l/c5a1d2/32.png) [@label](https://forums.rockylinux.org/u/label)\
**Post date:** [April 13, 2024, 8:56am UTC](https://forums.rockylinux.org/t/rocky-9-3-shim-x64-15-8-2-el9/13570/8 "2024-04-13T08:56:25Z")

</div>

If you want to create a bootable ISO all by itself, you can use lorax to do this. (The DVD is a different story).

```auto
dnf install epel-release -y
crb enable
dnf install mock -y
mock -r rocky-9-x86_64 --init
mock -r rocky-9-x86_64 --install lorax lorax-templates-rocky lorax-templates-generic xorriso
mock -r rocky-9-x86_64 --shell --enable-network --isolation=simple
. . .
lorax --product="Rocky Linux" \
  --version="9.3" \
  --release="9.3" \
  --isfinal \
  --source=https://dl.rockylinux.org/pub/rocky/9.3/BaseOS/x86_64/os \
  --source=https://dl.rockylinux.org/pub/rocky/9.3/AppStream/x86_64/os \
  --variant="BaseOS" \
  --volid="Rocky-9-3-x86_64-dvd" \
  --buildarch="x86_64" \
  --rootfs-size=3 

```

This might get you somewhat close. You may have to make some tweaks here and there.

---

<div class="post-metadata">

**Author:** ![gerry666uk](https://avatars.discourse-cdn.com/v4/letter/g/dbc845/32.png) [@gerry666uk](https://forums.rockylinux.org/u/gerry666uk)\
**Post date:** [April 13, 2024, 12:37pm UTC](https://forums.rockylinux.org/t/rocky-9-3-shim-x64-15-8-2-el9/13570/9 "2024-04-13T12:37:39Z")

</div>

Thanks for the tip about lorax, it’s new to me, so it might take a while to get it working.

---

<div class="post-metadata">

**Author:** ![jbkt23](https://avatars.discourse-cdn.com/v4/letter/j/9fc29f/32.png) [@jbkt23](https://forums.rockylinux.org/u/jbkt23)\
**Post date:** [April 17, 2024, 11:01pm UTC](https://forums.rockylinux.org/t/rocky-9-3-shim-x64-15-8-2-el9/13570/10 "2024-04-17T23:01:58Z")

</div>

Unless I’m missing the intent here, could you not download the netinstall media and use that to create a new system using the latest in the Rocky repos? This is how I install all my systems.

---

<div class="post-metadata">

**Author:** ![gerry666uk](https://avatars.discourse-cdn.com/v4/letter/g/dbc845/32.png) [@gerry666uk](https://forums.rockylinux.org/u/gerry666uk)\
**Post date:** [April 18, 2024, 3:50pm UTC](https://forums.rockylinux.org/t/rocky-9-3-shim-x64-15-8-2-el9/13570/11 "2024-04-18T15:50:43Z")

</div>

The intent to to better understand the Apr 2024 updates in relation to shim and grub.

In all cases SecureBoot is ON.

The first thing I tested was using older bootable media on a machine with Rocky 9.3 and the Apr 2024 updates.

Test #1  
Rocky-8.5-x86\_64-dvd1.iso, FAIL, sbat violation, shim-x64-15.4-2.el8\_5.2.rocky.x86\_64.rpm

Test #2  
Rocky-9.0-x86\_64-dvd.iso, FAIL, sbat violation, shim-x64-15.4-2.el9.rocky.1.x86\_64.rpm

These two kind of make sense, the shim is older and has been revoked by the new shim.

BUT.

Test #3  
CentOS-8-x86\_64-1905-dvd1.iso, able to boot, shim-x64-15-8.el8.x86\_64.rpm, but it’s older than Rocky?

Test #4  
GParted debian, able to boot, but it’s from 2019, shim-signed-common 1.32+15+1533136590.3beb971-5

How on earch can the original CentOS 8.0 work when it’s much older than Rocky 8.5 and Rocky 9.0, and how can an ancient debian from 2019 still work??

---

<div class="post-metadata">

**Author:** ![jbkt23](https://avatars.discourse-cdn.com/v4/letter/j/9fc29f/32.png) [@jbkt23](https://forums.rockylinux.org/u/jbkt23)\
**Post date:** [April 18, 2024, 9:38pm UTC](https://forums.rockylinux.org/t/rocky-9-3-shim-x64-15-8-2-el9/13570/12 "2024-04-18T21:38:45Z")

</div>

In case 1 & 2 you said that Rocky revoked the prior CA certificate, how is that done?

In case 3 & 4 there is no indication that those old certs were revoked so why would they fail?

---

<div class="post-metadata">

**Author:** ![jlehtone](https://avatars.discourse-cdn.com/v4/letter/j/e9a140/32.png) [@jlehtone](https://forums.rockylinux.org/u/jlehtone)\
**Post date:** [April 19, 2024, 6:21am UTC](https://forums.rockylinux.org/t/rocky-9-3-shim-x64-15-8-2-el9/13570/13 "2024-04-19T06:21:10Z")

</div>

Look at `mokutil -X --list-enrolled`  
Does it list keys?

* * *

[EDIT]  
This is from Alma8 system, for illustration:

```auto
# mokutil --pk | grep Subject:
        Subject: C=US, ST=Texas, L=Round Rock, O=Dell Inc., CN=Dell Inc. Platform Key
# mokutil --kek | grep Subject:
        Subject: C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Corporation KEK CA 2011
# mokutil --db | grep Subject:
        Subject: C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Corporation UEFI CA 2011
        Subject: C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Production PCA 2011
        Subject: C=US, ST=California, L=Palo Alto, O=VMware, Inc.
        Subject: C=US, ST=California, L=Palo Alto, O=VMware, Inc., CN=VMware Secure Boot Signing
# mokutil --dbx | grep Subject:
# mokutil -l | grep Subject:
        Subject: serialNumber=5561017/jurisdictionC=US/jurisdictionST=Delaware/businessCategory=Private Organization, C=US, ST=Florida, O=AlmaLinux OS Foundation, CN=AlmaLinux OS Foundation
        Subject: C=US, ST=Florida, L=Fort Myers, O=AlmaLinux OS Foundation/serialNumber=5561017, CN=AlmaLinux OS Foundation/businessCategory=Private Organization/jurisdictionST=Delaware/jurisdictionC=US
# mokutil -Xl | grep Subject:
# 

```

The “pk/kek/db” keys were there from start. The installer must start with something (shim) signed by one of those keys, or it could not boot with Secure Boot on. The “enrolled” keys are from Alma and must have been enrolled by the installer without the manual step that the `mokutil --import` requires with, for example ELRepo/NVidia/RPMFusion/dkms keys.

Logically, the shim is signed with Microsoft’s key, the kernel with Rocky’s key, and the grubx64.efi probably by Rocky’s key. Naturally, the shim must then contain certificates/revokes that allows it to load the grubx64.efi.

---

<div class="post-metadata">

**Author:** ![gerry666uk](https://avatars.discourse-cdn.com/v4/letter/g/dbc845/32.png) [@gerry666uk](https://forums.rockylinux.org/u/gerry666uk)\
**Post date:** [April 19, 2024, 9:06am UTC](https://forums.rockylinux.org/t/rocky-9-3-shim-x64-15-8-2-el9/13570/14 "2024-04-19T09:06:45Z")

</div>

The most easy to understand article I can find about this is from ‘suse’.  
See Section 2.5 near the bottom of the TOC.

https://en.opensuse.org/openSUSE:UEFI

---

<div class="post-metadata">

**Author:** ![Sherif](https://sea2.discourse-cdn.com/flex020/user_avatar/forums.rockylinux.org/sherif/32/42_2.png) [@Sherif](https://forums.rockylinux.org/u/Sherif)\
**Post date:** [April 19, 2024, 10:06am UTC](https://forums.rockylinux.org/t/rocky-9-3-shim-x64-15-8-2-el9/13570/15 "2024-04-19T10:06:40Z")

</div>

So here are some points:

- Shim gets signed by MSFT , MSFT’s certs are in the firmware, vendors " like rocky " embed a CA cert into shim and generate certs to sign .EFI files such as kernelUKI, grub2, fwupd ,etc…
- If you are booting older iso with shim and grub2, that should boot as long as the DBX in firmware didn’t get updated " vendors and MSFT didn’t release any dbx update yet to revoke older shim" at least not until the current round of shim reviews, releases is sorted, otherwise, lots of vendors won’t be bootable unless secureboot is disabled
- You can install from the bootable media, then do dnf upgrade
- It is not about the “old” shim, it is about the revoked grub2, shim gets revoked from the firmware via DBX updates that includes the CA hash or the shim hash
- Shim revokes older grub2 " in our case " via the global number generation, current shim 15.8 will revoke any grub \< 3 or you can also build a shim dbx to revoke grub with hashes or certs
- I don’t know which shim centos uses on their bootable images, but I know it is really old, they already have a shim review open to get the new shim signed by MSFT

The issue of releasing new shims and new bootable media is an ongoing issue for vendors and they work it out based on how they see fit. Some vendors won’t even revoke anything via shim itself, but using external method to deliver a revocation mechanism  
Hope this explains things a little bit!

---

<div class="post-metadata">

**Author:** ![gerry666uk](https://avatars.discourse-cdn.com/v4/letter/g/dbc845/32.png) [@gerry666uk](https://forums.rockylinux.org/u/gerry666uk)\
**Post date:** [April 19, 2024, 7:47pm UTC](https://forums.rockylinux.org/t/rocky-9-3-shim-x64-15-8-2-el9/13570/16 "2024-04-19T19:47:58Z")

</div>

> [@Sherif](#):
>
> I don’t know which shim centos uses on their bootable images

My post #11 in this thread shows the shim versions next to each o/s.

---

<div class="post-metadata">

**Author:** ![gerry666uk](https://avatars.discourse-cdn.com/v4/letter/g/dbc845/32.png) [@gerry666uk](https://forums.rockylinux.org/u/gerry666uk)\
**Post date:** [May 9, 2024, 8:51pm UTC](https://forums.rockylinux.org/t/rocky-9-3-shim-x64-15-8-2-el9/13570/17 "2024-05-09T20:51:55Z")

</div>

I don’t know if it’s related, but an upgrade of RHEL 9.3 to 9.4 failed today on VMWare. It won’t boot at all. Could be our VMWare firmware is not right (or something).

It would be good if someone can test upgrading Rocky 9.3 to 9.4 on VMWare with secure boot enabled. But the shim in RHEL might not be identical to the one in Rocky anyway.

---

<div class="post-metadata">

**Author:** ![iwalker](https://sea2.discourse-cdn.com/flex020/user_avatar/forums.rockylinux.org/iwalker/32/2599_2.png) [@iwalker](https://forums.rockylinux.org/u/iwalker)\
**Post date:** [May 9, 2024, 8:57pm UTC](https://forums.rockylinux.org/t/rocky-9-3-shim-x64-15-8-2-el9/13570/18 "2024-05-09T20:57:24Z")

</div>

> [@gerry666uk](#):
>
> I don’t know if it’s related, but an upgrade of RHEL 9.3 to 9.4 failed today on VMWare. It won’t boot at all. Could be our VMWare firmware is not right (or something).

RHEL 9.4 works fine for me on VMware 8 Update 2. And this is also with secure boot enabled. Rocky 9.4 is not released yet, so can only be tested properly in due course when it’s released shortly.

---

<div class="post-metadata">

**Author:** ![label](https://avatars.discourse-cdn.com/v4/letter/l/c5a1d2/32.png) [@label](https://forums.rockylinux.org/u/label)\
**Post date:** [May 9, 2024, 11:38pm UTC](https://forums.rockylinux.org/t/rocky-9-3-shim-x64-15-8-2-el9/13570/19 "2024-05-09T23:38:04Z")

</div>

Secure boot is one of the many things that we test. One of our testers uses primarily vmware did not report any issues updating, booting, or installing systems.

---

<div class="post-metadata">

**Author:** ![gerry666uk](https://avatars.discourse-cdn.com/v4/letter/g/dbc845/32.png) [@gerry666uk](https://forums.rockylinux.org/u/gerry666uk)\
**Post date:** [May 10, 2024, 8:22am UTC](https://forums.rockylinux.org/t/rocky-9-3-shim-x64-15-8-2-el9/13570/20 "2024-05-10T08:22:29Z")

</div>

It turns out the RHEL 9.4 box that failed to boot was caused by a “Crowdstrike” process called “falcon-sensor”, so completely unrelated.

[Next page](https://forums.rockylinux.org/t/rocky-9-3-shim-x64-15-8-2-el9/13570.md?page=2)
