Hello!
I am having trouble to find the SHIM version I have installed in my laptop with Zorin OS 18.1
I ran in Terminal the command: shim --version but it came back that the shim command was not found, and that I needed to install some library to be able to run it.
I installed the needed library, and ran the command again and this is what I got:
shim --version
Usage: shim < socket> < command>
I didn't get the SHIM version. What I am doing wrong?
Any help will be very much appreciated.
Thank you!
You could try it with mokutil. Type in Terminal one after the other:
mokutil --pk
mokutil --kek
mokutil --db
mokutil --dbx
I"ll try it.
Thank you!
It didn't work, a bunch of stuff came back, but not what I was looking for.
Is it this you are looking for?
~$ dpkg -l shim shim-signed
Gewünscht=Unbekannt/Installieren/R=Entfernen/P=Vollständig Löschen/Halten
| Status=Nicht/Installiert/Config/U=Entpackt/halb konFiguriert/
Halb installiert/Trigger erWartet/Trigger anhängig
|/ Fehler?=(kein)/R=Neuinstallation notwendig (Status, Fehler: GROSS=schlecht)
||/ Name Version Architektur Beschreibung
+++-==============-==================-============-==============================================================
un shim (keine Beschreibung vorhanden)
ii shim-signed 1.58+15.8-0ubuntu1 amd64 Secure Boot chain-loading bootloader (Microsoft-signed binary)
Hello!
Thank you for the information.
Is that the latest shim version?
How can I check it in my laptop?
What for an Output did You got?
I got these:
IdeaPad-Slim-3-15IAN8:~$ mokutil --pk
[key 1]
SHA1 Fingerprint: 5f:11:ee:cc:b1:03:36:e6:53:08:8c:ba:0a:bc:62:f2:53:32:71:a6
Certificate:
Data:
Version: 3 (0x2)
Serial Number:
(Negative)66:b0:74:ed:24:f3:72:4d:b6:91:28:f0:04:d2:26:ed
Signature Algorithm: sha256WithRSAEncryption
Issuer: CN=Trust - Lenovo Certificate
Validity
Not Before: Jun 20 02:16:47 2012 GMT
Not After : Dec 31 23:59:59 2039 GMT
Subject: CN=Ideapad Products
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
Public-Key: (2048 bit)
Modulus:
00:e1:ec:19:1d:f8:2e:40:a9:10:0b:22:6f:1c:5b:
99:8c:82:16:6b:52:69:f1:02:22:f7:dd:7b:32:e3:
17:79:32:6d:08:d9:ee:d2:f1:18:5b:aa:62:80:6d:
65:59:a5:92:36:0d:2a:52:78:7d:f6:1b:4a:2e:21:
2e:13:6a:f6:0d:24:dc:8b:d9:92:e1:b2:3b:3c:66:
1f:16:37:9f:d6:9d:c6:9e:1c:55:14:99:12:4b:1e:
7f:61:d3:0a:5b:d4:3f:e5:ed:89:e3:7a:42:58:5b:
e5:94:6d:77:6a:4c:6e:40:5d:d9:76:1f:fc:e6:54:
55:88:03:ec:f9:a6:73:eb:6b:5c:0e:a3:56:a3:41:
f8:4d:c3:a0:48:85:c9:2d:ed:5a:d1:bc:a7:e4:09:
64:cd:60:b6:f4:bd:5a:18:09:d1:12:f6:da:d1:8d:
ae:c9:a2:b6:df:af:57:f4:74:bb:fa:6b:50:9a:6c:
62:11:84:92:38:fe:76:b6:3d:b9:58:15:67:6d:7d:
c9:c9:39:60:73:f6:0f:0f:53:9c:e0:c7:74:1f:27:
6e:cc:69:2d:aa:f1:c4:ff:35:14:57:df:05:0a:4f:
7e:38:25:7c:cb:f5:c0:58:e4:8f:27:69:6c:ac:4a:
8b:d4:c9:83:df:f3:39:0e:e2:be:80:d5:b6:1d:3c:
a9:a9
Exponent: 65537 (0x10001)
X509v3 extensions:
2.5.29.1:
0M..b.~.....0...-.".'0%1#0!..U....Trust - Lenovo Certificate..^...k...@.F
...
Signature Algorithm: sha256WithRSAEncryption
Signature Value:
88:1d:46:75:74:67:2a:99:7a:f7:d1:91:5f:9e:5d:f1:5c:82:
72:64:6f:f3:71:44:f1:43:6d:f9:8c:63:74:ac:1c:f8:f5:fc:
f9:42:a9:cf:1b:57:01:6a:4c:4d:c0:67:57:fc:69:b3:2d:b5:
b6:a8:c0:6e:0c:13:e2:17:02:d9:99:a9:a1:bb:0c:12:cc:68:
22:ab:78:7c:d6:89:41:4c:b5:8f:53:0e:5d:9a:a5:bb:e4:da:
76:38:33:9a:f3:72:d0:de:f9:52:1a:69:67:b8:55:b9:4a:ff:
f1:a4:d3:32:29:98:95:cb:6c:42:82:7f:b6:83:35:c1:e5:aa:
ea:70:38:03:b5:76:2f:4a:b5:19:77:25:64:7d:d2:21:72:47:
d7:0c:50:32:c8:cc:4c:21:d2:b6:3b:61:5a:4d:f4:92:b6:1f:
5d:c2:1e:b9:79:4c:fb:25:f7:db:66:b8:e4:2c:3a:2b:14:fe:
9f:f4:92:a8:d3:51:f5:96:49:56:eb:7b:cb:cf:d6:ab:2f:36:
72:43:11:2c:f0:75:87:35:ce:e1:3a:13:d0:87:d6:bb:50:61:
dc:2e:9d:24:4f:10:ed:fe:93:c5:bd:78:ca:50:5f:13:a1:20:
60:d1:f2:52:0f:ba:01:42:b9:99:31:7e:16:59:5f:ef:b2:b4:
f2:54:27:65
IdeaPad-Slim-3-15IAN8:~$ mokutil --kek
[key 1]
SHA1 Fingerprint: 31:59:0b:fd:89:c9:d7:4e:d0:87:df:ac:66:33:4b:39:31:25:4b:30
Certificate:
Data:
Version: 3 (0x2)
Serial Number:
61:0a:d1:88:00:00:00:00:00:03
Signature Algorithm: sha256WithRSAEncryption
Issuer: C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Corporation Third Party Marketplace Root
Validity
Not Before: Jun 24 20:41:29 2011 GMT
Not After : Jun 24 20:51:29 2026 GMT
Subject: C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Corporation KEK CA 2011
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
Public-Key: (2048 bit)
Modulus:
00:c4:e8:b5:8a:bf:ad:57:26:b0:26:c3:ea:e7:fb:
57:7a:44:02:5d:07:0d:da:4a:e5:74:2a:e6:b0:0f:
ec:6d:eb:ec:7f:b9:e3:5a:63:32:7c:11:17:4f:0e:
e3:0b:a7:38:15:93:8e:c6:f5:e0:84:b1:9a:9b:2c:
e7:f5:b7:91:d6:09:e1:e2:c0:04:a8:ac:30:1c:df:
48:f3:06:50:9a:64:a7:51:7f:c8:85:4f:8f:20:86:
ce:fe:2f:e1:9f:ff:82:c0:ed:e9:cd:ce:f4:53:6a:
62:3a:0b:43:b9:e2:25:fd:fe:05:f9:d4:c4:14:ab:
11:e2:23:89:8d:70:b7:a4:1d:4d:ec:ae:e5:9c:fa:
16:c2:d7:c1:cb:d4:e8:c4:2f:e5:99:ee:24:8b:03:
ec:8d:f2:8b:ea:c3:4a:fb:43:11:12:0b:7e:b5:47:
92:6c:dc:e6:04:89:eb:f5:33:04:eb:10:01:2a:71:
e5:f9:83:13:3c:ff:25:09:2f:68:76:46:ff:ba:4f:
be:dc:ad:71:2a:58:aa:fb:0e:d2:79:3d:e4:9b:65:
3b:cc:29:2a:9f:fc:72:59:a2:eb:ae:92:ef:f6:35:
13:80:c6:02:ec:e4:5f:cc:9d:76:cd:ef:63:92:c1:
af:79:40:84:79:87:7f:e3:52:a8:e8:9d:7b:07:69:
8f:15
Exponent: 65537 (0x10001)
X509v3 extensions:
1.3.6.1.4.1.311.21.1:
...
X509v3 Subject Key Identifier:
62:FC:43:CD:A0:3E:A4:CB:67:12:D2:5B:D9:55:AC:7B:CC:B6:8A:5F
1.3.6.1.4.1.311.20.2:
.
.S.u.b.C.A
X509v3 Key Usage:
Digital Signature, Certificate Sign, CRL Sign
X509v3 Basic Constraints: critical
CA:TRUE
X509v3 Authority Key Identifier:
45:66:52:43:E1:7E:58:11:BF:D6:4E:9E:23:55:08:3B:3A:22:6A:A8
X509v3 CRL Distribution Points:
Full Name:
URI:http://crl.microsoft.com/pki/crl/products/MicCorThiParMarRoo_2010-10-05.crl
Authority Information Access:
CA Issuers - URI:http://www.microsoft.com/pki/certs/MicCorThiParMarRoo_2010-10-05.crt
Signature Algorithm: sha256WithRSAEncryption
Signature Value:
d4:84:88:f5:14:94:18:02:ca:2a:3c:fb:2a:92:1c:0c:d7:a0:
d1:f1:e8:52:66:a8:ee:a2:b5:75:7a:90:00:aa:2d:a4:76:5a:
ea:79:b7:b9:37:6a:51:7b:10:64:f6:e1:64:f2:02:67:be:f7:
a8:1b:78:bd:ba:ce:88:58:64:0c:d6:57:c8:19:a3:5f:05:d6:
db:c6:d0:69:ce:48:4b:32:b7:eb:5d:d2:30:f5:c0:f5:b8:ba:
78:07:a3:2b:fe:9b:db:34:56:84:ec:82:ca:ae:41:25:70:9c:
6b:e9:fe:90:0f:d7:96:1f:e5:e7:94:1f:b2:2a:0c:8d:4b:ff:
28:29:10:7b:f7:d7:7c:a5:d1:76:b9:05:c8:79:ed:0f:90:92:
9c:c2:fe:df:6f:7e:6c:0f:7b:d4:c1:45:dd:34:51:96:39:0f:
e5:5e:56:d8:18:05:96:f4:07:a6:42:b3:a0:77:fd:08:19:f2:
71:56:cc:9f:86:23:a4:87:cb:a6:fd:58:7e:d4:69:67:15:91:
7e:81:f2:7f:13:e5:0d:8b:8a:3c:87:84:eb:e3:ce:bd:43:e5:
ad:2d:84:93:8e:6a:2b:5a:7c:44:fa:52:aa:81:c8:2d:1c:bb:
e0:52:df:00:11:f8:9a:3d:c1:60:b0:e1:33:b5:a3:88:d1:65:
19:0a:1a:e7:ac:7c:a4:c1:82:87:4e:38:b1:2f:0d:c5:14:87:
6f:fd:8d:2e:bc:39:b6:e7:e6:c3:e0:e4:cd:27:84:ef:94:42:
ef:29:8b:90:46:41:3b:81:1b:67:d8:f9:43:59:65:cb:0d:bc:
fd:00:92:4f:f4:75:3b:a7:a9:24:fc:50:41:40:79:e0:2d:4f:
0a:6a:27:76:6e:52:ed:96:69:7b:af:0f:f7:87:05:d0:45:c2:
ad:53:14:81:1f:fb:30:04:aa:37:36:61:da:4a:69:1b:34:d8:
68:ed:d6:02:cf:6c:94:0c:d3:cf:6c:22:79:ad:b1:f0:bc:03:
a2:46:60:a9:c4:07:c2:21:82:f1:fd:f2:e8:79:32:60:bf:d8:
ac:a5:22:14:4b:ca:c1:d8:4b:eb:7d:3f:57:35:b2:e6:4f:75:
b4:b0:60:03:22:53:ae:91:79:1d:d6:9b:41:1f:15:86:54:70:
b2:de:0d:35:0f:7c:b0:34:72:ba:97:60:3b:f0:79:eb:a2:b2:
1c:5d:a2:16:b8:87:c5:e9:1b:f6:b5:97:25:6f:38:9f:e3:91:
fa:8a:79:98:c3:69:0e:b7:a3:1c:20:05:97:f8:ca:14:ae:00:
d7:c4:f3:c0:14:10:75:6b:34:a0:1b:b5:99:60:f3:5c:b0:c5:
57:4e:36:d2:32:84:bf:9e
[key 2]
SHA1 Fingerprint: 45:9a:b6:fb:5e:28:4d:27:2d:5e:3e:6a:bc:8e:d6:63:82:9d:63:2b
Certificate:
Data:
Version: 3 (0x2)
Serial Number:
33:00:00:00:13:14:16:b8:61:6d:82:82:4b:00:00:00:00:00:13
Signature Algorithm: sha256WithRSAEncryption
Issuer: C=US, O=Microsoft Corporation, CN=Microsoft RSA Devices Root CA 2021
Validity
Not Before: Mar 2 20:21:35 2023 GMT
Not After : Mar 2 20:31:35 2038 GMT
Subject: C=US, O=Microsoft Corporation, CN=Microsoft Corporation KEK 2K CA 2023
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
Public-Key: (2048 bit)
Modulus:
00:e3:5e:88:8b:73:2c:c3:0a:c4:e9:f5:ce:81:2d:
f1:0f:f1:26:35:37:d1:49:53:71:b1:5b:93:52:af:
e1:15:df:de:8b:39:bd:af:4c:65:75:53:e5:da:0a:
32:98:2f:33:26:b6:2b:be:94:99:9f:ec:da:c2:8e:
05:34:92:13:0f:63:bf:74:a2:72:a8:29:7e:9f:32:
21:29:08:59:c4:77:c4:2a:92:4c:87:b6:03:37:eb:
9a:e2:c3:c9:b4:48:21:c3:61:94:ea:17:51:b1:e7:
14:e2:24:63:2e:d5:f2:c6:a5:f2:a2:5e:1f:69:c6:
51:0d:a7:29:fb:52:0a:9b:e3:88:e8:68:ff:bb:fa:
92:69:af:c4:16:ff:5d:e5:5f:e0:df:ec:66:55:0b:
61:c2:ac:3b:20:6e:df:b4:0d:eb:2b:c8:d0:c2:34:
4e:82:96:39:ee:f1:31:85:04:3d:ef:d6:76:fb:c3:
ca:c1:d5:8c:2f:0b:10:28:9b:48:9a:b0:10:14:a4:
d9:94:e5:68:5b:cd:6e:e7:7a:ec:bc:a0:49:b8:a9:
53:d8:4d:2f:b2:7b:c8:da:bc:b2:e7:fc:ab:70:10:
77:95:45:49:fd:ad:d2:3f:17:cb:66:9a:f2:7d:36:
dd:0a:2c:e2:c0:87:21:2d:93:db:08:96:d2:e8:5c:
54:e1
Exponent: 65537 (0x10001)
X509v3 extensions:
X509v3 Key Usage: critical
Digital Signature, Certificate Sign, CRL Sign
1.3.6.1.4.1.311.21.1:
...
X509v3 Subject Key Identifier:
E0:AB:72:BC:96:3E:FF:B8:66:9B:7D:10:5A:43:3E:5C:42:54:87:5F
1.3.6.1.4.1.311.20.2:
.
.S.u.b.C.A
X509v3 Basic Constraints: critical
CA:TRUE
X509v3 Authority Key Identifier:
84:44:86:06:00:98:3F:2C:AA:B3:C5:89:F3:AC:2E:C9:E6:9D:09:03
X509v3 CRL Distribution Points:
Full Name:
URI:http://www.microsoft.com/pkiops/crl/Microsoft%20RSA%20Devices%20Root%20CA%202021.crl
Authority Information Access:
CA Issuers - URI:http://www.microsoft.com/pkiops/certs/Microsoft%20RSA%20Devices%20Root%20CA%202021.crt
Signature Algorithm: sha256WithRSAEncryption
Birdman:
mokutil --kek
[key 1 ]
SHA1 Fingerprint: 31:59:0b:fd:89:c9:d7:4e:d0:87:df:ac:66:33:4b:39:31:25:4b:30
Certificate:
Data:
Version: 3 (0x2)
Serial Number:
61:0a:d1:88:00:00:00:00:00:03
Signature Algorithm: sha256WithRSAEncryption
Issuer: C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Corporation Third Party Marketplace Root
Validity
Not Before: Jun 24 20:41:29 2011 GMT
Not After : Jun 24 20:51:29 2026 GMT
Subject: C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Corporation KEK CA 2011
The old one. And the 2nd Key here seems to be the new one:
Birdman:
[key 2 ]
SHA1 Fingerprint: 45:9a:b6:fb:5e:28:4d:27:2d:5e:3e:6a:bc:8e:d6:63:82:9d:63:2b
Certificate:
Data:
Version: 3 (0x2)
Serial Number:
33:00:00:00:13:14:16:b8:61:6d:82:82:4b:00:00:00:00:00:13
Signature Algorithm: sha256WithRSAEncryption
Issuer: C=US, O=Microsoft Corporation, CN=Microsoft RSA Devices Root CA 2021
Validity
Not Before: Mar 2 20:21:35 2023 GMT
Not After : Mar 2 20:31:35 2038 GMT
Subject: C=US, O=Microsoft Corporation, CN=Microsoft Corporation KEK 2K CA 2023
I apologize for my ignorance, but where is the SHIM version there?
I just typed in Terminal:
apt search shim-signed
Finally I got the answer:
shim-signed/noble,now 1.58+15.8-0ubuntu1 amd64 [installed]
Secure Boot chain-loading bootloader (Microsoft-signed binary)
Thank you so much!!!