diff --git a/debian/changelog b/debian/changelog index 53750d0b..ca90eaa9 100644 --- a/debian/changelog +++ b/debian/changelog @@ -1,3 +1,10 @@ +livecd-rootfs (2.664.42) UNRELEASED; urgency=medium + + * ubuntu-cpc: Install `shim-signed` and `grub-efi-arm64-signed` to enable + secureboot on ARM64 images (LP:#1980358) + + -- Ivan Kapelyukhin Thu, 30 Jun 2022 14:06:30 +0200 + livecd-rootfs (2.664.42) focal; urgency=medium * Switch intel-iot to use intel-iotg-edge, the 5.15 based IOTG kernel diff --git a/live-build/ubuntu-cpc/hooks.d/base/disk-image-uefi.binary b/live-build/ubuntu-cpc/hooks.d/base/disk-image-uefi.binary index b3f4613a..a619299b 100755 --- a/live-build/ubuntu-cpc/hooks.d/base/disk-image-uefi.binary +++ b/live-build/ubuntu-cpc/hooks.d/base/disk-image-uefi.binary @@ -117,7 +117,7 @@ install_grub() { # please file a bug against grub2 to include the affected module. case $ARCH in arm64) - chroot mountpoint apt-get -qqy install --no-install-recommends grub-efi-arm64 grub-efi-arm64-bin + chroot mountpoint apt-get -qqy install --no-install-recommends shim-signed grub-efi-arm64-signed efi_target=arm64-efi ;; armhf)