17 lines
735 B
INI
17 lines
735 B
INI
[Unit]
|
|
Description=Secure Boot updates for DB and DBX
|
|
ConditionPathExists=/sys/firmware/efi/efivars/db-d719b2cb-3d3a-4596-a3bc-dad00e67656f
|
|
|
|
[Service]
|
|
Type=oneshot
|
|
ExecStartPre=-/usr/bin/chattr -i /sys/firmware/efi/efivars/KEK-8be4df61-93ca-11d2-aa0d-00e098032b8c
|
|
ExecStartPre=-/usr/bin/chattr -i /sys/firmware/efi/efivars/db-d719b2cb-3d3a-4596-a3bc-dad00e67656f
|
|
ExecStartPre=-/usr/bin/chattr -i /sys/firmware/efi/efivars/dbx-d719b2cb-3d3a-4596-a3bc-dad00e67656f
|
|
ExecStart=/usr/bin/sbkeysync --no-default-keystores --keystore /usr/share/secureboot/updates --verbose
|
|
# This is expected to fail with some firmware, but that shouldn't cause
|
|
# this unit to fail. See LP: #1892797.
|
|
SuccessExitStatus=1
|
|
|
|
[Install]
|
|
WantedBy=multi-user.target
|