(In reply to Joey Lee from comment #8) > The _real_ shim of TW is from latest Leap. The shim-leap be used to > repackage MS-signed shim from Leap. Currently the shim-leap only repackages > x86_64 shim. If we > want to support MS-signed shim on aarch64, then the spec file of shim-leap > must be modified for also repackage MS-signed shim from Leap aarch64. > > So, the shim of openSUSE Leap aarch64 must be sent to MS sign first. Then we > repackage it by shim-leap for TW aarch64. Thanks Joey for the detail information, that is reason why I filed the bug. If we have plan to support MS sign key. I can use the corresponding aavmf binaries then. Anyway, I can move on my tests with opensuse key.