(repling to Gary Lin at comment #18) >unsigned shim without openssl patch Yes, that one works fine. I'm testing with secure-boot disabled, which I take to be what you wanted.