{
 "category": "security",
 "detail": {
  "path": "/var/lib/dkms/mok.pub",
  "sha256": "c66f9437ad3e37d73df5d75c17cf0061b30198bd5d51499dd66e06dbe1c843e3",
  "shipped_in": "4.1.0"
 },
 "evidence": [
  {
   "kind": "file",
   "note": "793 bytes",
   "ok": true,
   "source": "/usr/share/shadowfetch/security/shared-dkms-mok.sha256"
  },
  {
   "kind": "file",
   "note": "832 bytes",
   "ok": true,
   "source": "/var/lib/dkms/mok.pub"
  }
 ],
 "gated": false,
 "id": "sec.dkms_mok",
 "remedy": "This DKMS signing key shipped inside a Shadowfetch ISO with its private key, so every install from that ISO has it. If 'sudo mokutil --test-key /var/lib/dkms/mok.pub' says it is enrolled, run 'sudo mokutil --delete /var/lib/dkms/mok.pub', then 'sudo rm /var/lib/dkms/mok.key /var/lib/dkms/mok.pub', rebuild each module from 'dkms status' with 'sudo dkms build --force <module>/<version> && sudo dkms install --force <module>/<version>', run 'sudo mokutil --import /var/lib/dkms/mok.pub' for the new per-machine key and reboot (MOK Manager: Delete MOK, then Enroll MOK). If it is not enrolled, deleting the two files is enough. See the 5.0.0 release notes, Known issues.",
 "status": "fail",
 "summary": "/var/lib/dkms/mok.pub is the key shipped in the Shadowfetch 4.1.0 ISO and shared by every install from it",
 "title": "DKMS signing key is this machine's own"
}
