[Documentation]: Guidance for OEM self-generation of Secure Boot variable contents and append updates
@SochiOgbuanya ya está trabajando en esto.
Desde el 16/12/2025.
Evaluación
Este issue todavía no se ha evaluado.
Descripción
Request Description
Hello,
We're using secureboot_objects to generate our own KEK/db/dbx contents for VMs running on the XCP-ng hypervisor. During this process, we've run into a few issues:
- https://github.com/microsoft/secureboot_objects/commit/e64d1a5c89e5bc851f72297ab8979a5cec0ffd20 has changed all current templates to point to
dbx_info_msft_latest.jsoninstead of recommending to ship an empty dbx by default. Is this an intentional change? - LegacyFirmwareDefaults.toml suggests to use our own signature owner GUID. Yet WHCP instructs that the MS GUID be used for KEK, without a mention of timestamp. So what's the signature owner and timestamp we should use in our generated SB databases (KEK/db/dbx)?
- Self-generated dbx databases are not append-compatible with the signed versions. In other words, even if we shipped our own dbx, Windows will append its own signed database to the dbx variable. This would quickly consume all of the dbx variable's available space and cause subsequent updates to fail. Do you have any guidance on how to avoid this issue?
- Similarly, are the signed versions append-compatible with what Windows uses to update the dbx? Will there be issues with duplicate EFI_SIGNATURE_DATA if the signed version was shipped?
A final note: We hope that the Secure Boot objects could be shipped under a permissive license (e.g. BSD) that allows us to ship these objects in open-source projects.
Are you going to make the change?
Someone else needs to make the change
Do you need maintainer feedback?
Maintainer feedback requested
Anything else?
No response
- Lenguaje dominante
- Python
- Estrellas
- 289
- Forks
- 89
- Merge medio
- 3 d 10 h
- PR fusionados (30 d)
- 7
Guía de contribución
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de microsoft/secureboot_objects
-
Dificultad 5/5 Más de una semana Aptitud para principiantes 35/100
microsoft/secureboot_objects#471 ·
-
state:needs-owner state:needs-triage type:bug urgency:high
Dificultad 4/5 3-5 días Aptitud para principiantes 55/100
microsoft/secureboot_objects#467 · 3 comentarios ·
-
state:needs-triage type:feature-request urgency:low
Dificultad 3/5 1-2 días Aptitud para principiantes 55/100
microsoft/secureboot_objects#466 ·
-
state:needs-triage type:feature-request urgency:low
Dificultad 4/5 3-5 días Aptitud para principiantes 48/100
microsoft/secureboot_objects#462 · 3 comentarios ·
-
state:needs-owner state:needs-triage type:bug urgency:low
Dificultad 3/5 1-2 días Aptitud para principiantes 68/100
microsoft/secureboot_objects#424 · 6 comentarios ·
Todos los issues de microsoft/secureboot_objects
Issues similares
-
bug
Dificultad 2/5 1-3 horas Aptitud para principiantes 75/100
xinnan-tech/xiaozhi-fde-talk#263 ·
-
rules
Dificultad 1/5 Menos de una hora Aptitud para principiantes 90/100
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 70/100
huggingface/Repo2RLEnv#163 · 1 comentario ·
-
Dificultad 1/5 Menos de una hora Aptitud para principiantes 95/100
huggingface/sentence-transformers#4074 ·
-
comp/dashboard invalid P3
Dificultad 2/5 1-3 horas Aptitud para principiantes 70/100
NousResearch/hermes-agent#121143 ·