[Documentation]: Guidance for OEM self-generation of Secure Boot variable contents and append updates
@SochiOgbuanya 已经在做这个了。
开始于 2025年12月16日。
评估
这个 Issue 还没有评估数据。
描述
Request Description
Hello,
We're using secureboot_objects to generate our own KEK/db/dbx contents for VMs running on the XCP-ng hypervisor. During this process, we've run into a few issues:
- https://github.com/microsoft/secureboot_objects/commit/e64d1a5c89e5bc851f72297ab8979a5cec0ffd20 has changed all current templates to point to
dbx_info_msft_latest.jsoninstead of recommending to ship an empty dbx by default. Is this an intentional change? - LegacyFirmwareDefaults.toml suggests to use our own signature owner GUID. Yet WHCP instructs that the MS GUID be used for KEK, without a mention of timestamp. So what's the signature owner and timestamp we should use in our generated SB databases (KEK/db/dbx)?
- Self-generated dbx databases are not append-compatible with the signed versions. In other words, even if we shipped our own dbx, Windows will append its own signed database to the dbx variable. This would quickly consume all of the dbx variable's available space and cause subsequent updates to fail. Do you have any guidance on how to avoid this issue?
- Similarly, are the signed versions append-compatible with what Windows uses to update the dbx? Will there be issues with duplicate EFI_SIGNATURE_DATA if the signed version was shipped?
A final note: We hope that the Secure Boot objects could be shipped under a permissive license (e.g. BSD) that allows us to ship these objects in open-source projects.
Are you going to make the change?
Someone else needs to make the change
Do you need maintainer feedback?
Maintainer feedback requested
Anything else?
No response
- 主要语言
- Python
- 星标
- 289
- 派生
- 89
- 平均合并
- 2 天 8 小时
- 30 天内合并 PR
- 5
环境准备
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
microsoft/secureboot_objects 的其他 Issue
-
难度 5/5 一周以上 新手友好度 35/100
microsoft/secureboot_objects#471 ·
-
state:needs-owner state:needs-triage type:bug urgency:high
难度 4/5 3-5 天 新手友好度 55/100
microsoft/secureboot_objects#467 · 3 条评论 ·
-
state:needs-triage type:feature-request urgency:low
难度 3/5 1-2 天 新手友好度 55/100
microsoft/secureboot_objects#466 ·
-
state:needs-triage type:feature-request urgency:low
难度 4/5 3-5 天 新手友好度 48/100
microsoft/secureboot_objects#462 · 3 条评论 ·
-
state:needs-owner state:needs-triage type:bug urgency:low
难度 3/5 1-2 天 新手友好度 68/100
microsoft/secureboot_objects#424 · 6 条评论 ·
查看 microsoft/secureboot_objects 的全部 Issue
相似的 Issue
-
难度 1/5 1 小时以内 新手友好度 92/100
raullenchai/Rapid-MLX#4042 ·
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 78/100
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 84/100
LearningCircuit/local-deep-research#7067 ·
维护者通常 1 天内回复
-
#bug
难度 1/5 1 小时以内 新手友好度 92/100
apache/superset#44923 · 1 条评论 ·
维护者通常 2 天内回复
-
难度 2/5 1-3 小时 新手友好度 84/100
lawndoc/stack-back#123 ·