Skip to content

[Secure Boot KEK Update] Microsoft PK-Signed KEK Update#398

Closed
Flickdm wants to merge 2 commits into
microsoft:mainfrom
Flickdm:upload/fixed-microsoft-bin
Closed

[Secure Boot KEK Update] Microsoft PK-Signed KEK Update#398
Flickdm wants to merge 2 commits into
microsoft:mainfrom
Flickdm:upload/fixed-microsoft-bin

Conversation

@Flickdm
Copy link
Copy Markdown
Member

@Flickdm Flickdm commented Apr 16, 2026

Description

When this file was originally created, somehow it generated an invalid signature and would fail when applied.

This was corrected in Windows Update. However, I am publishing that change here to reflect that change.

For details on how to complete these options and their meaning refer to CONTRIBUTING.md.

  • Impacts functionality?
  • Impacts security?
  • Breaking change?
  • Includes tests?
  • Includes documentation?

How This Was Tested

Hyper-V

Integration Instructions

There were additional changes required to support PK-Signed KEK updates for HyperV that were a part of the March 3B release.

@Flickdm Flickdm closed this Apr 16, 2026
@hughsie
Copy link
Copy Markdown

hughsie commented Apr 24, 2026

@Flickdm this KEK fast-failed on the LVFS -- it's only working for ~20% of the 230 people that attempted it. I've attached the report JSON -- comparing the good:bad reports there are tiny differences like Intel Xeon Silver 4110 CPU @ 2.10GHz vs Intel Xeon CPU E5-2690 0 @ 2.90GHz -- both otherwise completely identical.

Most failures seem to be Read-only file system which could either be efivarfs being mounted ro (but then you'd expect that we'd see this failure for all the other KEK updates too) or that the "firmware" is returning with -EROFS when we attempt the write. Any ideas?

@hughsie
Copy link
Copy Markdown

hughsie commented Apr 24, 2026

export.json

@Flickdm
Copy link
Copy Markdown
Member Author

Flickdm commented Apr 28, 2026

@hughsie

https://support.microsoft.com/en-us/topic/known-issues-and-resolutions-for-secure-boot-certificates-updates-5813673d-2577-4718-ad28-2554a9178e40

This is a known issue that we're looking ito!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants