Microsoft's Secure Boot UEFI bootloader signing key expires in September, posing problems for Linux users
source: tomshardware.com/tech-industry…
It's up to manufacturers to make sure "the signature database (db), revoked signatures database (dbx), and Key Enrollment Key database (KEK)" are "stored on the firmware nonvolatile RAM (NV-RAM) at manufacturing time." The manufacturer then "locks the firmware from editing, except for updates that are signed with the correct key or updates by a physically present user who is using firmware menus, then generates a platform key (PK) [...] used to sign updates to the KEK or to turn off Secure Boot."
#boot #uefi #bios #microsoft #fail #problem #linux #update #firmware #future #bootloader
Microsoft's Secure Boot UEFI bootloader signing key expires in September, posing problems for Linux users
A new key was issued in 2023, but it might not be well-supported ahead of the original key's expiration.Nathaniel Mott (Tom's Hardware)
like this
reshared this