Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

enroll-keys: Enroll Microsoft KEK along with their other keys #192

Merged
merged 1 commit into from
Feb 11, 2023

Conversation

alois31
Copy link
Contributor

@alois31 alois31 commented Jan 14, 2023

If enrolling the Microsoft db keys, also enroll their KEK. This allows applying the official dbx updates, which are important for security, as they allow blocking binaries with known vulnerabilities which Microsoft has signed in the past.

If enrolling the Microsoft db keys, also enroll their KEK. This allows
applying the official dbx updates, which are important for security, as
they allow blocking binaries with known vulnerabilities which Microsoft
has signed in the past.
@Foxboron
Copy link
Owner

Nice, this implements what I had in mind to include the KEK key. Thanks.

I'll try and get to testing this and give some feedback soon'ish :) Just have a long todo atm.

@Foxboron Foxboron merged commit 6868ff3 into Foxboron:master Feb 11, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants