Skip to content

[Secure Boot KEK Update] Microsoft PK-Signed KEK Update#399

Merged
Flickdm merged 1 commit intomicrosoft:mainfrom
Flickdm:upload/fixed-microsoft-bin
Apr 17, 2026
Merged

[Secure Boot KEK Update] Microsoft PK-Signed KEK Update#399
Flickdm merged 1 commit intomicrosoft:mainfrom
Flickdm:upload/fixed-microsoft-bin

Conversation

@Flickdm
Copy link
Copy Markdown
Member

@Flickdm Flickdm commented Apr 16, 2026

OEM Certificate Submission

OEM Name: Microsoft
Contact Email: sbkeyoem@microsoft.com

Certificate Details

  • Platform Key Thumbprint: b3bd98f4777241d721a96cd584dcb9d4b2098beb269c44442bdf609adce3b6c0
  • Expiration Date: [2014-4-24]

The expired certificate is not a problem for firmware.

Testing Completed

  • Windows validation (HyperV)
  • Linux validation

Security Review

  • No known security issues

Additional Notes

When this file was originally created, somehow it generated an invalid signature and would fail when applied.

This was corrected in Windows Update. However, I am publishing that change here to reflect that change.
There were additional changes required to support PK-Signed KEK updates for

HyperV that were a part of the March 3B release.

@Flickdm Flickdm requested review from Javagedes and apop5 April 16, 2026 23:34
@Flickdm Flickdm enabled auto-merge (rebase) April 17, 2026 00:24
@Flickdm Flickdm merged commit 29901a3 into microsoft:main Apr 17, 2026
6 checks passed
@Flickdm Flickdm deleted the upload/fixed-microsoft-bin branch April 17, 2026 00:33
@hughsie
Copy link
Copy Markdown

hughsie commented Apr 17, 2026

Mirrored to the LVFS as https://fwupd.org/lvfs/firmware/133107/

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants