[Secure Boot KEK Update] Siemens PK-Signed KEK Update#402
[Secure Boot KEK Update] Siemens PK-Signed KEK Update#402wagnerdo wants to merge 1 commit intomicrosoft:mainfrom
Conversation
|
@wagnerdo please read the following Contributor License Agreement(CLA). If you agree with the CLA, please reply with the following information.
Contributor License AgreementContribution License AgreementThis Contribution License Agreement (“Agreement”) is agreed to by the party signing below (“You”),
|
|
I added a new check to my script because I when I was manually reviewing it I suspected this was a thing. For the same reasons I laid out here #374 (comment) having ContentInfo in your payload while technically not incorrect on firmware that's older may cause issues. I would recommend stripping the contentinfo off in the script I added in the PR and adding the file back and doing "git commit --amend --no-edit" and a "git push -f" |
de5549d to
603769b
Compare
603769b to
d476c36
Compare
Thanks. I noticed that commit f475aff referenced this, but was unsure whether I should apply it here as well. I did verify that our firmware will correctly process the file on a real device.
Done, and thanks for the script! I have no doubt that the resulting file will work, but I will double-check with a real device just to be sure. Might take until monday to complete the test though. As for CLA, clarification with Legal is ongoing and might take a while, so I expect this PR to remain in limbo for a bit. |
Yeah I personally have no doubt that the 19 bytes being removed won't impact if these binaries are successful. Its simply that you're more likely to be more successful (at least on older machines -- that you might not have without them). I assumed you used
Let me know when you're ready for me to merge this! |
|
https://github.com/microsoft/secureboot_objects/actions/runs/24857590443?pr=402 Confirmed -- Everything is green ✅ |
OEM Certificate Submission
OEM Name: Siemens AG
Contact Email: wagner.dominik@siemens.com
Certificate Details
75d67554b3f49e3e83108c6daa067873dab65984Testing Completed
Security Review
Additional Notes
I am responsible for this submission, thus I have supplied my personal mail as contact Email.
The official security contact is productcert@siemens.com
Testing was performed with FW version
V29.01.07.Windows: Windows 10 LTSC 2021 with BitLocker enabled using PowerShell as described in Wiki
Linux: Ubuntu 22.04.1 LTS using
efi-updatevaras described in Wiki