Skip to content

Commit 89f5a80

Browse files
committed
Updating Documentation for KEK Update Process
1 parent c2f1a36 commit 89f5a80

1 file changed

Lines changed: 23 additions & 4 deletions

File tree

‎PostSignedObjects/KEK/Readme.md‎

Lines changed: 23 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -2,8 +2,27 @@
22

33
These represent the KEK update files that Microsoft has been collecting from various OEMs.
44

5-
For Windows based systems these files will be automatically applied during regular
6-
Secure Boot servicing.
5+
## For OEMs
76

8-
For Linux based systems tooling like `fwupd` will automatically apply these during
9-
regular Secure Boot servicing.
7+
If you are an Original Equipment Manufacturer (OEM) and want to contribute your PK-signed KEK
8+
certificates to this repository, please visit:
9+
10+
**[https://github.com/microsoft/secureboot_objects/wiki/OEM-Certificate-Key-Rolling](https://github.com/microsoft/secureboot_objects/wiki/OEM-Certificate-Key-Rolling)**
11+
12+
This wiki page contains detailed instructions on:
13+
14+
- How to prepare your KEK certificates for submission
15+
- Required file formats and naming conventions
16+
- Validation procedures and requirements
17+
- The pull request submission process
18+
19+
### Important Notes
20+
21+
- **OEM Verification Required**: Microsoft reserves the right to deny pull requests if the
22+
contributor cannot be verified as a legitimate OEM
23+
- **Certificate Validation**: All submitted KEK certificates must be properly signed by the
24+
OEM's Platform Key (PK)
25+
- **Documentation**: Submissions must include proper documentation as described on the wiki
26+
27+
For questions about the submission process, please open an issue in this repository or contact
28+
Microsoft through official OEM channels.

0 commit comments

Comments
 (0)