Skip to content

v1.6.0

Choose a tag to compare

@github-actions github-actions released this 20 Oct 03:51

⚠️ IMPORTANT

Signed DBX and Revocations have been updated to include the revocations for Igel* - see #272

Updating post signed folder with signed DB update packages for 3P UEFI CA and Option ROM CA - see
#226

Bumping SVN revocation for Windows bootmgr from 5 to 7 - see
#263

What's Changed

  • Updating Post signed DBX folder with latest revocation of vulnerable IGEL shims SochiOgbuanya (#272)
    Change Details
      ## Description

    Secure Boot Bypass due to vulnerable IGEL Linux shims

    Attacker who has gained physical access to the device can plant vulnerable shims that allow loading older Linux loader which in turn loads unsigned Kernel. It is integrity bypass for boot code.

    • Impacts functionality?
    • Impacts security?
    • Breaking change?
    • Includes tests?
    • Includes documentation?

    How This Was Tested

    Verified by trying to boot using vulnerable IGEL boot module to ensure the modules are blocked from booting on Secure boot enabled system

    Integration Instructions

    N/A

      </blockquote>
      <hr>
    </details>
    
  • Clean up Post Signed Objects Branch Doug Flick (@Flickdm) (#265)
    Change Details
      ## Description

    Cleaning up documentation to point to the Wiki.

    Additionally,

    • Deleted uncessary copy of kek_update_map.json
    • Fixing auth_var_tool.py so it creates the output folder if it doesn't exist

    For details on how to complete these options and their meaning refer to CONTRIBUTING.md.

    • Impacts functionality?
    • Impacts security?
    • Breaking change?
    • Includes tests?
    • Includes documentation?

    How This Was Tested

    Local testing to verify functionality of wiki

    Integration Instructions

    N/A




  • Bumping SVN revocation for Windows bootmgr from 5 to 7 SochiOgbuanya (#263)
    Change Details
      ## Description

    Windows bootmgr svn revocation bumped from 5 to 7 as Windows Boot Manager can be rolled back to previous vulnerable version to trigger Secure boot rollback.

    For details on how to complete these options and their meaning refer to CONTRIBUTING.md.

    • Impacts functionality? No
    • Impacts security? Yes
    • Breaking change?
    • Includes tests? No
    • Includes documentation? No

    How This Was Tested

    Booted to latest Windows version and blocked affected versions

    Integration Instructions

    N/A

      </blockquote>
      <hr>
    </details>
    
  • Feature: Authenticated Variable Tooling Doug Flick (@Flickdm) (#236)
    Change Details
      ## Description This pull request introduces two major updates: a CLI utility for working with secure boot objects in the operating system and a test script to generate test certificates to debug and work with a platform. These scripts can be used to perform the full end to end secure boot workflow in two configurations - local signing, or remote signing.

    Full chain usage will be added to the WIKI and a link will be added here.

    How This Was Tested

    Local Testing on Devkit

    Integration Instructions

    N/A




  • Fix "Lable" misspelling in Make2023BootableMedia.ps1 @[copilot-swe-agent[bot]](https://github.com/apps/copilot-swe-agent) (#221)
    Change Details
      Fixed multiple spelling errors in the PowerShell script `Make2023BootableMedia.ps1`:

    Primary fix:

    • Corrected ISO_Lable to ISO_Label throughout the script (4 occurrences on lines 230, 718, 719, and 725)
    • This ensures consistency with the correctly spelled variable declaration on line 806

    Additional spelling corrections:

    • Fixed "Avalable" to "Available" in ADK requirement message (line 76)
    • Fixed "defualt" to "default" in comment (line 717)
    • Fixed "$ISOLable" to "$ISOLabel" in comment (line 717)

    The variable name inconsistency could have caused runtime errors when the script attempts to reference $global:ISO_Label but some parts of the code were setting $global:ISO_Lable. All variable references now use the correct spelling ISO_Label.

    Fixes #220.


    💡 You can make Copilot smarter by setting up custom instructions, customizing its development environment and configuring Model Context Protocol (MCP) servers. Learn more Copilot coding agent tips in the docs.




  • Updating Post signed folder with signed db update packages for 3P CAs. SochiOgbuanya (#226)
    Change Details
      ## Description

    Updating post signed folder with signed DB update packages for 3P UEFI CA and Option ROM CA

    Added db update packages for 3P UEFI CA 2023 and Option ROM CA 2023 to post signed folder.
    Moved older json to archives.

    • Impacts functionality?
    • Impacts security?
    • Breaking change?
    • Includes tests?
    • Includes documentation?

    How This Was Tested

    Updated on local machines and Richard Hughes (@hughsie) tested via fwupd

    Integration Instructions

    FIrmware does not require this payload however third party operating systems may




  • Create pipeline to validate DBX JSON certificate references @[copilot-swe-agent[bot]](https://github.com/apps/copilot-swe-agent) (#225)
    Change Details
      This PR implements a validation pipeline to ensure that DBX JSON files reference certificate files that actually exist in the `PreSignedObjects/DBX/Certificates` folder.

    Problem

    When new DBX JSON files are created, the internal certificate names referenced in the JSON don't always match the external filenames in the Certificates folder, and there was no validation to catch these mismatches. For example, the current dbx_info_msft_06_10_25.json references WindowsProduction2011.cer but the actual file is named MicWinProPCA2011_2011-10-19.der.

    Solution

    Added a new validation script and CI pipeline step that:

    1. Finds the latest DBX JSON file - Automatically locates dbx_info_msft_<date>.json files
    2. Validates certificate references - Checks that all certificates listed in the "certificates" array actually exist in the Certificates folder
    3. Provides clear error messages - Shows exactly which certificates are missing and lists available files for debugging
    4. Handles edge cases - Gracefully handles missing certificates sections, malformed JSON, etc.

    Changes Made

    New Files

    • scripts/validate_dbx_references.py - Main validation script with CLI interface
    • scripts/test_validate_dbx_references.py - Comprehensive unit tests (7 test cases)

    CI Integration

    • Added validation step to .github/workflows/prepare-binaries.yml after unit tests
    • Pipeline will now fail on PR/release if certificate references are invalid

    Other

    • Fixed .gitignore to properly exclude __pycache__ directories
    • Removed accidentally committed cache files

    Testing

    # Current mismatch is detected
    $ python scripts/validate_dbx_references.py PreSignedObjects/DBX
    ERROR: Certificate file 'WindowsProduction2011.cer' referenced in JSON but not found in PreSignedObjects/DBX/Certificates
    INFO: Available certificate files:
    INFO:   - MicWinProPCA2011_2011-10-19.der
    
    # All unit tests pass
    $ pytest scripts/test_validate_dbx_references.py
    7 passed in 0.01s

    The validation script successfully detects the existing mismatch and will prevent similar issues in the future through automated CI checks.

    Fixes #224.


    💡 You can make Copilot smarter by setting up custom instructions, customizing its development environment and configuring Model Context Protocol (MCP) servers. Learn more Copilot coding agent tips in the docs.




  • Make2023BootableMedia.ps1 handle spaces in ISOPath christophvw (#210)
    Change Details
      ## Description Make2023BootableMedia.ps1 handle spaces in ISOPath
      </blockquote>
      <hr>
    </details>
    
  • Fix dbx\_info\_msft\_06\_10\_25.json cert file name Tu Dinh (@dinhngtu) (#223)
    Change Details
      Fixes: eb36a97 ("Updating DBX update package with the latest revocations")

    Description

    eb36a97 broke the dbx_info.json certificate file name again.

    For details on how to complete these options and their meaning refer to CONTRIBUTING.md.

    • Impacts functionality?
    • Impacts security?
    • Breaking change?
    • Includes tests?
    • Includes documentation?

    How This Was Tested

    N/A

    Integration Instructions

    N/A

      </blockquote>
      <hr>
    </details>
    

Full Changelog: v1.5.1...v1.5.2

What's Changed

New Contributors

Full Changelog: v1.5.1...v1.6.0