microsoft / secureboot_objects

Secure boot objects recommended by Microsoft.
Other
35 stars 11 forks source link

CSV files of pre-signed objects missing some DBX hashes #137

Open ilyarooc opened 4 days ago

ilyarooc commented 4 days ago

Both dbx_info_msft_4_09_24.csv and dbx_info_uefi_org_7_18_23.csv files are missing some hashes, although these hashes are present in the signed binary DBX.

For example, some of the hashes from the Microsoft Security Advisory 2871690 article:

Of course, these files are not the actual source of the Secure Boot Forbidden Signature Database for a firmware. But it would be nice to have these CSV files up to date and reflecting the actual values in the DBX lists.

SochiOgbuanya commented 3 days ago

Still looking into the amd64 hashes, but for the x86 hash not included in both CSVs this is because there some hashes commented out (removed) of the DBX for devices that apply the dbx2024 update file to revoke the Windows Production PCA 2011 cert. This 363384D14D1F2E0B7815626484C459AD57A318EF4396266048D058C5A19BBF76 (exist in the x86/DBXUpdate.bin) + many others are now revoked by cert and not by hash.