-
Notifications
You must be signed in to change notification settings - Fork 65
Open
Description
I think admins (myself included) have a lot of questions about the SB updates on Hyper-V and a new document specific to it is warranted (I think under https://aka.ms/getsecureboot would make sense to strengthen the already quality documentation there).
Some things to document (maybe a FAQ format) include:
- March CU requirements, what changed.
- Hotpatch vs coldpatch CU
- Version compatibility for HV hosts supporting KEK updates (Windows Server 2012R2 I think with ESU entitlements?)
- Gen 1 vs Gen 2 security posture
- Compare + contrast the "features" of the three secure boot templates
- Impacts of VMs with TPMs (and shielding)
- Guest operating systems supported (in theory it shouldn't matter, even linux VMs updating with fwupd should work....)
- Why is the PK expired?
- Do VMs created after the March LCU is applied automatically include the 2023 certs? Or which version/patch combinations of HV VMs include all 2023 certs/keys "out of the box"?
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels