Skip to content

Microsoft's https://aka.ms/secure-boot-version-violation SVN Security Violation URL is still not operational #238

@pbatard

Description

@pbatard

Not sure if this is the best place to report this problem, but considering that this is related to Secure Boot revocation and that this repository is maintained by Microsoft, I hope you can redirect this to the relevant people.

More than 1 year ago, Microsoft introduced SVN as a revocation mechanism in their Windows UEFI bootloaders, that, similar to the Linux Shim's SBAT, allows bulk validation and revocation of bootloaders, without having to add individual UEFI bootloader hashes to the DBX.

When such a revocation occurs, the end-user is faced with a message similar to this one:

svn_error

The problem is that, after at least more than a year since this message has been part of Microsoft's UEFI bootloaders, the https://aka.ms/secure-boot-version-violation URL, that is referenced in the error screen, does not link to anything.

Considering that end-users very much can and do run in this error screen already (another recent example here), it is very problematic that the URL provided is invalid, as it makes a problem significantly worse.

We therefore ask that the Microsoft team in charge of Windows bootmgr (which is where this message comes from) takes care of making sure that the URL they included does resolve to a working page that explains to end users what Microsoft's SVN validation does, what conditions can lead to the error screen, and what kind of remediation users can bring, to avoid the error.

Thank you.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions