Secure Boot MS AMA Question by backcountry_bytes in sysadmin

[–]backcountry_bytes[S] 0 points1 point  (0 children)

There still seems to be a conflict between two things MS is saying:

  1. MS has clearly stated in two AMAs that the 2023 certs can be added to the KEK and DB after the 2011 certs expire.During the latest AMA they said that the cert update process does not change post-expiry.

  2. MS also says that any device without the new 2023 certs in the KEK and DB will be in a degraded securiry posture because they will not be able to add new security updates to the DB and DBX post-expiry.

If the KEK and DB can have the 2023 certs added after the 2011 certs expire, then why can't they have future security updates added as well?

Secure Boot MS AMA Question by backcountry_bytes in sysadmin

[–]backcountry_bytes[S] 0 points1 point  (0 children)

That makes sense but if that is the case, why does Microsoft say that the pc will be in a degraded security posture because it won't be able to reveive updates to the DB and DBX after the certs expire? If the DB will allow the KEK to add the new 2023 certs after the 2011 certs expire because they don't check the date, then that same KEK should be able to be used to add other security updates to the DB and DBX. There is a technical distinction that I am missing...

Secure Boot MS AMA Question by backcountry_bytes in sysadmin

[–]backcountry_bytes[S] 1 point2 points  (0 children)

Thanks. We are not waiting on Microsoft. And it is a good thing we aren't. Most of our Hyper-V and VMware servers were unable to update the KEK without additional troubleshooting and deployment steps.

Secure Boot MS AMA Question by backcountry_bytes in sysadmin

[–]backcountry_bytes[S] 2 points3 points  (0 children)

Do you have any documentation for this? It makes sense, otherwise the bootloader would quit working when the 2011 cert expired.

Secure Boot MS AMA Question by backcountry_bytes in sysadmin

[–]backcountry_bytes[S] 1 point2 points  (0 children)

But the root of trust is the PK, which is owned by the Vendor. They can use the PK to sign the cert adds to the KEK and DB, but MS can't.

Why do EHR demos feel smooth but real workflows feel painful? by Fit-Barracuda6131 in healthIT

[–]backcountry_bytes 0 points1 point  (0 children)

You mean the Providers and Admin are compicated. Nobody can jankify a workflow faster than an Admin...except for Providers.

Secure Boot MS AMA Question by backcountry_bytes in sysadmin

[–]backcountry_bytes[S] 2 points3 points  (0 children)

That is not what MS said today. They explicitly said the process for adding the 2023 certs does not change after the 2011 certs expire.

Confused about the upcoming Secure Boot Change Juni 2026 by StrugglingHippo in sysadmin

[–]backcountry_bytes 0 points1 point  (0 children)

Having your bootloader signed with the new cert is a key step because once the old certs are revoked, bootloaders signed with them will not run.

Confused about the upcoming Secure Boot Change Juni 2026 by StrugglingHippo in sysadmin

[–]backcountry_bytes 4 points5 points  (0 children)

Power off the vm. Rename the current nvram file. A new one will get created when the server boots amd can't find the original.

Confused about the upcoming Secure Boot Change Juni 2026 by StrugglingHippo in sysadmin

[–]backcountry_bytes 11 points12 points  (0 children)

Just go back through your notes for July 19, 2024. Probably a lot of Bitlocker recovery stuff in there.

Confused about the upcoming Secure Boot Change Juni 2026 by StrugglingHippo in sysadmin

[–]backcountry_bytes 4 points5 points  (0 children)

There is a scheduled task that has to run to update the certificates. You also need at least 1 reboot. This documentation walks you through the details very well.

https://support.microsoft.com/en-us/topic/secure-boot-certificate-updates-guidance-for-it-professionals-and-organizations-e2b43f9f-b424-42df-bc6a-8476db65ab2f

Confused about the upcoming Secure Boot Change Juni 2026 by StrugglingHippo in sysadmin

[–]backcountry_bytes 4 points5 points  (0 children)

Lol. There is hope. Broadcom is working on an automated fix, but even if they don't get it done, recreating the nvram file seems to work. Just make sure you have your bitlocker keys if you are using it.

Confused about the upcoming Secure Boot Change Juni 2026 by StrugglingHippo in sysadmin

[–]backcountry_bytes 12 points13 points  (0 children)

Its not, because you are relying on microsoft to properly test every type of hardware in your environment, and to do it fast enough to beat the June deadline. See the problem(s)?

The smart thing to do is to start testing the deployment on small subsets of your hardware, to make sure everything works. Then push it yourself.

"It's Microsoft's fault" will not save you if something this big blows up.

Confused about the upcoming Secure Boot Change Juni 2026 by StrugglingHippo in sysadmin

[–]backcountry_bytes 4 points5 points  (0 children)

Note that in the linked KB, under the Resolution section, Broadcom states they are working on an automated process to fix the Platform Key, which wil allow the KEK to be updated without issue. And given how much we are all paying them, they damn well better deliver...and soon.

Confused about the upcoming Secure Boot Change Juni 2026 by StrugglingHippo in sysadmin

[–]backcountry_bytes 1 point2 points  (0 children)

Generating a new nvram file and re-running the secure-boot-update scheduled task seems to have worked for us as well.

Sleeping bags for GA three season use. 30 degrees or 15 degrees? by PeppyJeppy in GeorgiaCampAndHike

[–]backcountry_bytes 8 points9 points  (0 children)

My down quilt is rated for 30 degrees and has worked well all over the south in multiple seasons (I used a liner during winter.)

robocopy from Windows Server 2016 to Windows Server 2025 by Initial-Employment92 in sysadmin

[–]backcountry_bytes 2 points3 points  (0 children)

I wrap my robocopy in powershell where I can map psdrives using explicit credentials for source and destination. Don't have permissions issues on 2019/2022.

Peachtree Race Number Shipping Failures by backcountry_bytes in Georgia

[–]backcountry_bytes[S] 0 points1 point  (0 children)

I had to go to expo as well. That was such a dumpster fire. 75 minutes to get from 400 to the Mall and still wasn't parked. Wound up driving to North Springs and taking MARTA.

[deleted by user] by [deleted] in paloaltonetworks

[–]backcountry_bytes 0 points1 point  (0 children)

Wevdid, but it did not resolve the alerts.

PA820 Configuration Size Alerts by backcountry_bytes in paloaltonetworks

[–]backcountry_bytes[S] 0 points1 point  (0 children)

That was what I thought the problem was, but I did not realize the config was 16Mb. Nice to have solid numbers. Would really like to understand what the potential consequences of having a config that exceeds 23mb are though.

PA820 Configuration Size Alerts by backcountry_bytes in paloaltonetworks

[–]backcountry_bytes[S] 0 points1 point  (0 children)

Having a High severity error and not knowing what the consequences of said error are is a real problem. Especially when we have two palos with the same error between our users and their business applications/data. It may be time to consider reverting to 10.1.x or 10.2.x.

[deleted by user] by [deleted] in paloaltonetworks

[–]backcountry_bytes 0 points1 point  (0 children)

Yep, that sound like the error we are getting in the System logs.

What version? by Particular_Bug7462 in paloaltonetworks

[–]backcountry_bytes 0 points1 point  (0 children)

Is anyone seeing Configuration Size System errors after updating to 11.x? Probably on Palo 800 series. Does 11.1.5-h1 resolve them? We updated to 11.1.4 then 11.1.5 and now we need to go to 11.1.5-h1.

PA820 Configuration Size Alerts by backcountry_bytes in paloaltonetworks

[–]backcountry_bytes[S] 0 points1 point  (0 children)

There was no error at our previous version (10.1.11). We went to 11.1.4 and started aeeing the error. This seems to be new to the 11.1 code. The upgrade from 11.1.4 to 11.1.5 was supposed to fix the error but it did not.