Post B4qpzDGjRIT2ItbtL6 by amy@sk.girlthi.ng
 (DIR) More posts by amy@sk.girlthi.ng
 (DIR) Post #B4qWAXs1BaesIfB1Ie by amy@sk.girlthi.ng
       0 likes, 0 repeats
       
       duck duck fedi (because a quick search didnt yield much)any fellow windows admins seeing a spike in bitlocker key issues in the past few days? keys not getting pulled out of the TPM so users see the recovery screen.boosts appreciated
       
 (DIR) Post #B4qWAY58Op9MxLJUkC by Rairii@labyrinth.zone
       0 likes, 0 repeats
       
       @amy systems taking the db update or a dbx update?
       
 (DIR) Post #B4qpzDGjRIT2ItbtL6 by amy@sk.girlthi.ng
       0 likes, 0 repeats
       
       @Rairii@labyrinth.zone which updates are those ​:neocat_think:​
       
 (DIR) Post #B4qpzDgxrlS1cFsqEC by Rairii@labyrinth.zone
       0 likes, 0 repeats
       
       @amy db update to allow the new rotated certsdbx update to revoke vvulnerable bootloaders
       
 (DIR) Post #B4qt1TJ74zfcUIUbWy by amy@sk.girlthi.ng
       0 likes, 0 repeats
       
       @Rairii@labyrinth.zone ahh those ones, we didn’t do it explicitly so maybe that would be an issue, though our devices are mostly new enough + it wasn’t secure boot as much as bitlocker but perhaps those updates tickled the firmware too much for the TPMs liking hmm
       
 (DIR) Post #B4qt1TZ47gQlHlxLOa by Rairii@labyrinth.zone
       0 likes, 0 repeats
       
       @amy TPM unseal depends on PCR7 which means db+dbx+the cert in db that verified the executed bootloader
       
 (DIR) Post #B4qw0c4TJHZzF0vUtU by amy@sk.girlthi.ng
       0 likes, 0 repeats
       
       @Rairii@labyrinth.zone not impossible this was it - where would they come from? we are running mainly lenovo fwiw. i dont suppose windows update could do it?
       
 (DIR) Post #B4qw0cHaWW4Tth3yL2 by Rairii@labyrinth.zone
       0 likes, 0 repeats
       
       @amy yeah, windows update can do it, but its supposed to suspend bitlocker for a couple of reboots to prevent this issue