Post B4qt1TZ47gQlHlxLOa by Rairii@labyrinth.zone
(DIR) More posts by Rairii@labyrinth.zone
(DIR) Post #B4qWAXs1BaesIfB1Ie by amy@sk.girlthi.ng
0 likes, 0 repeats
duck duck fedi (because a quick search didnt yield much)any fellow windows admins seeing a spike in bitlocker key issues in the past few days? keys not getting pulled out of the TPM so users see the recovery screen.boosts appreciated
(DIR) Post #B4qWAY58Op9MxLJUkC by Rairii@labyrinth.zone
0 likes, 0 repeats
@amy systems taking the db update or a dbx update?
(DIR) Post #B4qpzDGjRIT2ItbtL6 by amy@sk.girlthi.ng
0 likes, 0 repeats
@Rairii@labyrinth.zone which updates are those :neocat_think:
(DIR) Post #B4qpzDgxrlS1cFsqEC by Rairii@labyrinth.zone
0 likes, 0 repeats
@amy db update to allow the new rotated certsdbx update to revoke vvulnerable bootloaders
(DIR) Post #B4qt1TJ74zfcUIUbWy by amy@sk.girlthi.ng
0 likes, 0 repeats
@Rairii@labyrinth.zone ahh those ones, we didn’t do it explicitly so maybe that would be an issue, though our devices are mostly new enough + it wasn’t secure boot as much as bitlocker but perhaps those updates tickled the firmware too much for the TPMs liking hmm
(DIR) Post #B4qt1TZ47gQlHlxLOa by Rairii@labyrinth.zone
0 likes, 0 repeats
@amy TPM unseal depends on PCR7 which means db+dbx+the cert in db that verified the executed bootloader
(DIR) Post #B4qw0c4TJHZzF0vUtU by amy@sk.girlthi.ng
0 likes, 0 repeats
@Rairii@labyrinth.zone not impossible this was it - where would they come from? we are running mainly lenovo fwiw. i dont suppose windows update could do it?
(DIR) Post #B4qw0cHaWW4Tth3yL2 by Rairii@labyrinth.zone
0 likes, 0 repeats
@amy yeah, windows update can do it, but its supposed to suspend bitlocker for a couple of reboots to prevent this issue