Microsoft security update that blocks Black Lotus (and, incidentally, also blocks a *lot* of existing Windows boot media and recovery images - you do want to be careful in applying this, but I'm still kind of amazed this ended up being politically viable!) https://support.microsoft.com/en-us/topic/kb5025885-how-to-manage-the-windows-boot-manager-revocations-for-secure-boot-changes-associated-with-cve-2023-24932-41a975df-beb2-40c1-99a3-b3ff139f832d
KB5025885: How to manage the Windows Boot Manager revocations for Secure Boot changes associated with CVE-2023-24932 - Microsoft Support

@mjg59 same. i'd have thought i'd have been told in advance about this, too (i wasn't). and there's got to be some boot applications they missed. i'll check later (not at home right now)
@Rairii dbx revocation is purely of old bootloaders, for any that support policy management for boot apps they've just added a policy that prohibits loading *all* old boot apps

@mjg59 yeah i need to look at the cipolicy later

and double check the hashes, i'm SURE there's some missing.

thing is, there's a few boot environment quirks that may or may not have been considered too, i'll need to look further

@Rairii @mjg59 i think this is intended to be the advance notice, it says that they're not planning to have windows update automatically apply the revocations until q1 2024 (but are "looking for opportunities to accelerate this schedule" )
@leo @mjg59 i missed that. the fact they're going to automatically apply a dbx update that will break some windows install media EVEN WITH SECURE BOOT DISABLED (thanks to a bootmgr quirk) is hilarious
@Rairii @mjg59 wait, is the revocation list enforced even with secure boot disabled? huh
@leo @mjg59 since win10, yes (for dbx), and bootmgr sigchecks itself
@mjg59 I'm still not sure when to push the LVFS updates. We do check all the stuff in the ESP to make sure that nothing's going to get bricked, but that doesn't count recovery images...
@hughsie Honestly I think lining up with the Microsoft schedule of 2024 makes sense, but doing something to enable manual updates for people who have this sort of thing as part of their threat model

@mjg59 @hughsie

Right, but what happens if there are new revocations appended before 2024?

The list would need to be manually managed and not the one as-is from uefi.org?

@Foxboron @mjg59 I honestly can't see MS customers waiting that long.