Latest Windows update is messing up booting Linux operating systems

Moderator: Forum moderators

Post Reply
User avatar
bigpup
Moderator
Posts: 6819
Joined: Tue Jul 14, 2020 11:19 pm
Location: Earth, South Eastern U.S.
Has thanked: 866 times
Been thanked: 1469 times

Latest Windows update is messing up booting Linux operating systems

Post by bigpup »

If you are dual booting Windows and some version of Linux (like Puppy Linux).

With secure boot enabled in the computers UEFI bios settings.
---------------------------------------------------------------------------------------------------------------------------------------------------------

The latest update to Windows 10 and 11 has done something to not allow booting the Linux OS.

You will get this error when trying to boot Linux:

Verifiying shim SBAT data failed: Security Policy Violation Something has gone seriously wrong: SBAT self-check failed: Security Policy Violation

This is one way to fix this:
https://askubuntu.com/questions/1523438 ... -violation

Note:
This is not an issue, if you have secure boot disabled, in the computers UEFI bios settings.

I tried to find some good info on what SBAT is, but about all I got out of reading, was it is something used by secure boot, that now needs updated in the boot loader.

The things you do not tell us, are usually the clue to fixing the problem.
When I was a kid, I wanted to be older.
This is not what I expected :o

User avatar
rockedge
Site Admin
Posts: 6344
Joined: Mon Dec 02, 2019 1:38 am
Location: Connecticut,U.S.A.
Has thanked: 2529 times
Been thanked: 2509 times
Contact:

Re: Latest Windows update is messing up booting Linux operating systems

Post by rockedge »

checkout a previous discussion -> viewtopic.php?p=128936#p128936

There must be a fix coming from Microsoft soon, they had claimed in the documentation that the update would not effect dual booting Linux OS's

[Secure Boot Advanced Targeting (SBAT) and Linux Extensible Firmware Interface (EFI)] This update applies SBAT to systems that run Windows. This stops vulnerable Linux EFI (Shim bootloaders) from running. This SBAT update will not apply to systems that dual-boot Windows and Linux. After the SBAT update is applied, older Linux ISO images might not boot. If this occurs, work with your Linux vendor to get an updated ISO image.

User avatar
wiak
Posts: 3998
Joined: Tue Dec 03, 2019 6:10 am
Location: Packing - big job
Has thanked: 60 times
Been thanked: 1156 times
Contact:

Re: Latest Windows update is messing up booting Linux operating systems

Post by wiak »

Reading some MS docs concerning UEFI, secure boot, and Public Key Infrastructure two things become alarmingly clear. MS has incredible power over this whole scheme and whilst provision appears to have been made for Linux providers, at least for X86 and X86_64 based machines, it is far from clear to me that smaller Linux distros will always be provided for. I would certainly have no idea what MS tool, CA or whatever to use to sign a FR initrd if that became necessary.

The second concern is simply the complexity involved in all this chain of trust stuff. All sorts of mechanisms can be employed - seems advanced degree capability in that complex domain is needed to understand most of it. Yes there are some published shim tricks, but that just scratches the surface and should these mechanisms get blocked for their less secure simplicity, what happens to this forum then.

Of course some may imagine some here will always provide working methods - I am not convinced any of us could. So we may be at the mercy of what the likes of MS do... Is that the true Future of forum distro thread nightmare - will newer machines even allow turning off secure boot I wonder, like alone this threat from Windows updates on underlying UEFI firmware behaviour. All seems very fragile.

Older computers may become increasingly important to us.

Last edited by bigpup on Mon Aug 19, 2024 1:58 pm, edited 1 time in total.
Reason: spelling correction

https://www.tinylinux.info/
DOWNLOAD wd_multi for hundreds of 'distros' at your fingertips: viewtopic.php?p=99154#p99154
Αξίζει να μεταφραστεί;

User avatar
rockedge
Site Admin
Posts: 6344
Joined: Mon Dec 02, 2019 1:38 am
Location: Connecticut,U.S.A.
Has thanked: 2529 times
Been thanked: 2509 times
Contact:

Re: Latest Windows update is messing up booting Linux operating systems

Post by rockedge »

I would certainly have no idea what MS tool, CA or whatever to use to sign a FR initrd if that became necessary.

I have seen an example of using Void Linux's xbps-src tool to sign programs. Looks kind of like what would be needed but......
https://learn.microsoft.com/en-us/windo ... windows-11

I have been concerned that our ability to build kernels without signing the modules will be hampered and because the UEFI machines will be unable to boot "unsecured" kernels. So far it isn't but I also see that Microsoft has now enough control to lock machines into only Windows and it should be expected that they will go the next step. Comes down to we must continue on assembling these operating systems for holding onto the freedom of choice.

Older computers may become increasingly important to us.

Totally agree. And we have a collection of operating systems to keep them viable that we continue to assemble and distribute world wide.

geo_c
Posts: 2842
Joined: Fri Jul 31, 2020 3:37 am
Has thanked: 2137 times
Been thanked: 858 times

Re: Latest Windows update is messing up booting Linux operating systems

Post by geo_c »

rockedge wrote: Mon Aug 19, 2024 1:38 pm

I would certainly have no idea what MS tool, CA or whatever to use to sign a FR initrd if that became necessary.

I have seen an example of using Void Linux's xbps-src tool to sign programs. Looks kind of like what would be needed but......

I have been concerned that our ability to build kernels without signing the modules will be hampered and because the UEFI machines will be unable to boot "unsecured" kernels. So far it isn't but I also see that Microsoft has now enough control to lock machines into only Windows and it should be expected that they will go the next step. Comes down to we must continue on assembling these operating systems for holding onto the freedom of choice.

Older computers may become increasingly important to us.

Totally agree. And we have a collection of operating systems to keep them viable that we continue to assemble and distribute world wide.

From what I remember reading, but don't have links at hand, the trend in processors and devices is to be able to circumvent any attempt to run the device "off-the-grid" including things like using VPN's. The VPN's will work, but the processors and hardware chips will make them irrelevant in terms of surveillance.

Computer manufacturing is moving the way cars are moving, in that if one wants to operate independent from Big Tech, in other words one doesn't want a SMART car reporting their biometrics and driving habits to a central location, it will become increasingly difficult and one day perhaps illegal to own and operate one.

But at least with old computers, they will run offline. And that's something. I have a small collection of 6 desktops and 8 older laptops, but have often thought that I simply can't have enough old computers in this day and age. And for this reason I manage all my data off-line, so that I don't suddenly lose access to it by not using the "official" OS on the "official" device.

Last edited by geo_c on Mon Aug 19, 2024 2:37 pm, edited 4 times in total.

geo_c
Old School Hipster, and Such

User avatar
wiak
Posts: 3998
Joined: Tue Dec 03, 2019 6:10 am
Location: Packing - big job
Has thanked: 60 times
Been thanked: 1156 times
Contact:

Re: Latest Windows update is messing up booting Linux operating systems

Post by wiak »

Yes, we should certainly also protect any data that is important to us from potentially vanishing or tamperable cloud-only status ( i.e. the opposite to what big Tech encourages).

Old machines/technology may become underground anti Big Brother tools of immense importance to communities determined to avoid oppression and protect individuality, freedom to be different, and simple privacy.

Clarity seems to think we should embrace new technologies with optimism, but in some cases I'm far from convinced that is wise.

Indeed I still think the nuclear bomb was an inevitably bad idea for long term likely future. And AI? And have smart phones improved our social behaviors during their relatively short existence in our daily lives? Or the internet more generally; do we have more free time as a result?

https://www.tinylinux.info/
DOWNLOAD wd_multi for hundreds of 'distros' at your fingertips: viewtopic.php?p=99154#p99154
Αξίζει να μεταφραστεί;

User avatar
mikewalsh
Moderator
Posts: 6017
Joined: Tue Dec 03, 2019 1:40 pm
Location: King's Lynn, UK
Has thanked: 732 times
Been thanked: 1892 times

Re: Latest Windows update is messing up booting Linux operating systems

Post by mikewalsh »

This whole issue has merely reinforced my view on running Windows, AND the advice I shall continue to give to anyone who has a NEED to use the one OS alongside a desire to run the other; if there's any way on God's green earth you can do so, keep Windows and Linux totally separate. And that MEANS on separate machines. Less hassle all round.

Windows, unfortunately, NEEDS reasonably powerful hardware to function in anything approaching a usable manner. Linux requirements are nowhere near so steep. In either case, there's a ton of reasonably-priced refurbs out there that should cover all the bases....

(*shrug...*)

Mike. Image

User avatar
Jasper
Posts: 1813
Joined: Wed Sep 07, 2022 1:20 pm
Has thanked: 766 times
Been thanked: 421 times

Re: Latest Windows update is messing up booting Linux operating systems

Post by Jasper »

Microsoft has published a solution to this issue:
.
https://learn.microsoft.com/en-us/windo ... ue-details

Last edited by bigpup on Wed Aug 28, 2024 9:33 pm, edited 1 time in total.
Reason: changed web address to clickable link (in the forum a web address is seen as a clickable link)
redquine
Posts: 40
Joined: Sat Jun 13, 2020 12:38 pm
Has thanked: 116 times
Been thanked: 10 times

Re: Latest Windows update is messing up booting Linux operating systems

Post by redquine »

Thanks, Jasper. Definitely worth keeping a note of that!

We are investigating the issue with our Linux partners and will provide an update when more information is available.

Hmm... looks like they might have published a workaround because they've realised the move could hurt their own pockets. Their relationship with Linux grows murkier by the day.

I briefly thought my HP Stream was safe as it's not eligible for upgrade to Windows 11. Unfortunately, I see the issue also affects Windows 10 versions 22H2 & 21H2 and Windows 10 Enterprise 2015 LTSB. I'm on 22H2 and was hoping to keep at least one machine still running Windows as I very occasionally have to resort to it. But it's already so slow, it's practically unusable. Worst comes to the worst, I'll wipe off Windows and see if I can find another 'Dozer in the bargain bucket.

All this goes to show how daft it is to pay top dollar for shiny new stuff. With Puppy, that old lappie bursts into life and starts singing and dancing like a sprightly youngster. (Not literally, that would be weird.) You never know: there may come a day when old-but-reliable tech becomes the norm. Especially for people who want to own what they buy, rather than being owned by the OS it runs.

User avatar
wiak
Posts: 3998
Joined: Tue Dec 03, 2019 6:10 am
Location: Packing - big job
Has thanked: 60 times
Been thanked: 1156 times
Contact:

Re: Latest Windows update is messing up booting Linux operating systems

Post by wiak »

My Linux Mint machine just notified me that there are a few updates to install. One is a shim... per image attached... maybe something to do with all this?

Attachments
linux_mint_new_shim.png
linux_mint_new_shim.png (8.72 KiB) Viewed 220 times

https://www.tinylinux.info/
DOWNLOAD wd_multi for hundreds of 'distros' at your fingertips: viewtopic.php?p=99154#p99154
Αξίζει να μεταφραστεί;

User avatar
rockedge
Site Admin
Posts: 6344
Joined: Mon Dec 02, 2019 1:38 am
Location: Connecticut,U.S.A.
Has thanked: 2529 times
Been thanked: 2509 times
Contact:

Re: Latest Windows update is messing up booting Linux operating systems

Post by rockedge »

Yes I believe it is the update to match Microsoft's shim thing

Post Reply

Return to “Announcements”