microsoft / microsoft/secureboot_objects

GetSecureBoot Documentation Request: Hyper-V

Open
#370 7 comments 0 reactions 1 assignee View on GitHub

@mebersol is already working on this.

Since May 18, 2026.

state:backlog
Dominant language
Python
Stars
289
Forks
89
Avg merge
3d 10h
Merged PRs (30d)
7

Description

I think admins (myself included) have a lot of questions about the SB updates on Hyper-V and a new document specific to it is warranted (I think under https://aka.ms/getsecureboot would make sense to strengthen the already quality documentation there).

Some things to document (maybe a FAQ format) include:

  1. March CU requirements, what changed.
  2. Hotpatch vs coldpatch CU
  3. Version compatibility for HV hosts supporting KEK updates (Windows Server 2012R2 I think with ESU entitlements?)
  4. Gen 1 vs Gen 2 security posture
  5. Compare + contrast the "features" of the three secure boot templates
  6. Impacts of VMs with TPMs (and shielding)
  7. Guest operating systems supported (in theory it shouldn't matter, even linux VMs updating with fwupd should work....)
  8. Why is the PK expired?
  9. Do VMs created after the March LCU is applied automatically include the 2023 certs? Or which version/patch combinations of HV VMs include all 2023 certs/keys "out of the box"?

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.