Navigation: Linux Kernel Driver DataBase - web LKDDB: Main index - E index

CONFIG_EFI_SBAT_FILE: Embedded SBAT section file path

General informations

The Linux kernel configuration item CONFIG_EFI_SBAT_FILE:

Help text

SBAT section provides a way to improve SecureBoot revocations of UEFI binaries by introducing a generation-based mechanism. With SBAT, older UEFI binaries can be prevented from booting by bumping the minimal required generation for the specific component in the bootloader.

Note: SBAT information is distribution specific, i.e. the owner of the signing SecureBoot certificate must define the SBAT policy. Linux kernel upstream does not define SBAT components and their generations.

See https://github.com/rhboot/shim/blob/main/SBAT.md for the additional details.

Specify a file with SBAT data which is going to be embedded as '.sbat' section into the kernel.

If unsure, leave blank.

Hardware

LKDDb

Raw data from LKDDb:

Sources

This page is automaticly generated with free (libre, open) software lkddb(see lkddb-sources).

The data is retrived from:

Automatic links from Google (and ads)

Custom Search

Popular queries:

Navigation: Linux Kernel Driver DataBase - web LKDDB: main index - E index

Automatically generated (in year 2025). See also LKDDb sources on GitLab