Navigation: Linux Kernel Driver DataBase - web LKDDB: Main index - E index
The Linux kernel configuration item CONFIG_EFI_SBAT_FILE
:
CONFIG_EFI_ZBOOT
SBAT section provides a way to improve SecureBoot revocations of UEFI binaries by introducing a generation-based mechanism. With SBAT, older UEFI binaries can be prevented from booting by bumping the minimal required generation for the specific component in the bootloader.
Note: SBAT information is distribution specific, i.e. the owner of the signing SecureBoot certificate must define the SBAT policy. Linux kernel upstream does not define SBAT components and their generations.
See https://github.com/rhboot/shim/blob/main/SBAT.md for the additional details.
Specify a file with SBAT data which is going to be embedded as '.sbat' section into the kernel.
If unsure, leave blank.
Raw data from LKDDb:
(none)
This page is automaticly generated with free (libre, open) software lkddb(see lkddb-sources).
The data is retrived from:
Popular queries:
Navigation: Linux Kernel Driver DataBase - web LKDDB: main index - E index
Automatically generated (in year 2025). See also LKDDb sources on GitLab