Windows: make EFI trust checks dbx-aware

Reject revoked loader CA sets and diagnose the chainloaded Windows manager. Add PCA 2011 migration warnings and update Secure Boot guidance.
This commit is contained in:
Mounir IDRASSI
2026-07-10 21:53:11 +09:00
parent fdd8d77e7c
commit 301496c7e2
55 changed files with 1033 additions and 245 deletions
+3 -2
View File
@@ -1688,8 +1688,9 @@
<entry lang="ar" key="SYSENC_EFI_UNSUPPORTED_SECUREBOOT_CA">‮الإقلاع الآمن Secure Boot مفعّل، لكن قاعدة بيانات Secure Boot في البرنامج الثابت لا تثق بأي مجموعة Microsoft UEFI CA يدعمها محمل الإقلاع EFI الخاص بـ ڤيراكربت. فعّل إما Microsoft Corporation UEFI CA 2011، أو كليهما Microsoft UEFI CA 2023 و Microsoft Option ROM UEFI CA 2023، ثم شغّل خيار الإصلاح/إعادة التنصيب في ڤيراكربت. بدلاً من ذلك، عطّل Secure Boot.</entry>
<entry lang="ar" key="MACOSX_CHECK_FILESYS">‮ستفتح نافذة الطرفية بعد الضغط على 'موافق' وستتحقق من نظام الملفات على مجلد ڤيراكربت المحدد باستخدام 'diskutil'. ستُعرض النتيجة في تلك النافذة.\n\nإذا تعذر بدء التحقق، فسيتم تشغيل أداة القرص بدلاً من ذلك.</entry>
<entry lang="ar" key="MACOSX_REPAIR_FILESYS">‮ستفتح نافذة الطرفية بعد الضغط على 'موافق' وستحاول إصلاح نظام الملفات على مجلد ڤيراكربت المحدد باستخدام 'diskutil'. ستُعرض النتيجة في تلك النافذة.\n\nإذا تعذر بدء الإصلاح، فسيتم تشغيل أداة القرص بدلاً من ذلك.</entry>
<entry lang="en" key="SYSENC_EFI_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: Secure Boot is enabled, but the Microsoft UEFI CA that signs the installed VeraCrypt EFI bootloader was not found in the firmware Secure Boot database (db). The firmware may refuse to start VeraCrypt at the next reboot, so Windows will not start until Secure Boot is disabled or the trusted certificates/loader set are repaired.\n\nBefore restarting this computer, do not disable or remove Microsoft Corporation UEFI CA 2011 unless the firmware db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and VeraCrypt has been repaired/reinstalled so the 2023-signed loader set is installed. Enable the required Microsoft certificates in the BIOS/UEFI settings if needed, then run VeraCrypt Repair/Reinstall. Make sure you have an up-to-date VeraCrypt Rescue Disk before restarting.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: Secure Boot is enabled, but the Microsoft CA that signs the Windows Boot Manager copy used by VeraCrypt (bootmgfw_ms.vc) was not found in the firmware Secure Boot database (db). After successful pre-boot authentication, the handoff to Windows may fail and the computer may return to the VeraCrypt password prompt.\n\nBefore restarting this computer, do not disable or revoke Microsoft Windows Production PCA 2011 unless Windows Boot Manager has migrated to a Windows UEFI CA 2023-signed version and the firmware db contains Windows UEFI CA 2023. Apply the Windows Secure Boot certificate updates, then run VeraCrypt Repair/Reinstall if needed. Make sure you have an up-to-date VeraCrypt Rescue Disk before restarting.</entry>
<entry lang="en" key="SYSENC_EFI_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: VeraCrypt could not validate the installed EFI bootloader files against one complete embedded resource set and confirm that all known required signing CAs are present in db and not listed by dbx. Firmware may reject VeraCrypt when Secure Boot is enabled.\n\nBefore booting with Secure Boot enabled, restore the required Microsoft certificates and current dbx as needed, then run VeraCrypt Repair/Reinstall. Do not remove Microsoft Corporation UEFI CA 2011 until db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and the actual installed files match VeraCrypt's 2023 set. This check cannot model every image-hash or security-version revocation. Make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: VeraCrypt could not validate the embedded signature and known-CA compatibility of the Windows Boot Manager it chainloads (bootmgfw_ms.vc). The file may be missing, unreadable, not a Windows Boot Manager, have an unrecognized embedded signer, or use a known signing CA that is absent from db or listed by dbx. The handoff to Windows may fail when Secure Boot is enabled.\n\nComplete or repair the Windows Secure Boot certificate and boot-manager update, keep the VeraCrypt System Favorites service enabled, and run VeraCrypt Repair/Reinstall. Repair also checks Windows' serviced EFI_EX/EFI copies for a compatible current Boot Manager. If Windows cannot start, temporarily disable Secure Boot to recover. Make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_PCA2011_MIGRATION_NEEDED">Warning: The embedded signature of the Windows Boot Manager used by VeraCrypt (bootmgfw_ms.vc) is still issued by Microsoft Windows Production PCA 2011, although firmware db already contains Windows UEFI CA 2023. Its known CA is currently allowed, but it will no longer start after the PCA 2011 certificate is added to dbx.\n\nDo not apply the PCA 2011 revocation (AvailableUpdates bit 0x80, including combined value 0x280) yet. First complete the Windows 2023 boot-manager update while the VeraCrypt System Favorites service is enabled, then run VeraCrypt Repair/Reinstall so VeraCrypt can import a compatible serviced EFI_EX/EFI copy. Verify the embedded issuer of bootmgfw_ms.vc is Windows UEFI CA 2023 and make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
</localization>
<xs:schema attributeFormDefault="unqualified" elementFormDefault="qualified" xmlns:xs="http://www.w3.org/2001/XMLSchema">
<xs:element name="VeraCrypt">
+3 -2
View File
@@ -1688,8 +1688,9 @@
<entry lang="be" key="SYSENC_EFI_UNSUPPORTED_SECUREBOOT_CA">Secure Boot уключаны, але база даных Secure Boot у прашыўцы не давярае ніводнаму набору Microsoft UEFI CA, які падтрымліваецца загрузчыкам EFI VeraCrypt. Уключыце альбо Microsoft Corporation UEFI CA 2011, альбо адначасова Microsoft UEFI CA 2023 і Microsoft Option ROM UEFI CA 2023, затым запусціце VeraCrypt Аднавіць/пераўсталяваць. У якасці альтэрнатывы адключыце Secure Boot.</entry>
<entry lang="be" key="MACOSX_CHECK_FILESYS">Пасля націску 'OK' адкрыецца акно Тэрмінала, у якім будзе праверана файлавая сістэма выбранага тома VeraCrypt з дапамогай 'diskutil'. Вынік будзе паказаны ў гэтым акне.\n\nКалі праверку немагчыма запусціць, замест гэтага будзе запушчана Дыскавая ўтыліта.</entry>
<entry lang="be" key="MACOSX_REPAIR_FILESYS">Пасля націску 'OK' адкрыецца акно Тэрмінала, у якім будзе выканана спроба аднавіць файлавую сістэму выбранага тома VeraCrypt з дапамогай 'diskutil'. Вынік будзе паказаны ў гэтым акне.\n\nКалі аднаўленне немагчыма запусціць, замест гэтага будзе запушчана Дыскавая ўтыліта.</entry>
<entry lang="en" key="SYSENC_EFI_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: Secure Boot is enabled, but the Microsoft UEFI CA that signs the installed VeraCrypt EFI bootloader was not found in the firmware Secure Boot database (db). The firmware may refuse to start VeraCrypt at the next reboot, so Windows will not start until Secure Boot is disabled or the trusted certificates/loader set are repaired.\n\nBefore restarting this computer, do not disable or remove Microsoft Corporation UEFI CA 2011 unless the firmware db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and VeraCrypt has been repaired/reinstalled so the 2023-signed loader set is installed. Enable the required Microsoft certificates in the BIOS/UEFI settings if needed, then run VeraCrypt Repair/Reinstall. Make sure you have an up-to-date VeraCrypt Rescue Disk before restarting.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: Secure Boot is enabled, but the Microsoft CA that signs the Windows Boot Manager copy used by VeraCrypt (bootmgfw_ms.vc) was not found in the firmware Secure Boot database (db). After successful pre-boot authentication, the handoff to Windows may fail and the computer may return to the VeraCrypt password prompt.\n\nBefore restarting this computer, do not disable or revoke Microsoft Windows Production PCA 2011 unless Windows Boot Manager has migrated to a Windows UEFI CA 2023-signed version and the firmware db contains Windows UEFI CA 2023. Apply the Windows Secure Boot certificate updates, then run VeraCrypt Repair/Reinstall if needed. Make sure you have an up-to-date VeraCrypt Rescue Disk before restarting.</entry>
<entry lang="en" key="SYSENC_EFI_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: VeraCrypt could not validate the installed EFI bootloader files against one complete embedded resource set and confirm that all known required signing CAs are present in db and not listed by dbx. Firmware may reject VeraCrypt when Secure Boot is enabled.\n\nBefore booting with Secure Boot enabled, restore the required Microsoft certificates and current dbx as needed, then run VeraCrypt Repair/Reinstall. Do not remove Microsoft Corporation UEFI CA 2011 until db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and the actual installed files match VeraCrypt's 2023 set. This check cannot model every image-hash or security-version revocation. Make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: VeraCrypt could not validate the embedded signature and known-CA compatibility of the Windows Boot Manager it chainloads (bootmgfw_ms.vc). The file may be missing, unreadable, not a Windows Boot Manager, have an unrecognized embedded signer, or use a known signing CA that is absent from db or listed by dbx. The handoff to Windows may fail when Secure Boot is enabled.\n\nComplete or repair the Windows Secure Boot certificate and boot-manager update, keep the VeraCrypt System Favorites service enabled, and run VeraCrypt Repair/Reinstall. Repair also checks Windows' serviced EFI_EX/EFI copies for a compatible current Boot Manager. If Windows cannot start, temporarily disable Secure Boot to recover. Make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_PCA2011_MIGRATION_NEEDED">Warning: The embedded signature of the Windows Boot Manager used by VeraCrypt (bootmgfw_ms.vc) is still issued by Microsoft Windows Production PCA 2011, although firmware db already contains Windows UEFI CA 2023. Its known CA is currently allowed, but it will no longer start after the PCA 2011 certificate is added to dbx.\n\nDo not apply the PCA 2011 revocation (AvailableUpdates bit 0x80, including combined value 0x280) yet. First complete the Windows 2023 boot-manager update while the VeraCrypt System Favorites service is enabled, then run VeraCrypt Repair/Reinstall so VeraCrypt can import a compatible serviced EFI_EX/EFI copy. Verify the embedded issuer of bootmgfw_ms.vc is Windows UEFI CA 2023 and make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
</localization>
<xs:schema attributeFormDefault="unqualified" elementFormDefault="qualified" xmlns:xs="http://www.w3.org/2001/XMLSchema">
<xs:element name="VeraCrypt">
+3 -2
View File
@@ -1688,8 +1688,9 @@
<entry lang="bg" key="SYSENC_EFI_UNSUPPORTED_SECUREBOOT_CA">Secure Boot е активирано, но базата данни на Secure Boot във фърмуера не се доверява на нито един набор Microsoft UEFI CA, поддържан от EFI зареждащия модул на VeraCrypt. Активирайте или Microsoft Corporation UEFI CA 2011, или едновременно Microsoft UEFI CA 2023 и Microsoft Option ROM UEFI CA 2023, след което стартирайте опцията Поправка/Преинсталация във VeraCrypt. Като алтернатива деактивирайте Secure Boot.</entry>
<entry lang="bg" key="MACOSX_CHECK_FILESYS">След като натиснете 'OK', ще се отвори прозорец на Терминал и ще провери файловата система на избрания том VeraCrypt чрез 'diskutil'. Резултатът ще бъде показан в този прозорец.\n\nАко проверката не може да бъде стартирана, вместо това ще бъде стартирана Дискова помощна програма.</entry>
<entry lang="bg" key="MACOSX_REPAIR_FILESYS">След като натиснете 'OK', ще се отвори прозорец на Терминал и ще се опита да поправи файловата система на избрания том VeraCrypt чрез 'diskutil'. Резултатът ще бъде показан в този прозорец.\n\nАко поправката не може да бъде стартирана, вместо това ще бъде стартирана Дискова помощна програма.</entry>
<entry lang="en" key="SYSENC_EFI_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: Secure Boot is enabled, but the Microsoft UEFI CA that signs the installed VeraCrypt EFI bootloader was not found in the firmware Secure Boot database (db). The firmware may refuse to start VeraCrypt at the next reboot, so Windows will not start until Secure Boot is disabled or the trusted certificates/loader set are repaired.\n\nBefore restarting this computer, do not disable or remove Microsoft Corporation UEFI CA 2011 unless the firmware db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and VeraCrypt has been repaired/reinstalled so the 2023-signed loader set is installed. Enable the required Microsoft certificates in the BIOS/UEFI settings if needed, then run VeraCrypt Repair/Reinstall. Make sure you have an up-to-date VeraCrypt Rescue Disk before restarting.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: Secure Boot is enabled, but the Microsoft CA that signs the Windows Boot Manager copy used by VeraCrypt (bootmgfw_ms.vc) was not found in the firmware Secure Boot database (db). After successful pre-boot authentication, the handoff to Windows may fail and the computer may return to the VeraCrypt password prompt.\n\nBefore restarting this computer, do not disable or revoke Microsoft Windows Production PCA 2011 unless Windows Boot Manager has migrated to a Windows UEFI CA 2023-signed version and the firmware db contains Windows UEFI CA 2023. Apply the Windows Secure Boot certificate updates, then run VeraCrypt Repair/Reinstall if needed. Make sure you have an up-to-date VeraCrypt Rescue Disk before restarting.</entry>
<entry lang="en" key="SYSENC_EFI_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: VeraCrypt could not validate the installed EFI bootloader files against one complete embedded resource set and confirm that all known required signing CAs are present in db and not listed by dbx. Firmware may reject VeraCrypt when Secure Boot is enabled.\n\nBefore booting with Secure Boot enabled, restore the required Microsoft certificates and current dbx as needed, then run VeraCrypt Repair/Reinstall. Do not remove Microsoft Corporation UEFI CA 2011 until db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and the actual installed files match VeraCrypt's 2023 set. This check cannot model every image-hash or security-version revocation. Make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: VeraCrypt could not validate the embedded signature and known-CA compatibility of the Windows Boot Manager it chainloads (bootmgfw_ms.vc). The file may be missing, unreadable, not a Windows Boot Manager, have an unrecognized embedded signer, or use a known signing CA that is absent from db or listed by dbx. The handoff to Windows may fail when Secure Boot is enabled.\n\nComplete or repair the Windows Secure Boot certificate and boot-manager update, keep the VeraCrypt System Favorites service enabled, and run VeraCrypt Repair/Reinstall. Repair also checks Windows' serviced EFI_EX/EFI copies for a compatible current Boot Manager. If Windows cannot start, temporarily disable Secure Boot to recover. Make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_PCA2011_MIGRATION_NEEDED">Warning: The embedded signature of the Windows Boot Manager used by VeraCrypt (bootmgfw_ms.vc) is still issued by Microsoft Windows Production PCA 2011, although firmware db already contains Windows UEFI CA 2023. Its known CA is currently allowed, but it will no longer start after the PCA 2011 certificate is added to dbx.\n\nDo not apply the PCA 2011 revocation (AvailableUpdates bit 0x80, including combined value 0x280) yet. First complete the Windows 2023 boot-manager update while the VeraCrypt System Favorites service is enabled, then run VeraCrypt Repair/Reinstall so VeraCrypt can import a compatible serviced EFI_EX/EFI copy. Verify the embedded issuer of bootmgfw_ms.vc is Windows UEFI CA 2023 and make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
</localization>
<xs:schema attributeFormDefault="unqualified" elementFormDefault="qualified" xmlns:xs="http://www.w3.org/2001/XMLSchema">
<xs:element name="VeraCrypt">
+3 -2
View File
@@ -1688,8 +1688,9 @@
<entry lang="ca" key="SYSENC_EFI_UNSUPPORTED_SECUREBOOT_CA">Secure Boot està activat, però la base de dades Secure Boot del microprogramari no confia en cap conjunt de Microsoft UEFI CA compatible amb el carregador d'arrencada EFI de VeraCrypt. Activeu Microsoft Corporation UEFI CA 2011, o bé Microsoft UEFI CA 2023 i Microsoft Option ROM UEFI CA 2023, i després executeu VeraCrypt Reparar/Reinstal·lar. Alternativament, desactiveu Secure Boot.</entry>
<entry lang="ca" key="MACOSX_CHECK_FILESYS">Després de prémer 'OK', s'obrirà una finestra del Terminal i es comprovarà el sistema de fitxers del volum VeraCrypt seleccionat amb 'diskutil'. El resultat es mostrarà en aquesta finestra.\n\nSi no es pot iniciar la comprovació, s'obrirà la Utilitat de Discos.</entry>
<entry lang="ca" key="MACOSX_REPAIR_FILESYS">Després de prémer 'OK', s'obrirà una finestra del Terminal i s'intentarà reparar el sistema de fitxers del volum VeraCrypt seleccionat amb 'diskutil'. El resultat es mostrarà en aquesta finestra.\n\nSi no es pot iniciar la reparació, s'obrirà la Utilitat de Discos.</entry>
<entry lang="en" key="SYSENC_EFI_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: Secure Boot is enabled, but the Microsoft UEFI CA that signs the installed VeraCrypt EFI bootloader was not found in the firmware Secure Boot database (db). The firmware may refuse to start VeraCrypt at the next reboot, so Windows will not start until Secure Boot is disabled or the trusted certificates/loader set are repaired.\n\nBefore restarting this computer, do not disable or remove Microsoft Corporation UEFI CA 2011 unless the firmware db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and VeraCrypt has been repaired/reinstalled so the 2023-signed loader set is installed. Enable the required Microsoft certificates in the BIOS/UEFI settings if needed, then run VeraCrypt Repair/Reinstall. Make sure you have an up-to-date VeraCrypt Rescue Disk before restarting.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: Secure Boot is enabled, but the Microsoft CA that signs the Windows Boot Manager copy used by VeraCrypt (bootmgfw_ms.vc) was not found in the firmware Secure Boot database (db). After successful pre-boot authentication, the handoff to Windows may fail and the computer may return to the VeraCrypt password prompt.\n\nBefore restarting this computer, do not disable or revoke Microsoft Windows Production PCA 2011 unless Windows Boot Manager has migrated to a Windows UEFI CA 2023-signed version and the firmware db contains Windows UEFI CA 2023. Apply the Windows Secure Boot certificate updates, then run VeraCrypt Repair/Reinstall if needed. Make sure you have an up-to-date VeraCrypt Rescue Disk before restarting.</entry>
<entry lang="en" key="SYSENC_EFI_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: VeraCrypt could not validate the installed EFI bootloader files against one complete embedded resource set and confirm that all known required signing CAs are present in db and not listed by dbx. Firmware may reject VeraCrypt when Secure Boot is enabled.\n\nBefore booting with Secure Boot enabled, restore the required Microsoft certificates and current dbx as needed, then run VeraCrypt Repair/Reinstall. Do not remove Microsoft Corporation UEFI CA 2011 until db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and the actual installed files match VeraCrypt's 2023 set. This check cannot model every image-hash or security-version revocation. Make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: VeraCrypt could not validate the embedded signature and known-CA compatibility of the Windows Boot Manager it chainloads (bootmgfw_ms.vc). The file may be missing, unreadable, not a Windows Boot Manager, have an unrecognized embedded signer, or use a known signing CA that is absent from db or listed by dbx. The handoff to Windows may fail when Secure Boot is enabled.\n\nComplete or repair the Windows Secure Boot certificate and boot-manager update, keep the VeraCrypt System Favorites service enabled, and run VeraCrypt Repair/Reinstall. Repair also checks Windows' serviced EFI_EX/EFI copies for a compatible current Boot Manager. If Windows cannot start, temporarily disable Secure Boot to recover. Make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_PCA2011_MIGRATION_NEEDED">Warning: The embedded signature of the Windows Boot Manager used by VeraCrypt (bootmgfw_ms.vc) is still issued by Microsoft Windows Production PCA 2011, although firmware db already contains Windows UEFI CA 2023. Its known CA is currently allowed, but it will no longer start after the PCA 2011 certificate is added to dbx.\n\nDo not apply the PCA 2011 revocation (AvailableUpdates bit 0x80, including combined value 0x280) yet. First complete the Windows 2023 boot-manager update while the VeraCrypt System Favorites service is enabled, then run VeraCrypt Repair/Reinstall so VeraCrypt can import a compatible serviced EFI_EX/EFI copy. Verify the embedded issuer of bootmgfw_ms.vc is Windows UEFI CA 2023 and make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
</localization>
<xs:schema attributeFormDefault="unqualified" elementFormDefault="qualified" xmlns:xs="http://www.w3.org/2001/XMLSchema">
<xs:element name="VeraCrypt">
+3 -2
View File
@@ -1710,8 +1710,9 @@ Information about Corsican localization:
<entry lang="co" key="SYSENC_EFI_UNSUPPORTED_SECUREBOOT_CA">A piccera sicurizata hè attiva ma a basa di dati di a piccera sicurizata di u microprugramma ùn face micca cunfidenza à alcunu inseme dauturità di certificazione UEFI di Microsoft accettatu da u caricadore di piccera EFI di VeraCrypt. Attivà, sia Microsoft Corporation UEFI CA 2011, sia Microsoft UEFI CA 2023 è Microsoft Option ROM UEFI CA 2023 tremindui, eppò lancià « Riparà o riinstallà » di VeraCrypt. Osinnò, disattivà a piccera sicurizata.</entry>
<entry lang="co" key="MACOSX_CHECK_FILESYS">Una finestra di terminale saprerà dopu avè appughjatu nant’à « Vai » è ci serà un cuntrollu di u sistema di schedariu nant’à u vulume VeraCrypt selezziunatu impieghendu « diskutil ». U risultatu serà affissatu in quella finestra.\n\nS’è u cuntrollu ùn pò principià, « Disk Utility » serà lanciatu in rimpiazzamentu.</entry>
<entry lang="co" key="MACOSX_REPAIR_FILESYS">Una finestra di terminale saprerà dopu avè appughjatu nant’à « Vai » è ci serà un tentativu di riparà u sistema di schedariu nant’à u vulume VeraCrypt selezziunatu impieghendu « diskutil ». U risultatu serà affissatu in quella finestra.\n\nS’è a riparazione ùn pò principià, « Disk Utility » serà lanciatu in rimpiazzamentu.</entry>
<entry lang="en" key="SYSENC_EFI_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: Secure Boot is enabled, but the Microsoft UEFI CA that signs the installed VeraCrypt EFI bootloader was not found in the firmware Secure Boot database (db). The firmware may refuse to start VeraCrypt at the next reboot, so Windows will not start until Secure Boot is disabled or the trusted certificates/loader set are repaired.\n\nBefore restarting this computer, do not disable or remove Microsoft Corporation UEFI CA 2011 unless the firmware db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and VeraCrypt has been repaired/reinstalled so the 2023-signed loader set is installed. Enable the required Microsoft certificates in the BIOS/UEFI settings if needed, then run VeraCrypt Repair/Reinstall. Make sure you have an up-to-date VeraCrypt Rescue Disk before restarting.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: Secure Boot is enabled, but the Microsoft CA that signs the Windows Boot Manager copy used by VeraCrypt (bootmgfw_ms.vc) was not found in the firmware Secure Boot database (db). After successful pre-boot authentication, the handoff to Windows may fail and the computer may return to the VeraCrypt password prompt.\n\nBefore restarting this computer, do not disable or revoke Microsoft Windows Production PCA 2011 unless Windows Boot Manager has migrated to a Windows UEFI CA 2023-signed version and the firmware db contains Windows UEFI CA 2023. Apply the Windows Secure Boot certificate updates, then run VeraCrypt Repair/Reinstall if needed. Make sure you have an up-to-date VeraCrypt Rescue Disk before restarting.</entry>
<entry lang="en" key="SYSENC_EFI_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: VeraCrypt could not validate the installed EFI bootloader files against one complete embedded resource set and confirm that all known required signing CAs are present in db and not listed by dbx. Firmware may reject VeraCrypt when Secure Boot is enabled.\n\nBefore booting with Secure Boot enabled, restore the required Microsoft certificates and current dbx as needed, then run VeraCrypt Repair/Reinstall. Do not remove Microsoft Corporation UEFI CA 2011 until db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and the actual installed files match VeraCrypt's 2023 set. This check cannot model every image-hash or security-version revocation. Make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: VeraCrypt could not validate the embedded signature and known-CA compatibility of the Windows Boot Manager it chainloads (bootmgfw_ms.vc). The file may be missing, unreadable, not a Windows Boot Manager, have an unrecognized embedded signer, or use a known signing CA that is absent from db or listed by dbx. The handoff to Windows may fail when Secure Boot is enabled.\n\nComplete or repair the Windows Secure Boot certificate and boot-manager update, keep the VeraCrypt System Favorites service enabled, and run VeraCrypt Repair/Reinstall. Repair also checks Windows' serviced EFI_EX/EFI copies for a compatible current Boot Manager. If Windows cannot start, temporarily disable Secure Boot to recover. Make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_PCA2011_MIGRATION_NEEDED">Warning: The embedded signature of the Windows Boot Manager used by VeraCrypt (bootmgfw_ms.vc) is still issued by Microsoft Windows Production PCA 2011, although firmware db already contains Windows UEFI CA 2023. Its known CA is currently allowed, but it will no longer start after the PCA 2011 certificate is added to dbx.\n\nDo not apply the PCA 2011 revocation (AvailableUpdates bit 0x80, including combined value 0x280) yet. First complete the Windows 2023 boot-manager update while the VeraCrypt System Favorites service is enabled, then run VeraCrypt Repair/Reinstall so VeraCrypt can import a compatible serviced EFI_EX/EFI copy. Verify the embedded issuer of bootmgfw_ms.vc is Windows UEFI CA 2023 and make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
</localization>
<xs:schema attributeFormDefault="unqualified" elementFormDefault="qualified" xmlns:xs="http://www.w3.org/2001/XMLSchema">
<xs:element name="VeraCrypt">
+3 -2
View File
@@ -1688,8 +1688,9 @@
<entry lang="cs" key="SYSENC_EFI_UNSUPPORTED_SECUREBOOT_CA">Secure Boot je povolen, ale databáze Secure Boot ve firmwaru nedůvěřuje žádné sadě Microsoft UEFI CA podporované zavaděčem EFI VeraCryptu. Povolte buď Microsoft Corporation UEFI CA 2011, nebo současně Microsoft UEFI CA 2023 a Microsoft Option ROM UEFI CA 2023, poté spusťte volbu Opravit/Přeinstalovat programu VeraCrypt. Případně Secure Boot zakažte.</entry>
<entry lang="cs" key="MACOSX_CHECK_FILESYS">Po stisknutí tlačítka „OK” se otevře okno Terminálu, ve kterém bude pomocí příkazu 'diskutil' zkontrolován systém souborů vybraného svazku VeraCryptu. Výsledek se zobrazí v tomto okně.\n\nPokud kontrolu nelze spustit, bude místo toho spuštěna Disková utilita.</entry>
<entry lang="cs" key="MACOSX_REPAIR_FILESYS">Po stisknutí tlačítka „OK” se otevře okno Terminálu, ve kterém bude pomocí příkazu 'diskutil' proveden pokus o opravu systému souborů vybraného svazku VeraCryptu. Výsledek se zobrazí v tomto okně.\n\nPokud opravu nelze spustit, bude místo toho spuštěna Disková utilita.</entry>
<entry lang="en" key="SYSENC_EFI_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: Secure Boot is enabled, but the Microsoft UEFI CA that signs the installed VeraCrypt EFI bootloader was not found in the firmware Secure Boot database (db). The firmware may refuse to start VeraCrypt at the next reboot, so Windows will not start until Secure Boot is disabled or the trusted certificates/loader set are repaired.\n\nBefore restarting this computer, do not disable or remove Microsoft Corporation UEFI CA 2011 unless the firmware db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and VeraCrypt has been repaired/reinstalled so the 2023-signed loader set is installed. Enable the required Microsoft certificates in the BIOS/UEFI settings if needed, then run VeraCrypt Repair/Reinstall. Make sure you have an up-to-date VeraCrypt Rescue Disk before restarting.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: Secure Boot is enabled, but the Microsoft CA that signs the Windows Boot Manager copy used by VeraCrypt (bootmgfw_ms.vc) was not found in the firmware Secure Boot database (db). After successful pre-boot authentication, the handoff to Windows may fail and the computer may return to the VeraCrypt password prompt.\n\nBefore restarting this computer, do not disable or revoke Microsoft Windows Production PCA 2011 unless Windows Boot Manager has migrated to a Windows UEFI CA 2023-signed version and the firmware db contains Windows UEFI CA 2023. Apply the Windows Secure Boot certificate updates, then run VeraCrypt Repair/Reinstall if needed. Make sure you have an up-to-date VeraCrypt Rescue Disk before restarting.</entry>
<entry lang="en" key="SYSENC_EFI_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: VeraCrypt could not validate the installed EFI bootloader files against one complete embedded resource set and confirm that all known required signing CAs are present in db and not listed by dbx. Firmware may reject VeraCrypt when Secure Boot is enabled.\n\nBefore booting with Secure Boot enabled, restore the required Microsoft certificates and current dbx as needed, then run VeraCrypt Repair/Reinstall. Do not remove Microsoft Corporation UEFI CA 2011 until db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and the actual installed files match VeraCrypt's 2023 set. This check cannot model every image-hash or security-version revocation. Make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: VeraCrypt could not validate the embedded signature and known-CA compatibility of the Windows Boot Manager it chainloads (bootmgfw_ms.vc). The file may be missing, unreadable, not a Windows Boot Manager, have an unrecognized embedded signer, or use a known signing CA that is absent from db or listed by dbx. The handoff to Windows may fail when Secure Boot is enabled.\n\nComplete or repair the Windows Secure Boot certificate and boot-manager update, keep the VeraCrypt System Favorites service enabled, and run VeraCrypt Repair/Reinstall. Repair also checks Windows' serviced EFI_EX/EFI copies for a compatible current Boot Manager. If Windows cannot start, temporarily disable Secure Boot to recover. Make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_PCA2011_MIGRATION_NEEDED">Warning: The embedded signature of the Windows Boot Manager used by VeraCrypt (bootmgfw_ms.vc) is still issued by Microsoft Windows Production PCA 2011, although firmware db already contains Windows UEFI CA 2023. Its known CA is currently allowed, but it will no longer start after the PCA 2011 certificate is added to dbx.\n\nDo not apply the PCA 2011 revocation (AvailableUpdates bit 0x80, including combined value 0x280) yet. First complete the Windows 2023 boot-manager update while the VeraCrypt System Favorites service is enabled, then run VeraCrypt Repair/Reinstall so VeraCrypt can import a compatible serviced EFI_EX/EFI copy. Verify the embedded issuer of bootmgfw_ms.vc is Windows UEFI CA 2023 and make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
</localization>
<xs:schema attributeFormDefault="unqualified" elementFormDefault="qualified" xmlns:xs="http://www.w3.org/2001/XMLSchema">
<xs:element name="VeraCrypt">
+3 -2
View File
@@ -1688,8 +1688,9 @@
<entry lang="da" key="SYSENC_EFI_UNSUPPORTED_SECUREBOOT_CA">Secure Boot er aktiveret, men firmwarens Secure Boot-database har ikke tillid til nogen Microsoft UEFI CA-samling, der understøttes af VeraCrypts EFI-bootloader. Aktivér enten Microsoft Corporation UEFI CA 2011 eller både Microsoft UEFI CA 2023 og Microsoft Option ROM UEFI CA 2023, og kør derefter VeraCrypt Reparer/geninstaller. Alternativt kan du deaktivere Secure Boot.</entry>
<entry lang="da" key="MACOSX_CHECK_FILESYS">Et Terminal-vindue åbnes, når du trykker på 'OK', og kontrollerer filsystemet på det valgte VeraCrypt-bind med 'diskutil'. Resultatet vises i det vindue.\n\nHvis kontrollen ikke kan startes, startes Diskværktøj i stedet.</entry>
<entry lang="da" key="MACOSX_REPAIR_FILESYS">Et Terminal-vindue åbnes, når du trykker på 'OK', og forsøger at reparere filsystemet på det valgte VeraCrypt-bind med 'diskutil'. Resultatet vises i det vindue.\n\nHvis reparationen ikke kan startes, startes Diskværktøj i stedet.</entry>
<entry lang="en" key="SYSENC_EFI_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: Secure Boot is enabled, but the Microsoft UEFI CA that signs the installed VeraCrypt EFI bootloader was not found in the firmware Secure Boot database (db). The firmware may refuse to start VeraCrypt at the next reboot, so Windows will not start until Secure Boot is disabled or the trusted certificates/loader set are repaired.\n\nBefore restarting this computer, do not disable or remove Microsoft Corporation UEFI CA 2011 unless the firmware db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and VeraCrypt has been repaired/reinstalled so the 2023-signed loader set is installed. Enable the required Microsoft certificates in the BIOS/UEFI settings if needed, then run VeraCrypt Repair/Reinstall. Make sure you have an up-to-date VeraCrypt Rescue Disk before restarting.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: Secure Boot is enabled, but the Microsoft CA that signs the Windows Boot Manager copy used by VeraCrypt (bootmgfw_ms.vc) was not found in the firmware Secure Boot database (db). After successful pre-boot authentication, the handoff to Windows may fail and the computer may return to the VeraCrypt password prompt.\n\nBefore restarting this computer, do not disable or revoke Microsoft Windows Production PCA 2011 unless Windows Boot Manager has migrated to a Windows UEFI CA 2023-signed version and the firmware db contains Windows UEFI CA 2023. Apply the Windows Secure Boot certificate updates, then run VeraCrypt Repair/Reinstall if needed. Make sure you have an up-to-date VeraCrypt Rescue Disk before restarting.</entry>
<entry lang="en" key="SYSENC_EFI_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: VeraCrypt could not validate the installed EFI bootloader files against one complete embedded resource set and confirm that all known required signing CAs are present in db and not listed by dbx. Firmware may reject VeraCrypt when Secure Boot is enabled.\n\nBefore booting with Secure Boot enabled, restore the required Microsoft certificates and current dbx as needed, then run VeraCrypt Repair/Reinstall. Do not remove Microsoft Corporation UEFI CA 2011 until db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and the actual installed files match VeraCrypt's 2023 set. This check cannot model every image-hash or security-version revocation. Make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: VeraCrypt could not validate the embedded signature and known-CA compatibility of the Windows Boot Manager it chainloads (bootmgfw_ms.vc). The file may be missing, unreadable, not a Windows Boot Manager, have an unrecognized embedded signer, or use a known signing CA that is absent from db or listed by dbx. The handoff to Windows may fail when Secure Boot is enabled.\n\nComplete or repair the Windows Secure Boot certificate and boot-manager update, keep the VeraCrypt System Favorites service enabled, and run VeraCrypt Repair/Reinstall. Repair also checks Windows' serviced EFI_EX/EFI copies for a compatible current Boot Manager. If Windows cannot start, temporarily disable Secure Boot to recover. Make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_PCA2011_MIGRATION_NEEDED">Warning: The embedded signature of the Windows Boot Manager used by VeraCrypt (bootmgfw_ms.vc) is still issued by Microsoft Windows Production PCA 2011, although firmware db already contains Windows UEFI CA 2023. Its known CA is currently allowed, but it will no longer start after the PCA 2011 certificate is added to dbx.\n\nDo not apply the PCA 2011 revocation (AvailableUpdates bit 0x80, including combined value 0x280) yet. First complete the Windows 2023 boot-manager update while the VeraCrypt System Favorites service is enabled, then run VeraCrypt Repair/Reinstall so VeraCrypt can import a compatible serviced EFI_EX/EFI copy. Verify the embedded issuer of bootmgfw_ms.vc is Windows UEFI CA 2023 and make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
</localization>
<xs:schema attributeFormDefault="unqualified" elementFormDefault="qualified" xmlns:xs="http://www.w3.org/2001/XMLSchema">
<xs:element name="VeraCrypt">
+4 -3
View File
@@ -1688,11 +1688,12 @@
<entry lang="de" key="MACOSX_APFS_EROFS_HINT">macOS hat das ausgewählte Gerät als schreibgeschützt gemeldet. Handelt es sich um eine APFS-Festplatte, stellen Sie sicher, dass Sie die physische APFS-Speicherpartition ausgewählt haben und nicht ein synthetisches APFS-Volume. Identifizieren Sie die physische Partition mit dem Festplatten-Dienstprogramm oder dem Befehl „diskutil list“ und versuchen Sie es dann erneut.</entry>
<entry lang="de" key="FAVORITE_PIM_OR_KDF_CHANGED">Dieses Volume ist als Systemfavorit registriert und seine PIM- und/oder KDF-Einstellungen wurden geändert.\nMöchten Sie, dass VeraCrypt die Konfiguration des Systemfavoriten automatisch aktualisiert (Administratorrechte erforderlich)?\n\nBitte beachten Sie: Wenn Sie mit „Nein“ antworten, müssen Sie den Systemfavoriten manuell aktualisieren.</entry>
<entry lang="de" key="PIM_RESET_ON_KDF_CHANGE_CONFIRM">Die ausgewählte KDF verwendet andere PIM-Parameter, daher wird VeraCrypt den derzeitigen benutzerdefinierten PIM nicht wiederverwenden. Die neuen Volume-Kopfdaten verwenden den Standard-PIM für die ausgewählte KDF, es sei denn, Sie wählen im Abschnitt „Neu“ die Option „PIM verwenden“ aus und geben einen benutzerdefinierten Wert ein.\n\nMöchten Sie fortfahren?</entry>
<entry lang="en" key="SYSENC_EFI_UNSUPPORTED_SECUREBOOT_CA">Secure Boot is enabled, but the firmware Secure Boot database does not trust any Microsoft UEFI CA set supported by VeraCrypt's EFI bootloader. Enable either Microsoft Corporation UEFI CA 2011, or both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023, then run VeraCrypt Repair/Reinstall. Alternatively, disable Secure Boot.</entry>
<entry lang="en" key="SYSENC_EFI_UNSUPPORTED_SECUREBOOT_CA">VeraCrypt could not confirm that an EFI bootloader set is compatible with the current Secure Boot configuration. A required Microsoft CA may be missing from db or listed by dbx, or a firmware variable may be unreadable or malformed. An absent dbx variable is valid; a nonzero dbx diagnostic error is not.\n\nEnable either Microsoft Corporation UEFI CA 2011, or both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023, and run VeraCrypt Repair/Reinstall. Keep Secure Boot disabled until the diagnostics show a complete compatible assessment.</entry>
<entry lang="en" key="MACOSX_CHECK_FILESYS">A Terminal window will open after you press 'OK' and check the file system on the selected VeraCrypt volume using 'diskutil'. The result will be shown in that window.\n\nIf the check cannot be started, Disk Utility will be launched instead.</entry>
<entry lang="en" key="MACOSX_REPAIR_FILESYS">A Terminal window will open after you press 'OK' and attempt to repair the file system on the selected VeraCrypt volume using 'diskutil'. The result will be shown in that window.\n\nIf the repair cannot be started, Disk Utility will be launched instead.</entry>
<entry lang="en" key="SYSENC_EFI_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: Secure Boot is enabled, but the Microsoft UEFI CA that signs the installed VeraCrypt EFI bootloader was not found in the firmware Secure Boot database (db). The firmware may refuse to start VeraCrypt at the next reboot, so Windows will not start until Secure Boot is disabled or the trusted certificates/loader set are repaired.\n\nBefore restarting this computer, do not disable or remove Microsoft Corporation UEFI CA 2011 unless the firmware db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and VeraCrypt has been repaired/reinstalled so the 2023-signed loader set is installed. Enable the required Microsoft certificates in the BIOS/UEFI settings if needed, then run VeraCrypt Repair/Reinstall. Make sure you have an up-to-date VeraCrypt Rescue Disk before restarting.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: Secure Boot is enabled, but the Microsoft CA that signs the Windows Boot Manager copy used by VeraCrypt (bootmgfw_ms.vc) was not found in the firmware Secure Boot database (db). After successful pre-boot authentication, the handoff to Windows may fail and the computer may return to the VeraCrypt password prompt.\n\nBefore restarting this computer, do not disable or revoke Microsoft Windows Production PCA 2011 unless Windows Boot Manager has migrated to a Windows UEFI CA 2023-signed version and the firmware db contains Windows UEFI CA 2023. Apply the Windows Secure Boot certificate updates, then run VeraCrypt Repair/Reinstall if needed. Make sure you have an up-to-date VeraCrypt Rescue Disk before restarting.</entry>
<entry lang="en" key="SYSENC_EFI_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: VeraCrypt could not validate the installed EFI bootloader files against one complete embedded resource set and confirm that all known required signing CAs are present in db and not listed by dbx. Firmware may reject VeraCrypt when Secure Boot is enabled.\n\nBefore booting with Secure Boot enabled, restore the required Microsoft certificates and current dbx as needed, then run VeraCrypt Repair/Reinstall. Do not remove Microsoft Corporation UEFI CA 2011 until db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and the actual installed files match VeraCrypt's 2023 set. This check cannot model every image-hash or security-version revocation. Make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: VeraCrypt could not validate the embedded signature and known-CA compatibility of the Windows Boot Manager it chainloads (bootmgfw_ms.vc). The file may be missing, unreadable, not a Windows Boot Manager, have an unrecognized embedded signer, or use a known signing CA that is absent from db or listed by dbx. The handoff to Windows may fail when Secure Boot is enabled.\n\nComplete or repair the Windows Secure Boot certificate and boot-manager update, keep the VeraCrypt System Favorites service enabled, and run VeraCrypt Repair/Reinstall. Repair also checks Windows' serviced EFI_EX/EFI copies for a compatible current Boot Manager. If Windows cannot start, temporarily disable Secure Boot to recover. Make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_PCA2011_MIGRATION_NEEDED">Warning: The embedded signature of the Windows Boot Manager used by VeraCrypt (bootmgfw_ms.vc) is still issued by Microsoft Windows Production PCA 2011, although firmware db already contains Windows UEFI CA 2023. Its known CA is currently allowed, but it will no longer start after the PCA 2011 certificate is added to dbx.\n\nDo not apply the PCA 2011 revocation (AvailableUpdates bit 0x80, including combined value 0x280) yet. First complete the Windows 2023 boot-manager update while the VeraCrypt System Favorites service is enabled, then run VeraCrypt Repair/Reinstall so VeraCrypt can import a compatible serviced EFI_EX/EFI copy. Verify the embedded issuer of bootmgfw_ms.vc is Windows UEFI CA 2023 and make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
</localization>
<!-- XML-Schema -->
<xs:schema attributeFormDefault="unqualified" elementFormDefault="qualified" xmlns:xs="http://www.w3.org/2001/XMLSchema">
+3 -2
View File
@@ -1688,8 +1688,9 @@
<entry lang="el" key="SYSENC_EFI_UNSUPPORTED_SECUREBOOT_CA">Το Secure Boot είναι ενεργοποιημένο, αλλά η βάση δεδομένων Secure Boot του υλικολογισμικού δεν εμπιστεύεται κανένα σύνολο Microsoft UEFI CA που υποστηρίζεται από τον EFI φορτωτή εκκίνησης του VeraCrypt. Ενεργοποιήστε είτε το Microsoft Corporation UEFI CA 2011 είτε και τα δύο Microsoft UEFI CA 2023 και Microsoft Option ROM UEFI CA 2023, και στη συνέχεια εκτελέστε το VeraCrypt Επιδιόρθωση/Επανεγκατάσταση. Εναλλακτικά, απενεργοποιήστε το Secure Boot.</entry>
<entry lang="el" key="MACOSX_CHECK_FILESYS">Αφού πατήσετε 'OK', θα ανοίξει ένα παράθυρο Τερματικού και θα ελεγχθεί το σύστημα αρχείων στον επιλεγμένο τόμο VeraCrypt χρησιμοποιώντας το 'diskutil'. Το αποτέλεσμα θα εμφανιστεί σε αυτό το παράθυρο.\n\nΕάν ο έλεγχος δεν μπορεί να ξεκινήσει, θα εκκινηθεί αντ' αυτού το Βοήθημα Δίσκων.</entry>
<entry lang="el" key="MACOSX_REPAIR_FILESYS">Αφού πατήσετε 'OK', θα ανοίξει ένα παράθυρο Τερματικού και θα γίνει προσπάθεια επιδιόρθωσης του συστήματος αρχείων στον επιλεγμένο τόμο VeraCrypt χρησιμοποιώντας το 'diskutil'. Το αποτέλεσμα θα εμφανιστεί σε αυτό το παράθυρο.\n\nΕάν η επιδιόρθωση δεν μπορεί να ξεκινήσει, θα εκκινηθεί αντ' αυτού το Βοήθημα Δίσκων.</entry>
<entry lang="en" key="SYSENC_EFI_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: Secure Boot is enabled, but the Microsoft UEFI CA that signs the installed VeraCrypt EFI bootloader was not found in the firmware Secure Boot database (db). The firmware may refuse to start VeraCrypt at the next reboot, so Windows will not start until Secure Boot is disabled or the trusted certificates/loader set are repaired.\n\nBefore restarting this computer, do not disable or remove Microsoft Corporation UEFI CA 2011 unless the firmware db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and VeraCrypt has been repaired/reinstalled so the 2023-signed loader set is installed. Enable the required Microsoft certificates in the BIOS/UEFI settings if needed, then run VeraCrypt Repair/Reinstall. Make sure you have an up-to-date VeraCrypt Rescue Disk before restarting.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: Secure Boot is enabled, but the Microsoft CA that signs the Windows Boot Manager copy used by VeraCrypt (bootmgfw_ms.vc) was not found in the firmware Secure Boot database (db). After successful pre-boot authentication, the handoff to Windows may fail and the computer may return to the VeraCrypt password prompt.\n\nBefore restarting this computer, do not disable or revoke Microsoft Windows Production PCA 2011 unless Windows Boot Manager has migrated to a Windows UEFI CA 2023-signed version and the firmware db contains Windows UEFI CA 2023. Apply the Windows Secure Boot certificate updates, then run VeraCrypt Repair/Reinstall if needed. Make sure you have an up-to-date VeraCrypt Rescue Disk before restarting.</entry>
<entry lang="en" key="SYSENC_EFI_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: VeraCrypt could not validate the installed EFI bootloader files against one complete embedded resource set and confirm that all known required signing CAs are present in db and not listed by dbx. Firmware may reject VeraCrypt when Secure Boot is enabled.\n\nBefore booting with Secure Boot enabled, restore the required Microsoft certificates and current dbx as needed, then run VeraCrypt Repair/Reinstall. Do not remove Microsoft Corporation UEFI CA 2011 until db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and the actual installed files match VeraCrypt's 2023 set. This check cannot model every image-hash or security-version revocation. Make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: VeraCrypt could not validate the embedded signature and known-CA compatibility of the Windows Boot Manager it chainloads (bootmgfw_ms.vc). The file may be missing, unreadable, not a Windows Boot Manager, have an unrecognized embedded signer, or use a known signing CA that is absent from db or listed by dbx. The handoff to Windows may fail when Secure Boot is enabled.\n\nComplete or repair the Windows Secure Boot certificate and boot-manager update, keep the VeraCrypt System Favorites service enabled, and run VeraCrypt Repair/Reinstall. Repair also checks Windows' serviced EFI_EX/EFI copies for a compatible current Boot Manager. If Windows cannot start, temporarily disable Secure Boot to recover. Make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_PCA2011_MIGRATION_NEEDED">Warning: The embedded signature of the Windows Boot Manager used by VeraCrypt (bootmgfw_ms.vc) is still issued by Microsoft Windows Production PCA 2011, although firmware db already contains Windows UEFI CA 2023. Its known CA is currently allowed, but it will no longer start after the PCA 2011 certificate is added to dbx.\n\nDo not apply the PCA 2011 revocation (AvailableUpdates bit 0x80, including combined value 0x280) yet. First complete the Windows 2023 boot-manager update while the VeraCrypt System Favorites service is enabled, then run VeraCrypt Repair/Reinstall so VeraCrypt can import a compatible serviced EFI_EX/EFI copy. Verify the embedded issuer of bootmgfw_ms.vc is Windows UEFI CA 2023 and make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
</localization>
<xs:schema attributeFormDefault="unqualified" elementFormDefault="qualified" xmlns:xs="http://www.w3.org/2001/XMLSchema">
<xs:element name="VeraCrypt">
+3 -2
View File
@@ -1688,8 +1688,9 @@
<entry lang="es" key="SYSENC_EFI_UNSUPPORTED_SECUREBOOT_CA">Secure Boot está habilitado, pero la base de datos de Secure Boot del firmware no confía en ningún conjunto de CA UEFI de Microsoft compatible con el cargador de arranque EFI de VeraCrypt. Habilite Microsoft Corporation UEFI CA 2011 o tanto Microsoft UEFI CA 2023 como Microsoft Option ROM UEFI CA 2023, y luego ejecute la opción Reparar/Reinstalar de VeraCrypt. Alternativamente, deshabilite Secure Boot.</entry>
<entry lang="es" key="MACOSX_CHECK_FILESYS">Después de pulsar 'Aceptar', se abrirá una ventana de Terminal para comprobar el sistema de archivos del volumen VeraCrypt seleccionado usando 'diskutil'. El resultado se mostrará en esa ventana.\n\nSi no se puede iniciar la comprobación, se iniciará en su lugar la Utilidad de Discos.</entry>
<entry lang="es" key="MACOSX_REPAIR_FILESYS">Después de pulsar 'Aceptar', se abrirá una ventana de Terminal para intentar reparar el sistema de archivos del volumen VeraCrypt seleccionado usando 'diskutil'. El resultado se mostrará en esa ventana.\n\nSi no se puede iniciar la reparación, se iniciará en su lugar la Utilidad de Discos.</entry>
<entry lang="en" key="SYSENC_EFI_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: Secure Boot is enabled, but the Microsoft UEFI CA that signs the installed VeraCrypt EFI bootloader was not found in the firmware Secure Boot database (db). The firmware may refuse to start VeraCrypt at the next reboot, so Windows will not start until Secure Boot is disabled or the trusted certificates/loader set are repaired.\n\nBefore restarting this computer, do not disable or remove Microsoft Corporation UEFI CA 2011 unless the firmware db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and VeraCrypt has been repaired/reinstalled so the 2023-signed loader set is installed. Enable the required Microsoft certificates in the BIOS/UEFI settings if needed, then run VeraCrypt Repair/Reinstall. Make sure you have an up-to-date VeraCrypt Rescue Disk before restarting.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: Secure Boot is enabled, but the Microsoft CA that signs the Windows Boot Manager copy used by VeraCrypt (bootmgfw_ms.vc) was not found in the firmware Secure Boot database (db). After successful pre-boot authentication, the handoff to Windows may fail and the computer may return to the VeraCrypt password prompt.\n\nBefore restarting this computer, do not disable or revoke Microsoft Windows Production PCA 2011 unless Windows Boot Manager has migrated to a Windows UEFI CA 2023-signed version and the firmware db contains Windows UEFI CA 2023. Apply the Windows Secure Boot certificate updates, then run VeraCrypt Repair/Reinstall if needed. Make sure you have an up-to-date VeraCrypt Rescue Disk before restarting.</entry>
<entry lang="en" key="SYSENC_EFI_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: VeraCrypt could not validate the installed EFI bootloader files against one complete embedded resource set and confirm that all known required signing CAs are present in db and not listed by dbx. Firmware may reject VeraCrypt when Secure Boot is enabled.\n\nBefore booting with Secure Boot enabled, restore the required Microsoft certificates and current dbx as needed, then run VeraCrypt Repair/Reinstall. Do not remove Microsoft Corporation UEFI CA 2011 until db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and the actual installed files match VeraCrypt's 2023 set. This check cannot model every image-hash or security-version revocation. Make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: VeraCrypt could not validate the embedded signature and known-CA compatibility of the Windows Boot Manager it chainloads (bootmgfw_ms.vc). The file may be missing, unreadable, not a Windows Boot Manager, have an unrecognized embedded signer, or use a known signing CA that is absent from db or listed by dbx. The handoff to Windows may fail when Secure Boot is enabled.\n\nComplete or repair the Windows Secure Boot certificate and boot-manager update, keep the VeraCrypt System Favorites service enabled, and run VeraCrypt Repair/Reinstall. Repair also checks Windows' serviced EFI_EX/EFI copies for a compatible current Boot Manager. If Windows cannot start, temporarily disable Secure Boot to recover. Make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_PCA2011_MIGRATION_NEEDED">Warning: The embedded signature of the Windows Boot Manager used by VeraCrypt (bootmgfw_ms.vc) is still issued by Microsoft Windows Production PCA 2011, although firmware db already contains Windows UEFI CA 2023. Its known CA is currently allowed, but it will no longer start after the PCA 2011 certificate is added to dbx.\n\nDo not apply the PCA 2011 revocation (AvailableUpdates bit 0x80, including combined value 0x280) yet. First complete the Windows 2023 boot-manager update while the VeraCrypt System Favorites service is enabled, then run VeraCrypt Repair/Reinstall so VeraCrypt can import a compatible serviced EFI_EX/EFI copy. Verify the embedded issuer of bootmgfw_ms.vc is Windows UEFI CA 2023 and make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
</localization>
<xs:schema attributeFormDefault="unqualified" elementFormDefault="qualified" xmlns:xs="http://www.w3.org/2001/XMLSchema">
<xs:element name="VeraCrypt">
+3 -2
View File
@@ -1688,8 +1688,9 @@
<entry lang="et" key="SYSENC_EFI_UNSUPPORTED_SECUREBOOT_CA">Secure Boot on lubatud, kuid püsivara Secure Boot andmebaas ei usalda ühtegi Microsoft UEFI CA komplekti, mida VeraCrypti EFI alglaadur toetab. Lubage kas Microsoft Corporation UEFI CA 2011 või korraga Microsoft UEFI CA 2023 ja Microsoft Option ROM UEFI CA 2023, seejärel käivitage VeraCrypti valik "Parandage/installige uuesti". Teise võimalusena keelake Secure Boot.</entry>
<entry lang="et" key="MACOSX_CHECK_FILESYS">Pärast nupu 'Olgu' vajutamist avaneb Terminali aken ja valitud VeraCrypti köite failisüsteemi kontrollitakse käsuga 'diskutil'. Tulemus kuvatakse selles aknas.\n\nKui kontrolli ei saa käivitada, käivitatakse selle asemel Kettautiliit.</entry>
<entry lang="et" key="MACOSX_REPAIR_FILESYS">Pärast nupu 'Olgu' vajutamist avaneb Terminali aken ja valitud VeraCrypti köite failisüsteemi üritatakse parandada käsuga 'diskutil'. Tulemus kuvatakse selles aknas.\n\nKui parandust ei saa käivitada, käivitatakse selle asemel Kettautiliit.</entry>
<entry lang="en" key="SYSENC_EFI_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: Secure Boot is enabled, but the Microsoft UEFI CA that signs the installed VeraCrypt EFI bootloader was not found in the firmware Secure Boot database (db). The firmware may refuse to start VeraCrypt at the next reboot, so Windows will not start until Secure Boot is disabled or the trusted certificates/loader set are repaired.\n\nBefore restarting this computer, do not disable or remove Microsoft Corporation UEFI CA 2011 unless the firmware db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and VeraCrypt has been repaired/reinstalled so the 2023-signed loader set is installed. Enable the required Microsoft certificates in the BIOS/UEFI settings if needed, then run VeraCrypt Repair/Reinstall. Make sure you have an up-to-date VeraCrypt Rescue Disk before restarting.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: Secure Boot is enabled, but the Microsoft CA that signs the Windows Boot Manager copy used by VeraCrypt (bootmgfw_ms.vc) was not found in the firmware Secure Boot database (db). After successful pre-boot authentication, the handoff to Windows may fail and the computer may return to the VeraCrypt password prompt.\n\nBefore restarting this computer, do not disable or revoke Microsoft Windows Production PCA 2011 unless Windows Boot Manager has migrated to a Windows UEFI CA 2023-signed version and the firmware db contains Windows UEFI CA 2023. Apply the Windows Secure Boot certificate updates, then run VeraCrypt Repair/Reinstall if needed. Make sure you have an up-to-date VeraCrypt Rescue Disk before restarting.</entry>
<entry lang="en" key="SYSENC_EFI_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: VeraCrypt could not validate the installed EFI bootloader files against one complete embedded resource set and confirm that all known required signing CAs are present in db and not listed by dbx. Firmware may reject VeraCrypt when Secure Boot is enabled.\n\nBefore booting with Secure Boot enabled, restore the required Microsoft certificates and current dbx as needed, then run VeraCrypt Repair/Reinstall. Do not remove Microsoft Corporation UEFI CA 2011 until db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and the actual installed files match VeraCrypt's 2023 set. This check cannot model every image-hash or security-version revocation. Make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: VeraCrypt could not validate the embedded signature and known-CA compatibility of the Windows Boot Manager it chainloads (bootmgfw_ms.vc). The file may be missing, unreadable, not a Windows Boot Manager, have an unrecognized embedded signer, or use a known signing CA that is absent from db or listed by dbx. The handoff to Windows may fail when Secure Boot is enabled.\n\nComplete or repair the Windows Secure Boot certificate and boot-manager update, keep the VeraCrypt System Favorites service enabled, and run VeraCrypt Repair/Reinstall. Repair also checks Windows' serviced EFI_EX/EFI copies for a compatible current Boot Manager. If Windows cannot start, temporarily disable Secure Boot to recover. Make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_PCA2011_MIGRATION_NEEDED">Warning: The embedded signature of the Windows Boot Manager used by VeraCrypt (bootmgfw_ms.vc) is still issued by Microsoft Windows Production PCA 2011, although firmware db already contains Windows UEFI CA 2023. Its known CA is currently allowed, but it will no longer start after the PCA 2011 certificate is added to dbx.\n\nDo not apply the PCA 2011 revocation (AvailableUpdates bit 0x80, including combined value 0x280) yet. First complete the Windows 2023 boot-manager update while the VeraCrypt System Favorites service is enabled, then run VeraCrypt Repair/Reinstall so VeraCrypt can import a compatible serviced EFI_EX/EFI copy. Verify the embedded issuer of bootmgfw_ms.vc is Windows UEFI CA 2023 and make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
</localization>
<xs:schema attributeFormDefault="unqualified" elementFormDefault="qualified" xmlns:xs="http://www.w3.org/2001/XMLSchema">
<xs:element name="VeraCrypt">
+3 -2
View File
@@ -1688,8 +1688,9 @@
<entry lang="eu" key="SYSENC_EFI_UNSUPPORTED_SECUREBOOT_CA">Secure Boot gaituta dago, baina firmwareko Secure Boot datu-baseak ez du fidagarritzat hartzen VeraCrypt-en EFI abiarazleak onartzen duen Microsoft UEFI CA multzorik. Gaitu Microsoft Corporation UEFI CA 2011, edo bai Microsoft UEFI CA 2023 bai Microsoft Option ROM UEFI CA 2023, eta ondoren exekutatu VeraCrypt Konpondu/Berinstalatu. Bestela, desgaitu Secure Boot.</entry>
<entry lang="eu" key="MACOSX_CHECK_FILESYS">'Ados' sakatu ondoren Terminal leiho bat irekiko da eta hautatutako VeraCrypt bolumenaren fitxategi sistema egiaztatuko da 'diskutil' erabiliz. Emaitza leiho horretan erakutsiko da.\n\nEgiaztapena ezin bada hasi, Disko-utilitatea abiaraziko da horren ordez.</entry>
<entry lang="eu" key="MACOSX_REPAIR_FILESYS">'Ados' sakatu ondoren Terminal leiho bat irekiko da eta hautatutako VeraCrypt bolumenaren fitxategi sistema konpontzen saiatuko da 'diskutil' erabiliz. Emaitza leiho horretan erakutsiko da.\n\nKonponketa ezin bada hasi, Disko-utilitatea abiaraziko da horren ordez.</entry>
<entry lang="en" key="SYSENC_EFI_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: Secure Boot is enabled, but the Microsoft UEFI CA that signs the installed VeraCrypt EFI bootloader was not found in the firmware Secure Boot database (db). The firmware may refuse to start VeraCrypt at the next reboot, so Windows will not start until Secure Boot is disabled or the trusted certificates/loader set are repaired.\n\nBefore restarting this computer, do not disable or remove Microsoft Corporation UEFI CA 2011 unless the firmware db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and VeraCrypt has been repaired/reinstalled so the 2023-signed loader set is installed. Enable the required Microsoft certificates in the BIOS/UEFI settings if needed, then run VeraCrypt Repair/Reinstall. Make sure you have an up-to-date VeraCrypt Rescue Disk before restarting.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: Secure Boot is enabled, but the Microsoft CA that signs the Windows Boot Manager copy used by VeraCrypt (bootmgfw_ms.vc) was not found in the firmware Secure Boot database (db). After successful pre-boot authentication, the handoff to Windows may fail and the computer may return to the VeraCrypt password prompt.\n\nBefore restarting this computer, do not disable or revoke Microsoft Windows Production PCA 2011 unless Windows Boot Manager has migrated to a Windows UEFI CA 2023-signed version and the firmware db contains Windows UEFI CA 2023. Apply the Windows Secure Boot certificate updates, then run VeraCrypt Repair/Reinstall if needed. Make sure you have an up-to-date VeraCrypt Rescue Disk before restarting.</entry>
<entry lang="en" key="SYSENC_EFI_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: VeraCrypt could not validate the installed EFI bootloader files against one complete embedded resource set and confirm that all known required signing CAs are present in db and not listed by dbx. Firmware may reject VeraCrypt when Secure Boot is enabled.\n\nBefore booting with Secure Boot enabled, restore the required Microsoft certificates and current dbx as needed, then run VeraCrypt Repair/Reinstall. Do not remove Microsoft Corporation UEFI CA 2011 until db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and the actual installed files match VeraCrypt's 2023 set. This check cannot model every image-hash or security-version revocation. Make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: VeraCrypt could not validate the embedded signature and known-CA compatibility of the Windows Boot Manager it chainloads (bootmgfw_ms.vc). The file may be missing, unreadable, not a Windows Boot Manager, have an unrecognized embedded signer, or use a known signing CA that is absent from db or listed by dbx. The handoff to Windows may fail when Secure Boot is enabled.\n\nComplete or repair the Windows Secure Boot certificate and boot-manager update, keep the VeraCrypt System Favorites service enabled, and run VeraCrypt Repair/Reinstall. Repair also checks Windows' serviced EFI_EX/EFI copies for a compatible current Boot Manager. If Windows cannot start, temporarily disable Secure Boot to recover. Make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_PCA2011_MIGRATION_NEEDED">Warning: The embedded signature of the Windows Boot Manager used by VeraCrypt (bootmgfw_ms.vc) is still issued by Microsoft Windows Production PCA 2011, although firmware db already contains Windows UEFI CA 2023. Its known CA is currently allowed, but it will no longer start after the PCA 2011 certificate is added to dbx.\n\nDo not apply the PCA 2011 revocation (AvailableUpdates bit 0x80, including combined value 0x280) yet. First complete the Windows 2023 boot-manager update while the VeraCrypt System Favorites service is enabled, then run VeraCrypt Repair/Reinstall so VeraCrypt can import a compatible serviced EFI_EX/EFI copy. Verify the embedded issuer of bootmgfw_ms.vc is Windows UEFI CA 2023 and make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
</localization>
<xs:schema attributeFormDefault="unqualified" elementFormDefault="qualified" xmlns:xs="http://www.w3.org/2001/XMLSchema">
<xs:element name="VeraCrypt">
+3 -2
View File
@@ -1688,8 +1688,9 @@
<entry lang="fa" key="SYSENC_EFI_UNSUPPORTED_SECUREBOOT_CA">Secure Boot فعال است، اما پایگاه داده Secure Boot در میان‌افزار به هیچ مجموعه Microsoft UEFI CA که توسط بوت‌لودر EFI وراکریپت پشتیبانی می‌شود اعتماد ندارد. یا Microsoft Corporation UEFI CA 2011 را فعال کنید، یا هر دو Microsoft UEFI CA 2023 و Microsoft Option ROM UEFI CA 2023 را فعال کنید، سپس گزینه Repair/Reinstall را در VeraCrypt اجرا کنید. همچنین می‌توانید Secure Boot را غیرفعال کنید.</entry>
<entry lang="fa" key="MACOSX_CHECK_FILESYS">پس از فشار دادن 'قبول'، یک پنجره Terminal باز می‌شود و فایل سیستم حجم VeraCrypt انتخاب‌شده را با استفاده از 'diskutil' بررسی می‌کند. نتیجه در همان پنجره نمایش داده می‌شود.\n\nاگر بررسی قابل شروع نباشد، به‌جای آن Disk Utility اجرا خواهد شد.</entry>
<entry lang="fa" key="MACOSX_REPAIR_FILESYS">پس از فشار دادن 'قبول'، یک پنجره Terminal باز می‌شود و تلاش می‌کند فایل سیستم حجم VeraCrypt انتخاب‌شده را با استفاده از 'diskutil' تعمیر کند. نتیجه در همان پنجره نمایش داده می‌شود.\n\nاگر تعمیر قابل شروع نباشد، به‌جای آن Disk Utility اجرا خواهد شد.</entry>
<entry lang="en" key="SYSENC_EFI_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: Secure Boot is enabled, but the Microsoft UEFI CA that signs the installed VeraCrypt EFI bootloader was not found in the firmware Secure Boot database (db). The firmware may refuse to start VeraCrypt at the next reboot, so Windows will not start until Secure Boot is disabled or the trusted certificates/loader set are repaired.\n\nBefore restarting this computer, do not disable or remove Microsoft Corporation UEFI CA 2011 unless the firmware db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and VeraCrypt has been repaired/reinstalled so the 2023-signed loader set is installed. Enable the required Microsoft certificates in the BIOS/UEFI settings if needed, then run VeraCrypt Repair/Reinstall. Make sure you have an up-to-date VeraCrypt Rescue Disk before restarting.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: Secure Boot is enabled, but the Microsoft CA that signs the Windows Boot Manager copy used by VeraCrypt (bootmgfw_ms.vc) was not found in the firmware Secure Boot database (db). After successful pre-boot authentication, the handoff to Windows may fail and the computer may return to the VeraCrypt password prompt.\n\nBefore restarting this computer, do not disable or revoke Microsoft Windows Production PCA 2011 unless Windows Boot Manager has migrated to a Windows UEFI CA 2023-signed version and the firmware db contains Windows UEFI CA 2023. Apply the Windows Secure Boot certificate updates, then run VeraCrypt Repair/Reinstall if needed. Make sure you have an up-to-date VeraCrypt Rescue Disk before restarting.</entry>
<entry lang="en" key="SYSENC_EFI_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: VeraCrypt could not validate the installed EFI bootloader files against one complete embedded resource set and confirm that all known required signing CAs are present in db and not listed by dbx. Firmware may reject VeraCrypt when Secure Boot is enabled.\n\nBefore booting with Secure Boot enabled, restore the required Microsoft certificates and current dbx as needed, then run VeraCrypt Repair/Reinstall. Do not remove Microsoft Corporation UEFI CA 2011 until db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and the actual installed files match VeraCrypt's 2023 set. This check cannot model every image-hash or security-version revocation. Make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: VeraCrypt could not validate the embedded signature and known-CA compatibility of the Windows Boot Manager it chainloads (bootmgfw_ms.vc). The file may be missing, unreadable, not a Windows Boot Manager, have an unrecognized embedded signer, or use a known signing CA that is absent from db or listed by dbx. The handoff to Windows may fail when Secure Boot is enabled.\n\nComplete or repair the Windows Secure Boot certificate and boot-manager update, keep the VeraCrypt System Favorites service enabled, and run VeraCrypt Repair/Reinstall. Repair also checks Windows' serviced EFI_EX/EFI copies for a compatible current Boot Manager. If Windows cannot start, temporarily disable Secure Boot to recover. Make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_PCA2011_MIGRATION_NEEDED">Warning: The embedded signature of the Windows Boot Manager used by VeraCrypt (bootmgfw_ms.vc) is still issued by Microsoft Windows Production PCA 2011, although firmware db already contains Windows UEFI CA 2023. Its known CA is currently allowed, but it will no longer start after the PCA 2011 certificate is added to dbx.\n\nDo not apply the PCA 2011 revocation (AvailableUpdates bit 0x80, including combined value 0x280) yet. First complete the Windows 2023 boot-manager update while the VeraCrypt System Favorites service is enabled, then run VeraCrypt Repair/Reinstall so VeraCrypt can import a compatible serviced EFI_EX/EFI copy. Verify the embedded issuer of bootmgfw_ms.vc is Windows UEFI CA 2023 and make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
</localization>
<xs:schema attributeFormDefault="unqualified" elementFormDefault="qualified" xmlns:xs="http://www.w3.org/2001/XMLSchema">
<xs:element name="VeraCrypt">
+3 -2
View File
@@ -1688,8 +1688,9 @@
<entry lang="fi" key="SYSENC_EFI_UNSUPPORTED_SECUREBOOT_CA">Secure Boot on käytössä, mutta laiteohjelmiston Secure Boot -tietokanta ei luota yhteenkään Microsoft UEFI CA -joukkoon, jota VeraCryptin EFI-käynnistysohjelma tukee. Ota käyttöön joko Microsoft Corporation UEFI CA 2011 tai sekä Microsoft UEFI CA 2023 että Microsoft Option ROM UEFI CA 2023, ja suorita sitten VeraCryptin Korjaa/asenna uudelleen -toiminto. Vaihtoehtoisesti poista Secure Boot käytöstä.</entry>
<entry lang="fi" key="MACOSX_CHECK_FILESYS">Kun painat 'OK', Pääte-ikkuna avautuu ja siinä tarkistetaan valitun VeraCrypt-taltion tiedostojärjestelmä komennolla 'diskutil'. Tulos näytetään kyseisessä ikkunassa.\n\nJos tarkistusta ei voida käynnistää, Levytyökalu käynnistetään sen sijaan.</entry>
<entry lang="fi" key="MACOSX_REPAIR_FILESYS">Kun painat 'OK', Pääte-ikkuna avautuu ja siinä yritetään korjata valitun VeraCrypt-taltion tiedostojärjestelmä komennolla 'diskutil'. Tulos näytetään kyseisessä ikkunassa.\n\nJos korjausta ei voida käynnistää, Levytyökalu käynnistetään sen sijaan.</entry>
<entry lang="en" key="SYSENC_EFI_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: Secure Boot is enabled, but the Microsoft UEFI CA that signs the installed VeraCrypt EFI bootloader was not found in the firmware Secure Boot database (db). The firmware may refuse to start VeraCrypt at the next reboot, so Windows will not start until Secure Boot is disabled or the trusted certificates/loader set are repaired.\n\nBefore restarting this computer, do not disable or remove Microsoft Corporation UEFI CA 2011 unless the firmware db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and VeraCrypt has been repaired/reinstalled so the 2023-signed loader set is installed. Enable the required Microsoft certificates in the BIOS/UEFI settings if needed, then run VeraCrypt Repair/Reinstall. Make sure you have an up-to-date VeraCrypt Rescue Disk before restarting.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: Secure Boot is enabled, but the Microsoft CA that signs the Windows Boot Manager copy used by VeraCrypt (bootmgfw_ms.vc) was not found in the firmware Secure Boot database (db). After successful pre-boot authentication, the handoff to Windows may fail and the computer may return to the VeraCrypt password prompt.\n\nBefore restarting this computer, do not disable or revoke Microsoft Windows Production PCA 2011 unless Windows Boot Manager has migrated to a Windows UEFI CA 2023-signed version and the firmware db contains Windows UEFI CA 2023. Apply the Windows Secure Boot certificate updates, then run VeraCrypt Repair/Reinstall if needed. Make sure you have an up-to-date VeraCrypt Rescue Disk before restarting.</entry>
<entry lang="en" key="SYSENC_EFI_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: VeraCrypt could not validate the installed EFI bootloader files against one complete embedded resource set and confirm that all known required signing CAs are present in db and not listed by dbx. Firmware may reject VeraCrypt when Secure Boot is enabled.\n\nBefore booting with Secure Boot enabled, restore the required Microsoft certificates and current dbx as needed, then run VeraCrypt Repair/Reinstall. Do not remove Microsoft Corporation UEFI CA 2011 until db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and the actual installed files match VeraCrypt's 2023 set. This check cannot model every image-hash or security-version revocation. Make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: VeraCrypt could not validate the embedded signature and known-CA compatibility of the Windows Boot Manager it chainloads (bootmgfw_ms.vc). The file may be missing, unreadable, not a Windows Boot Manager, have an unrecognized embedded signer, or use a known signing CA that is absent from db or listed by dbx. The handoff to Windows may fail when Secure Boot is enabled.\n\nComplete or repair the Windows Secure Boot certificate and boot-manager update, keep the VeraCrypt System Favorites service enabled, and run VeraCrypt Repair/Reinstall. Repair also checks Windows' serviced EFI_EX/EFI copies for a compatible current Boot Manager. If Windows cannot start, temporarily disable Secure Boot to recover. Make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_PCA2011_MIGRATION_NEEDED">Warning: The embedded signature of the Windows Boot Manager used by VeraCrypt (bootmgfw_ms.vc) is still issued by Microsoft Windows Production PCA 2011, although firmware db already contains Windows UEFI CA 2023. Its known CA is currently allowed, but it will no longer start after the PCA 2011 certificate is added to dbx.\n\nDo not apply the PCA 2011 revocation (AvailableUpdates bit 0x80, including combined value 0x280) yet. First complete the Windows 2023 boot-manager update while the VeraCrypt System Favorites service is enabled, then run VeraCrypt Repair/Reinstall so VeraCrypt can import a compatible serviced EFI_EX/EFI copy. Verify the embedded issuer of bootmgfw_ms.vc is Windows UEFI CA 2023 and make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
</localization>
<xs:schema attributeFormDefault="unqualified" elementFormDefault="qualified" xmlns:xs="http://www.w3.org/2001/XMLSchema">
<xs:element name="VeraCrypt">
+3 -2
View File
@@ -1688,8 +1688,9 @@
<entry lang="fr" key="SYSENC_EFI_UNSUPPORTED_SECUREBOOT_CA">Secure Boot est activé, mais la base de données Secure Boot du firmware ne fait confiance à aucun ensemble Microsoft UEFI CA pris en charge par le chargeur de démarrage EFI de VeraCrypt. Activez soit Microsoft Corporation UEFI CA 2011, soit à la fois Microsoft UEFI CA 2023 et Microsoft Option ROM UEFI CA 2023, puis exécutez loption Réparer/Réinstaller de VeraCrypt. Vous pouvez également désactiver Secure Boot.</entry>
<entry lang="fr" key="MACOSX_CHECK_FILESYS">Après avoir cliqué sur 'OK', une fenêtre Terminal souvrira pour vérifier le système de fichiers du volume VeraCrypt sélectionné à laide de 'diskutil'. Le résultat sera affiché dans cette fenêtre.\n\nSi la vérification ne peut pas être lancée, lUtilitaire de disque sera lancé à la place.</entry>
<entry lang="fr" key="MACOSX_REPAIR_FILESYS">Après avoir cliqué sur 'OK', une fenêtre Terminal souvrira pour tenter de réparer le système de fichiers du volume VeraCrypt sélectionné à laide de 'diskutil'. Le résultat sera affiché dans cette fenêtre.\n\nSi la réparation ne peut pas être lancée, lUtilitaire de disque sera lancé à la place.</entry>
<entry lang="en" key="SYSENC_EFI_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: Secure Boot is enabled, but the Microsoft UEFI CA that signs the installed VeraCrypt EFI bootloader was not found in the firmware Secure Boot database (db). The firmware may refuse to start VeraCrypt at the next reboot, so Windows will not start until Secure Boot is disabled or the trusted certificates/loader set are repaired.\n\nBefore restarting this computer, do not disable or remove Microsoft Corporation UEFI CA 2011 unless the firmware db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and VeraCrypt has been repaired/reinstalled so the 2023-signed loader set is installed. Enable the required Microsoft certificates in the BIOS/UEFI settings if needed, then run VeraCrypt Repair/Reinstall. Make sure you have an up-to-date VeraCrypt Rescue Disk before restarting.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: Secure Boot is enabled, but the Microsoft CA that signs the Windows Boot Manager copy used by VeraCrypt (bootmgfw_ms.vc) was not found in the firmware Secure Boot database (db). After successful pre-boot authentication, the handoff to Windows may fail and the computer may return to the VeraCrypt password prompt.\n\nBefore restarting this computer, do not disable or revoke Microsoft Windows Production PCA 2011 unless Windows Boot Manager has migrated to a Windows UEFI CA 2023-signed version and the firmware db contains Windows UEFI CA 2023. Apply the Windows Secure Boot certificate updates, then run VeraCrypt Repair/Reinstall if needed. Make sure you have an up-to-date VeraCrypt Rescue Disk before restarting.</entry>
<entry lang="en" key="SYSENC_EFI_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: VeraCrypt could not validate the installed EFI bootloader files against one complete embedded resource set and confirm that all known required signing CAs are present in db and not listed by dbx. Firmware may reject VeraCrypt when Secure Boot is enabled.\n\nBefore booting with Secure Boot enabled, restore the required Microsoft certificates and current dbx as needed, then run VeraCrypt Repair/Reinstall. Do not remove Microsoft Corporation UEFI CA 2011 until db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and the actual installed files match VeraCrypt's 2023 set. This check cannot model every image-hash or security-version revocation. Make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: VeraCrypt could not validate the embedded signature and known-CA compatibility of the Windows Boot Manager it chainloads (bootmgfw_ms.vc). The file may be missing, unreadable, not a Windows Boot Manager, have an unrecognized embedded signer, or use a known signing CA that is absent from db or listed by dbx. The handoff to Windows may fail when Secure Boot is enabled.\n\nComplete or repair the Windows Secure Boot certificate and boot-manager update, keep the VeraCrypt System Favorites service enabled, and run VeraCrypt Repair/Reinstall. Repair also checks Windows' serviced EFI_EX/EFI copies for a compatible current Boot Manager. If Windows cannot start, temporarily disable Secure Boot to recover. Make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_PCA2011_MIGRATION_NEEDED">Warning: The embedded signature of the Windows Boot Manager used by VeraCrypt (bootmgfw_ms.vc) is still issued by Microsoft Windows Production PCA 2011, although firmware db already contains Windows UEFI CA 2023. Its known CA is currently allowed, but it will no longer start after the PCA 2011 certificate is added to dbx.\n\nDo not apply the PCA 2011 revocation (AvailableUpdates bit 0x80, including combined value 0x280) yet. First complete the Windows 2023 boot-manager update while the VeraCrypt System Favorites service is enabled, then run VeraCrypt Repair/Reinstall so VeraCrypt can import a compatible serviced EFI_EX/EFI copy. Verify the embedded issuer of bootmgfw_ms.vc is Windows UEFI CA 2023 and make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
</localization>
<xs:schema attributeFormDefault="unqualified" elementFormDefault="qualified" xmlns:xs="http://www.w3.org/2001/XMLSchema">
<xs:element name="VeraCrypt">
+3 -2
View File
@@ -1688,8 +1688,9 @@
<entry lang="he" key="SYSENC_EFI_UNSUPPORTED_SECUREBOOT_CA">Secure Boot מופעל, אך מסד הנתונים של Secure Boot בקושחה אינו נותן אמון באף ערכת Microsoft UEFI CA הנתמכת על ידי טוען האתחול EFI של VeraCrypt. הפעל את Microsoft Corporation UEFI CA 2011, או את שניהם Microsoft UEFI CA 2023 ו-Microsoft Option ROM UEFI CA 2023, ולאחר מכן הפעל את אפשרות התיקון/התקנה מחדש של VeraCrypt. לחלופין, השבת את Secure Boot.</entry>
<entry lang="he" key="MACOSX_CHECK_FILESYS">לאחר שתלחץ על 'אישור', ייפתח חלון Terminal ותתבצע בדיקה של מערכת הקבצים באמצעי האחסון VeraCrypt שנבחר באמצעות 'diskutil'. התוצאה תוצג בחלון זה.\n\nאם לא ניתן להתחיל את הבדיקה, יופעל במקום זאת כלי העזר לכוננים.</entry>
<entry lang="he" key="MACOSX_REPAIR_FILESYS">לאחר שתלחץ על 'אישור', ייפתח חלון Terminal וייעשה ניסיון לתקן את מערכת הקבצים באמצעי האחסון VeraCrypt שנבחר באמצעות 'diskutil'. התוצאה תוצג בחלון זה.\n\nאם לא ניתן להתחיל את התיקון, יופעל במקום זאת כלי העזר לכוננים.</entry>
<entry lang="en" key="SYSENC_EFI_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: Secure Boot is enabled, but the Microsoft UEFI CA that signs the installed VeraCrypt EFI bootloader was not found in the firmware Secure Boot database (db). The firmware may refuse to start VeraCrypt at the next reboot, so Windows will not start until Secure Boot is disabled or the trusted certificates/loader set are repaired.\n\nBefore restarting this computer, do not disable or remove Microsoft Corporation UEFI CA 2011 unless the firmware db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and VeraCrypt has been repaired/reinstalled so the 2023-signed loader set is installed. Enable the required Microsoft certificates in the BIOS/UEFI settings if needed, then run VeraCrypt Repair/Reinstall. Make sure you have an up-to-date VeraCrypt Rescue Disk before restarting.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: Secure Boot is enabled, but the Microsoft CA that signs the Windows Boot Manager copy used by VeraCrypt (bootmgfw_ms.vc) was not found in the firmware Secure Boot database (db). After successful pre-boot authentication, the handoff to Windows may fail and the computer may return to the VeraCrypt password prompt.\n\nBefore restarting this computer, do not disable or revoke Microsoft Windows Production PCA 2011 unless Windows Boot Manager has migrated to a Windows UEFI CA 2023-signed version and the firmware db contains Windows UEFI CA 2023. Apply the Windows Secure Boot certificate updates, then run VeraCrypt Repair/Reinstall if needed. Make sure you have an up-to-date VeraCrypt Rescue Disk before restarting.</entry>
<entry lang="en" key="SYSENC_EFI_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: VeraCrypt could not validate the installed EFI bootloader files against one complete embedded resource set and confirm that all known required signing CAs are present in db and not listed by dbx. Firmware may reject VeraCrypt when Secure Boot is enabled.\n\nBefore booting with Secure Boot enabled, restore the required Microsoft certificates and current dbx as needed, then run VeraCrypt Repair/Reinstall. Do not remove Microsoft Corporation UEFI CA 2011 until db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and the actual installed files match VeraCrypt's 2023 set. This check cannot model every image-hash or security-version revocation. Make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: VeraCrypt could not validate the embedded signature and known-CA compatibility of the Windows Boot Manager it chainloads (bootmgfw_ms.vc). The file may be missing, unreadable, not a Windows Boot Manager, have an unrecognized embedded signer, or use a known signing CA that is absent from db or listed by dbx. The handoff to Windows may fail when Secure Boot is enabled.\n\nComplete or repair the Windows Secure Boot certificate and boot-manager update, keep the VeraCrypt System Favorites service enabled, and run VeraCrypt Repair/Reinstall. Repair also checks Windows' serviced EFI_EX/EFI copies for a compatible current Boot Manager. If Windows cannot start, temporarily disable Secure Boot to recover. Make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_PCA2011_MIGRATION_NEEDED">Warning: The embedded signature of the Windows Boot Manager used by VeraCrypt (bootmgfw_ms.vc) is still issued by Microsoft Windows Production PCA 2011, although firmware db already contains Windows UEFI CA 2023. Its known CA is currently allowed, but it will no longer start after the PCA 2011 certificate is added to dbx.\n\nDo not apply the PCA 2011 revocation (AvailableUpdates bit 0x80, including combined value 0x280) yet. First complete the Windows 2023 boot-manager update while the VeraCrypt System Favorites service is enabled, then run VeraCrypt Repair/Reinstall so VeraCrypt can import a compatible serviced EFI_EX/EFI copy. Verify the embedded issuer of bootmgfw_ms.vc is Windows UEFI CA 2023 and make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
</localization>
<xs:schema attributeFormDefault="unqualified" elementFormDefault="qualified">
<xs:element name="VeraCrypt">
+3 -2
View File
@@ -1688,8 +1688,9 @@
<entry lang="hu" key="SYSENC_EFI_UNSUPPORTED_SECUREBOOT_CA">A Secure Boot engedélyezve van, de a firmware Secure Boot adatbázisa nem bízik meg egyetlen olyan Microsoft UEFI CA-készletben sem, amelyet a VeraCrypt EFI rendszerbetöltője támogat. Engedélyezze vagy a Microsoft Corporation UEFI CA 2011-et, vagy egyszerre a Microsoft UEFI CA 2023-at és a Microsoft Option ROM UEFI CA 2023-at, majd futtassa a VeraCrypt javítási/újratelepítési műveletét. Alternatív megoldásként tiltsa le a Secure Bootot.</entry>
<entry lang="hu" key="MACOSX_CHECK_FILESYS">Az 'OK' megnyomása után megnyílik egy Terminál ablak, és a 'diskutil' segítségével ellenőrzi a kiválasztott VeraCrypt kötet fájlrendszerét. Az eredmény ebben az ablakban jelenik meg.\n\nHa az ellenőrzés nem indítható el, helyette a Lemezkezelő indul el.</entry>
<entry lang="hu" key="MACOSX_REPAIR_FILESYS">Az 'OK' megnyomása után megnyílik egy Terminál ablak, és megkísérli kijavítani a kiválasztott VeraCrypt kötet fájlrendszerét a 'diskutil' segítségével. Az eredmény ebben az ablakban jelenik meg.\n\nHa a javítás nem indítható el, helyette a Lemezkezelő indul el.</entry>
<entry lang="en" key="SYSENC_EFI_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: Secure Boot is enabled, but the Microsoft UEFI CA that signs the installed VeraCrypt EFI bootloader was not found in the firmware Secure Boot database (db). The firmware may refuse to start VeraCrypt at the next reboot, so Windows will not start until Secure Boot is disabled or the trusted certificates/loader set are repaired.\n\nBefore restarting this computer, do not disable or remove Microsoft Corporation UEFI CA 2011 unless the firmware db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and VeraCrypt has been repaired/reinstalled so the 2023-signed loader set is installed. Enable the required Microsoft certificates in the BIOS/UEFI settings if needed, then run VeraCrypt Repair/Reinstall. Make sure you have an up-to-date VeraCrypt Rescue Disk before restarting.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: Secure Boot is enabled, but the Microsoft CA that signs the Windows Boot Manager copy used by VeraCrypt (bootmgfw_ms.vc) was not found in the firmware Secure Boot database (db). After successful pre-boot authentication, the handoff to Windows may fail and the computer may return to the VeraCrypt password prompt.\n\nBefore restarting this computer, do not disable or revoke Microsoft Windows Production PCA 2011 unless Windows Boot Manager has migrated to a Windows UEFI CA 2023-signed version and the firmware db contains Windows UEFI CA 2023. Apply the Windows Secure Boot certificate updates, then run VeraCrypt Repair/Reinstall if needed. Make sure you have an up-to-date VeraCrypt Rescue Disk before restarting.</entry>
<entry lang="en" key="SYSENC_EFI_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: VeraCrypt could not validate the installed EFI bootloader files against one complete embedded resource set and confirm that all known required signing CAs are present in db and not listed by dbx. Firmware may reject VeraCrypt when Secure Boot is enabled.\n\nBefore booting with Secure Boot enabled, restore the required Microsoft certificates and current dbx as needed, then run VeraCrypt Repair/Reinstall. Do not remove Microsoft Corporation UEFI CA 2011 until db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and the actual installed files match VeraCrypt's 2023 set. This check cannot model every image-hash or security-version revocation. Make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: VeraCrypt could not validate the embedded signature and known-CA compatibility of the Windows Boot Manager it chainloads (bootmgfw_ms.vc). The file may be missing, unreadable, not a Windows Boot Manager, have an unrecognized embedded signer, or use a known signing CA that is absent from db or listed by dbx. The handoff to Windows may fail when Secure Boot is enabled.\n\nComplete or repair the Windows Secure Boot certificate and boot-manager update, keep the VeraCrypt System Favorites service enabled, and run VeraCrypt Repair/Reinstall. Repair also checks Windows' serviced EFI_EX/EFI copies for a compatible current Boot Manager. If Windows cannot start, temporarily disable Secure Boot to recover. Make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_PCA2011_MIGRATION_NEEDED">Warning: The embedded signature of the Windows Boot Manager used by VeraCrypt (bootmgfw_ms.vc) is still issued by Microsoft Windows Production PCA 2011, although firmware db already contains Windows UEFI CA 2023. Its known CA is currently allowed, but it will no longer start after the PCA 2011 certificate is added to dbx.\n\nDo not apply the PCA 2011 revocation (AvailableUpdates bit 0x80, including combined value 0x280) yet. First complete the Windows 2023 boot-manager update while the VeraCrypt System Favorites service is enabled, then run VeraCrypt Repair/Reinstall so VeraCrypt can import a compatible serviced EFI_EX/EFI copy. Verify the embedded issuer of bootmgfw_ms.vc is Windows UEFI CA 2023 and make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
</localization>
<xs:schema attributeFormDefault="unqualified" elementFormDefault="qualified" xmlns:xs="http://www.w3.org/2001/XMLSchema">
<xs:element name="VeraCrypt">
+3 -2
View File
@@ -1688,8 +1688,9 @@
<entry lang="id" key="SYSENC_EFI_UNSUPPORTED_SECUREBOOT_CA">Secure Boot diaktifkan, tetapi basis data Secure Boot pada firmware tidak mempercayai set Microsoft UEFI CA apa pun yang didukung oleh bootloader EFI VeraCrypt. Aktifkan Microsoft Corporation UEFI CA 2011, atau aktifkan keduanya Microsoft UEFI CA 2023 dan Microsoft Option ROM UEFI CA 2023, lalu jalankan opsi Perbaiki/Pasang Ulang VeraCrypt. Sebagai alternatif, nonaktifkan Secure Boot.</entry>
<entry lang="id" key="MACOSX_CHECK_FILESYS">Sebuah jendela Terminal akan terbuka setelah Anda menekan 'Ok' dan memeriksa sistem berkas pada volume VeraCrypt yang dipilih menggunakan 'diskutil'. Hasilnya akan ditampilkan di jendela tersebut.\n\nJika pemeriksaan tidak dapat dimulai, Utilitas Disk akan dijalankan sebagai gantinya.</entry>
<entry lang="id" key="MACOSX_REPAIR_FILESYS">Sebuah jendela Terminal akan terbuka setelah Anda menekan 'Ok' dan mencoba memperbaiki sistem berkas pada volume VeraCrypt yang dipilih menggunakan 'diskutil'. Hasilnya akan ditampilkan di jendela tersebut.\n\nJika perbaikan tidak dapat dimulai, Utilitas Disk akan dijalankan sebagai gantinya.</entry>
<entry lang="en" key="SYSENC_EFI_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: Secure Boot is enabled, but the Microsoft UEFI CA that signs the installed VeraCrypt EFI bootloader was not found in the firmware Secure Boot database (db). The firmware may refuse to start VeraCrypt at the next reboot, so Windows will not start until Secure Boot is disabled or the trusted certificates/loader set are repaired.\n\nBefore restarting this computer, do not disable or remove Microsoft Corporation UEFI CA 2011 unless the firmware db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and VeraCrypt has been repaired/reinstalled so the 2023-signed loader set is installed. Enable the required Microsoft certificates in the BIOS/UEFI settings if needed, then run VeraCrypt Repair/Reinstall. Make sure you have an up-to-date VeraCrypt Rescue Disk before restarting.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: Secure Boot is enabled, but the Microsoft CA that signs the Windows Boot Manager copy used by VeraCrypt (bootmgfw_ms.vc) was not found in the firmware Secure Boot database (db). After successful pre-boot authentication, the handoff to Windows may fail and the computer may return to the VeraCrypt password prompt.\n\nBefore restarting this computer, do not disable or revoke Microsoft Windows Production PCA 2011 unless Windows Boot Manager has migrated to a Windows UEFI CA 2023-signed version and the firmware db contains Windows UEFI CA 2023. Apply the Windows Secure Boot certificate updates, then run VeraCrypt Repair/Reinstall if needed. Make sure you have an up-to-date VeraCrypt Rescue Disk before restarting.</entry>
<entry lang="en" key="SYSENC_EFI_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: VeraCrypt could not validate the installed EFI bootloader files against one complete embedded resource set and confirm that all known required signing CAs are present in db and not listed by dbx. Firmware may reject VeraCrypt when Secure Boot is enabled.\n\nBefore booting with Secure Boot enabled, restore the required Microsoft certificates and current dbx as needed, then run VeraCrypt Repair/Reinstall. Do not remove Microsoft Corporation UEFI CA 2011 until db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and the actual installed files match VeraCrypt's 2023 set. This check cannot model every image-hash or security-version revocation. Make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: VeraCrypt could not validate the embedded signature and known-CA compatibility of the Windows Boot Manager it chainloads (bootmgfw_ms.vc). The file may be missing, unreadable, not a Windows Boot Manager, have an unrecognized embedded signer, or use a known signing CA that is absent from db or listed by dbx. The handoff to Windows may fail when Secure Boot is enabled.\n\nComplete or repair the Windows Secure Boot certificate and boot-manager update, keep the VeraCrypt System Favorites service enabled, and run VeraCrypt Repair/Reinstall. Repair also checks Windows' serviced EFI_EX/EFI copies for a compatible current Boot Manager. If Windows cannot start, temporarily disable Secure Boot to recover. Make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_PCA2011_MIGRATION_NEEDED">Warning: The embedded signature of the Windows Boot Manager used by VeraCrypt (bootmgfw_ms.vc) is still issued by Microsoft Windows Production PCA 2011, although firmware db already contains Windows UEFI CA 2023. Its known CA is currently allowed, but it will no longer start after the PCA 2011 certificate is added to dbx.\n\nDo not apply the PCA 2011 revocation (AvailableUpdates bit 0x80, including combined value 0x280) yet. First complete the Windows 2023 boot-manager update while the VeraCrypt System Favorites service is enabled, then run VeraCrypt Repair/Reinstall so VeraCrypt can import a compatible serviced EFI_EX/EFI copy. Verify the embedded issuer of bootmgfw_ms.vc is Windows UEFI CA 2023 and make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
</localization>
<xs:schema attributeFormDefault="unqualified" elementFormDefault="qualified" xmlns:xs="http://www.w3.org/2001/XMLSchema">
<xs:element name="VeraCrypt">
+3 -2
View File
@@ -1688,8 +1688,9 @@
<entry lang="it" key="SYSENC_EFI_UNSUPPORTED_SECUREBOOT_CA">Secure Boot è abilitato, ma il database di Secure Boot del firmware non considera attendibile nessun set Microsoft UEFI CA supportato dal boot loader EFI di VeraCrypt. Abilita Microsoft Corporation UEFI CA 2011 oppure sia Microsoft UEFI CA 2023 sia Microsoft Option ROM UEFI CA 2023, quindi esegui l'opzione Ripara/Reinstalla di VeraCrypt. In alternativa, disabilita Secure Boot.</entry>
<entry lang="it" key="MACOSX_CHECK_FILESYS">Dopo aver premuto 'OK' si aprirà una finestra del Terminale che controllerà il file system del volume VeraCrypt selezionato usando 'diskutil'. Il risultato sarà mostrato in quella finestra.\n\nSe il controllo non può essere avviato, verrà avviata Utility Disco al suo posto.</entry>
<entry lang="it" key="MACOSX_REPAIR_FILESYS">Dopo aver premuto 'OK' si aprirà una finestra del Terminale che tenterà di riparare il file system del volume VeraCrypt selezionato usando 'diskutil'. Il risultato sarà mostrato in quella finestra.\n\nSe la riparazione non può essere avviata, verrà avviata Utility Disco al suo posto.</entry>
<entry lang="en" key="SYSENC_EFI_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: Secure Boot is enabled, but the Microsoft UEFI CA that signs the installed VeraCrypt EFI bootloader was not found in the firmware Secure Boot database (db). The firmware may refuse to start VeraCrypt at the next reboot, so Windows will not start until Secure Boot is disabled or the trusted certificates/loader set are repaired.\n\nBefore restarting this computer, do not disable or remove Microsoft Corporation UEFI CA 2011 unless the firmware db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and VeraCrypt has been repaired/reinstalled so the 2023-signed loader set is installed. Enable the required Microsoft certificates in the BIOS/UEFI settings if needed, then run VeraCrypt Repair/Reinstall. Make sure you have an up-to-date VeraCrypt Rescue Disk before restarting.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: Secure Boot is enabled, but the Microsoft CA that signs the Windows Boot Manager copy used by VeraCrypt (bootmgfw_ms.vc) was not found in the firmware Secure Boot database (db). After successful pre-boot authentication, the handoff to Windows may fail and the computer may return to the VeraCrypt password prompt.\n\nBefore restarting this computer, do not disable or revoke Microsoft Windows Production PCA 2011 unless Windows Boot Manager has migrated to a Windows UEFI CA 2023-signed version and the firmware db contains Windows UEFI CA 2023. Apply the Windows Secure Boot certificate updates, then run VeraCrypt Repair/Reinstall if needed. Make sure you have an up-to-date VeraCrypt Rescue Disk before restarting.</entry>
<entry lang="en" key="SYSENC_EFI_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: VeraCrypt could not validate the installed EFI bootloader files against one complete embedded resource set and confirm that all known required signing CAs are present in db and not listed by dbx. Firmware may reject VeraCrypt when Secure Boot is enabled.\n\nBefore booting with Secure Boot enabled, restore the required Microsoft certificates and current dbx as needed, then run VeraCrypt Repair/Reinstall. Do not remove Microsoft Corporation UEFI CA 2011 until db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and the actual installed files match VeraCrypt's 2023 set. This check cannot model every image-hash or security-version revocation. Make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: VeraCrypt could not validate the embedded signature and known-CA compatibility of the Windows Boot Manager it chainloads (bootmgfw_ms.vc). The file may be missing, unreadable, not a Windows Boot Manager, have an unrecognized embedded signer, or use a known signing CA that is absent from db or listed by dbx. The handoff to Windows may fail when Secure Boot is enabled.\n\nComplete or repair the Windows Secure Boot certificate and boot-manager update, keep the VeraCrypt System Favorites service enabled, and run VeraCrypt Repair/Reinstall. Repair also checks Windows' serviced EFI_EX/EFI copies for a compatible current Boot Manager. If Windows cannot start, temporarily disable Secure Boot to recover. Make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_PCA2011_MIGRATION_NEEDED">Warning: The embedded signature of the Windows Boot Manager used by VeraCrypt (bootmgfw_ms.vc) is still issued by Microsoft Windows Production PCA 2011, although firmware db already contains Windows UEFI CA 2023. Its known CA is currently allowed, but it will no longer start after the PCA 2011 certificate is added to dbx.\n\nDo not apply the PCA 2011 revocation (AvailableUpdates bit 0x80, including combined value 0x280) yet. First complete the Windows 2023 boot-manager update while the VeraCrypt System Favorites service is enabled, then run VeraCrypt Repair/Reinstall so VeraCrypt can import a compatible serviced EFI_EX/EFI copy. Verify the embedded issuer of bootmgfw_ms.vc is Windows UEFI CA 2023 and make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
</localization>
<xs:schema attributeFormDefault="unqualified" elementFormDefault="qualified" xmlns:xs="http://www.w3.org/2001/XMLSchema">
<xs:element name="VeraCrypt">
+3 -2
View File
@@ -1688,8 +1688,9 @@
<entry lang="ja" key="SYSENC_EFI_UNSUPPORTED_SECUREBOOT_CA">Secure Boot が有効になっていますが、ファームウェアの Secure Boot データベースは VeraCrypt の EFI ブートローダーがサポートする Microsoft UEFI CA セットを信頼していません。Microsoft Corporation UEFI CA 2011、または Microsoft UEFI CA 2023 と Microsoft Option ROM UEFI CA 2023 の両方を有効にしてから、VeraCrypt のリペア/再インストールを実行してください。または、Secure Boot を無効にしてください。</entry>
<entry lang="ja" key="MACOSX_CHECK_FILESYS">[OK] を押すとターミナルウィンドウが開き、'diskutil' を使用して選択された VeraCrypt ボリュームのファイルシステムを検査します。結果はそのウィンドウに表示されます。\n\n検査を開始できない場合は、代わりにディスクユーティリティが起動します。</entry>
<entry lang="ja" key="MACOSX_REPAIR_FILESYS">[OK] を押すとターミナルウィンドウが開き、'diskutil' を使用して選択された VeraCrypt ボリュームのファイルシステムの修復を試みます。結果はそのウィンドウに表示されます。\n\n修復を開始できない場合は、代わりにディスクユーティリティが起動します。</entry>
<entry lang="en" key="SYSENC_EFI_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: Secure Boot is enabled, but the Microsoft UEFI CA that signs the installed VeraCrypt EFI bootloader was not found in the firmware Secure Boot database (db). The firmware may refuse to start VeraCrypt at the next reboot, so Windows will not start until Secure Boot is disabled or the trusted certificates/loader set are repaired.\n\nBefore restarting this computer, do not disable or remove Microsoft Corporation UEFI CA 2011 unless the firmware db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and VeraCrypt has been repaired/reinstalled so the 2023-signed loader set is installed. Enable the required Microsoft certificates in the BIOS/UEFI settings if needed, then run VeraCrypt Repair/Reinstall. Make sure you have an up-to-date VeraCrypt Rescue Disk before restarting.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: Secure Boot is enabled, but the Microsoft CA that signs the Windows Boot Manager copy used by VeraCrypt (bootmgfw_ms.vc) was not found in the firmware Secure Boot database (db). After successful pre-boot authentication, the handoff to Windows may fail and the computer may return to the VeraCrypt password prompt.\n\nBefore restarting this computer, do not disable or revoke Microsoft Windows Production PCA 2011 unless Windows Boot Manager has migrated to a Windows UEFI CA 2023-signed version and the firmware db contains Windows UEFI CA 2023. Apply the Windows Secure Boot certificate updates, then run VeraCrypt Repair/Reinstall if needed. Make sure you have an up-to-date VeraCrypt Rescue Disk before restarting.</entry>
<entry lang="en" key="SYSENC_EFI_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: VeraCrypt could not validate the installed EFI bootloader files against one complete embedded resource set and confirm that all known required signing CAs are present in db and not listed by dbx. Firmware may reject VeraCrypt when Secure Boot is enabled.\n\nBefore booting with Secure Boot enabled, restore the required Microsoft certificates and current dbx as needed, then run VeraCrypt Repair/Reinstall. Do not remove Microsoft Corporation UEFI CA 2011 until db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and the actual installed files match VeraCrypt's 2023 set. This check cannot model every image-hash or security-version revocation. Make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: VeraCrypt could not validate the embedded signature and known-CA compatibility of the Windows Boot Manager it chainloads (bootmgfw_ms.vc). The file may be missing, unreadable, not a Windows Boot Manager, have an unrecognized embedded signer, or use a known signing CA that is absent from db or listed by dbx. The handoff to Windows may fail when Secure Boot is enabled.\n\nComplete or repair the Windows Secure Boot certificate and boot-manager update, keep the VeraCrypt System Favorites service enabled, and run VeraCrypt Repair/Reinstall. Repair also checks Windows' serviced EFI_EX/EFI copies for a compatible current Boot Manager. If Windows cannot start, temporarily disable Secure Boot to recover. Make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_PCA2011_MIGRATION_NEEDED">Warning: The embedded signature of the Windows Boot Manager used by VeraCrypt (bootmgfw_ms.vc) is still issued by Microsoft Windows Production PCA 2011, although firmware db already contains Windows UEFI CA 2023. Its known CA is currently allowed, but it will no longer start after the PCA 2011 certificate is added to dbx.\n\nDo not apply the PCA 2011 revocation (AvailableUpdates bit 0x80, including combined value 0x280) yet. First complete the Windows 2023 boot-manager update while the VeraCrypt System Favorites service is enabled, then run VeraCrypt Repair/Reinstall so VeraCrypt can import a compatible serviced EFI_EX/EFI copy. Verify the embedded issuer of bootmgfw_ms.vc is Windows UEFI CA 2023 and make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
</localization>
<xs:schema attributeFormDefault="unqualified" elementFormDefault="qualified" xmlns:xs="http://www.w3.org/2001/XMLSchema">
<xs:element name="VeraCrypt">
+3 -2
View File
@@ -1688,8 +1688,9 @@
<entry lang="ka" key="SYSENC_EFI_UNSUPPORTED_SECUREBOOT_CA">Secure Boot ჩართულია, მაგრამ მიკროპროგრამის Secure Boot მონაცემთა ბაზა არ ენდობა Microsoft UEFI CA-ის არცერთ კომპლექტს, რომელსაც VeraCrypt-ის EFI ჩამტვირთველი უჭერს მხარს. ჩართეთ ან Microsoft Corporation UEFI CA 2011, ან ორივე Microsoft UEFI CA 2023 და Microsoft Option ROM UEFI CA 2023, შემდეგ გაუშვით VeraCrypt აღდგენა/რეინსტალაცია. ალტერნატიულად, გამორთეთ Secure Boot.</entry>
<entry lang="ka" key="MACOSX_CHECK_FILESYS">'დიახ' ღილაკზე დაჭერის შემდეგ გაიხსნება ტერმინალის ფანჯარა და 'diskutil'-ის გამოყენებით შემოწმდება არჩეული VeraCrypt ტომის ფაილური სისტემა. შედეგი გამოჩნდება ამ ფანჯარაში.\n\nთუ შემოწმება ვერ დაიწყება, მის ნაცვლად გაეშვება დისკის უტილიტა.</entry>
<entry lang="ka" key="MACOSX_REPAIR_FILESYS">'დიახ' ღილაკზე დაჭერის შემდეგ გაიხსნება ტერმინალის ფანჯარა და 'diskutil'-ის გამოყენებით მოხდება არჩეული VeraCrypt ტომის ფაილური სისტემის შეკეთების მცდელობა. შედეგი გამოჩნდება ამ ფანჯარაში.\n\nთუ შეკეთება ვერ დაიწყება, მის ნაცვლად გაეშვება დისკის უტილიტა.</entry>
<entry lang="en" key="SYSENC_EFI_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: Secure Boot is enabled, but the Microsoft UEFI CA that signs the installed VeraCrypt EFI bootloader was not found in the firmware Secure Boot database (db). The firmware may refuse to start VeraCrypt at the next reboot, so Windows will not start until Secure Boot is disabled or the trusted certificates/loader set are repaired.\n\nBefore restarting this computer, do not disable or remove Microsoft Corporation UEFI CA 2011 unless the firmware db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and VeraCrypt has been repaired/reinstalled so the 2023-signed loader set is installed. Enable the required Microsoft certificates in the BIOS/UEFI settings if needed, then run VeraCrypt Repair/Reinstall. Make sure you have an up-to-date VeraCrypt Rescue Disk before restarting.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: Secure Boot is enabled, but the Microsoft CA that signs the Windows Boot Manager copy used by VeraCrypt (bootmgfw_ms.vc) was not found in the firmware Secure Boot database (db). After successful pre-boot authentication, the handoff to Windows may fail and the computer may return to the VeraCrypt password prompt.\n\nBefore restarting this computer, do not disable or revoke Microsoft Windows Production PCA 2011 unless Windows Boot Manager has migrated to a Windows UEFI CA 2023-signed version and the firmware db contains Windows UEFI CA 2023. Apply the Windows Secure Boot certificate updates, then run VeraCrypt Repair/Reinstall if needed. Make sure you have an up-to-date VeraCrypt Rescue Disk before restarting.</entry>
<entry lang="en" key="SYSENC_EFI_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: VeraCrypt could not validate the installed EFI bootloader files against one complete embedded resource set and confirm that all known required signing CAs are present in db and not listed by dbx. Firmware may reject VeraCrypt when Secure Boot is enabled.\n\nBefore booting with Secure Boot enabled, restore the required Microsoft certificates and current dbx as needed, then run VeraCrypt Repair/Reinstall. Do not remove Microsoft Corporation UEFI CA 2011 until db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and the actual installed files match VeraCrypt's 2023 set. This check cannot model every image-hash or security-version revocation. Make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: VeraCrypt could not validate the embedded signature and known-CA compatibility of the Windows Boot Manager it chainloads (bootmgfw_ms.vc). The file may be missing, unreadable, not a Windows Boot Manager, have an unrecognized embedded signer, or use a known signing CA that is absent from db or listed by dbx. The handoff to Windows may fail when Secure Boot is enabled.\n\nComplete or repair the Windows Secure Boot certificate and boot-manager update, keep the VeraCrypt System Favorites service enabled, and run VeraCrypt Repair/Reinstall. Repair also checks Windows' serviced EFI_EX/EFI copies for a compatible current Boot Manager. If Windows cannot start, temporarily disable Secure Boot to recover. Make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_PCA2011_MIGRATION_NEEDED">Warning: The embedded signature of the Windows Boot Manager used by VeraCrypt (bootmgfw_ms.vc) is still issued by Microsoft Windows Production PCA 2011, although firmware db already contains Windows UEFI CA 2023. Its known CA is currently allowed, but it will no longer start after the PCA 2011 certificate is added to dbx.\n\nDo not apply the PCA 2011 revocation (AvailableUpdates bit 0x80, including combined value 0x280) yet. First complete the Windows 2023 boot-manager update while the VeraCrypt System Favorites service is enabled, then run VeraCrypt Repair/Reinstall so VeraCrypt can import a compatible serviced EFI_EX/EFI copy. Verify the embedded issuer of bootmgfw_ms.vc is Windows UEFI CA 2023 and make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
</localization>
<xs:schema attributeFormDefault="unqualified" elementFormDefault="qualified" xmlns:xs="http://www.w3.org/2001/XMLSchema">
<xs:element name="VeraCrypt">
+3 -2
View File
@@ -1688,8 +1688,9 @@
<entry lang="ko" key="SYSENC_EFI_UNSUPPORTED_SECUREBOOT_CA">보안 부팅(Secure Boot)이 활성화되어 있지만 펌웨어의 Secure Boot 데이터베이스가 VeraCrypt의 EFI 부트 로더가 지원하는 어떤 Microsoft UEFI CA 세트도 신뢰하지 않습니다. Microsoft Corporation UEFI CA 2011을 활성화하거나 Microsoft UEFI CA 2023과 Microsoft Option ROM UEFI CA 2023을 모두 활성화한 다음 VeraCrypt 수리/재설치를 실행하세요. 또는 Secure Boot를 비활성화하세요.</entry>
<entry lang="ko" key="MACOSX_CHECK_FILESYS">'확인'을 누르면 터미널 창이 열리고 'diskutil'을 사용하여 선택한 VeraCrypt 볼륨의 파일 시스템을 검사합니다. 결과는 해당 창에 표시됩니다.\n\n검사를 시작할 수 없으면 대신 디스크 유틸리티가 실행됩니다.</entry>
<entry lang="ko" key="MACOSX_REPAIR_FILESYS">'확인'을 누르면 터미널 창이 열리고 'diskutil'을 사용하여 선택한 VeraCrypt 볼륨의 파일 시스템 복구를 시도합니다. 결과는 해당 창에 표시됩니다.\n\n복구를 시작할 수 없으면 대신 디스크 유틸리티가 실행됩니다.</entry>
<entry lang="en" key="SYSENC_EFI_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: Secure Boot is enabled, but the Microsoft UEFI CA that signs the installed VeraCrypt EFI bootloader was not found in the firmware Secure Boot database (db). The firmware may refuse to start VeraCrypt at the next reboot, so Windows will not start until Secure Boot is disabled or the trusted certificates/loader set are repaired.\n\nBefore restarting this computer, do not disable or remove Microsoft Corporation UEFI CA 2011 unless the firmware db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and VeraCrypt has been repaired/reinstalled so the 2023-signed loader set is installed. Enable the required Microsoft certificates in the BIOS/UEFI settings if needed, then run VeraCrypt Repair/Reinstall. Make sure you have an up-to-date VeraCrypt Rescue Disk before restarting.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: Secure Boot is enabled, but the Microsoft CA that signs the Windows Boot Manager copy used by VeraCrypt (bootmgfw_ms.vc) was not found in the firmware Secure Boot database (db). After successful pre-boot authentication, the handoff to Windows may fail and the computer may return to the VeraCrypt password prompt.\n\nBefore restarting this computer, do not disable or revoke Microsoft Windows Production PCA 2011 unless Windows Boot Manager has migrated to a Windows UEFI CA 2023-signed version and the firmware db contains Windows UEFI CA 2023. Apply the Windows Secure Boot certificate updates, then run VeraCrypt Repair/Reinstall if needed. Make sure you have an up-to-date VeraCrypt Rescue Disk before restarting.</entry>
<entry lang="en" key="SYSENC_EFI_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: VeraCrypt could not validate the installed EFI bootloader files against one complete embedded resource set and confirm that all known required signing CAs are present in db and not listed by dbx. Firmware may reject VeraCrypt when Secure Boot is enabled.\n\nBefore booting with Secure Boot enabled, restore the required Microsoft certificates and current dbx as needed, then run VeraCrypt Repair/Reinstall. Do not remove Microsoft Corporation UEFI CA 2011 until db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and the actual installed files match VeraCrypt's 2023 set. This check cannot model every image-hash or security-version revocation. Make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: VeraCrypt could not validate the embedded signature and known-CA compatibility of the Windows Boot Manager it chainloads (bootmgfw_ms.vc). The file may be missing, unreadable, not a Windows Boot Manager, have an unrecognized embedded signer, or use a known signing CA that is absent from db or listed by dbx. The handoff to Windows may fail when Secure Boot is enabled.\n\nComplete or repair the Windows Secure Boot certificate and boot-manager update, keep the VeraCrypt System Favorites service enabled, and run VeraCrypt Repair/Reinstall. Repair also checks Windows' serviced EFI_EX/EFI copies for a compatible current Boot Manager. If Windows cannot start, temporarily disable Secure Boot to recover. Make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_PCA2011_MIGRATION_NEEDED">Warning: The embedded signature of the Windows Boot Manager used by VeraCrypt (bootmgfw_ms.vc) is still issued by Microsoft Windows Production PCA 2011, although firmware db already contains Windows UEFI CA 2023. Its known CA is currently allowed, but it will no longer start after the PCA 2011 certificate is added to dbx.\n\nDo not apply the PCA 2011 revocation (AvailableUpdates bit 0x80, including combined value 0x280) yet. First complete the Windows 2023 boot-manager update while the VeraCrypt System Favorites service is enabled, then run VeraCrypt Repair/Reinstall so VeraCrypt can import a compatible serviced EFI_EX/EFI copy. Verify the embedded issuer of bootmgfw_ms.vc is Windows UEFI CA 2023 and make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
</localization>
<xs:schema attributeFormDefault="unqualified" elementFormDefault="qualified" xmlns:xs="http://www.w3.org/2001/XMLSchema">
<xs:element name="VeraCrypt">
+3 -2
View File
@@ -1688,8 +1688,9 @@
<entry lang="lv" key="SYSENC_EFI_UNSUPPORTED_SECUREBOOT_CA">Secure Boot ir iespējots, bet aparātprogrammatūras Secure Boot datubāze neuzticas nevienai Microsoft UEFI CA kopai, ko atbalsta VeraCrypt EFI sāknēšanas ielādētājs. Iespējojiet Microsoft Corporation UEFI CA 2011 vai gan Microsoft UEFI CA 2023, gan Microsoft Option ROM UEFI CA 2023, pēc tam palaidiet VeraCrypt labošanas/pārinstalēšanas opciju. Alternatīvi atspējojiet Secure Boot.</entry>
<entry lang="lv" key="MACOSX_CHECK_FILESYS">Pēc pogas 'Labi' nospiešanas tiks atvērts Termināļa logs un, izmantojot 'diskutil', tiks pārbaudīta atlasītā VeraCrypt sējuma datņu sistēma. Rezultāts tiks parādīts šajā logā.\n\nJa pārbaudi nevarēs sākt, tās vietā tiks palaista Diska utilīta.</entry>
<entry lang="lv" key="MACOSX_REPAIR_FILESYS">Pēc pogas 'Labi' nospiešanas tiks atvērts Termināļa logs un, izmantojot 'diskutil', tiks mēģināts salabot atlasītā VeraCrypt sējuma datņu sistēmu. Rezultāts tiks parādīts šajā logā.\n\nJa labošanu nevarēs sākt, tās vietā tiks palaista Diska utilīta.</entry>
<entry lang="en" key="SYSENC_EFI_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: Secure Boot is enabled, but the Microsoft UEFI CA that signs the installed VeraCrypt EFI bootloader was not found in the firmware Secure Boot database (db). The firmware may refuse to start VeraCrypt at the next reboot, so Windows will not start until Secure Boot is disabled or the trusted certificates/loader set are repaired.\n\nBefore restarting this computer, do not disable or remove Microsoft Corporation UEFI CA 2011 unless the firmware db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and VeraCrypt has been repaired/reinstalled so the 2023-signed loader set is installed. Enable the required Microsoft certificates in the BIOS/UEFI settings if needed, then run VeraCrypt Repair/Reinstall. Make sure you have an up-to-date VeraCrypt Rescue Disk before restarting.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: Secure Boot is enabled, but the Microsoft CA that signs the Windows Boot Manager copy used by VeraCrypt (bootmgfw_ms.vc) was not found in the firmware Secure Boot database (db). After successful pre-boot authentication, the handoff to Windows may fail and the computer may return to the VeraCrypt password prompt.\n\nBefore restarting this computer, do not disable or revoke Microsoft Windows Production PCA 2011 unless Windows Boot Manager has migrated to a Windows UEFI CA 2023-signed version and the firmware db contains Windows UEFI CA 2023. Apply the Windows Secure Boot certificate updates, then run VeraCrypt Repair/Reinstall if needed. Make sure you have an up-to-date VeraCrypt Rescue Disk before restarting.</entry>
<entry lang="en" key="SYSENC_EFI_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: VeraCrypt could not validate the installed EFI bootloader files against one complete embedded resource set and confirm that all known required signing CAs are present in db and not listed by dbx. Firmware may reject VeraCrypt when Secure Boot is enabled.\n\nBefore booting with Secure Boot enabled, restore the required Microsoft certificates and current dbx as needed, then run VeraCrypt Repair/Reinstall. Do not remove Microsoft Corporation UEFI CA 2011 until db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and the actual installed files match VeraCrypt's 2023 set. This check cannot model every image-hash or security-version revocation. Make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: VeraCrypt could not validate the embedded signature and known-CA compatibility of the Windows Boot Manager it chainloads (bootmgfw_ms.vc). The file may be missing, unreadable, not a Windows Boot Manager, have an unrecognized embedded signer, or use a known signing CA that is absent from db or listed by dbx. The handoff to Windows may fail when Secure Boot is enabled.\n\nComplete or repair the Windows Secure Boot certificate and boot-manager update, keep the VeraCrypt System Favorites service enabled, and run VeraCrypt Repair/Reinstall. Repair also checks Windows' serviced EFI_EX/EFI copies for a compatible current Boot Manager. If Windows cannot start, temporarily disable Secure Boot to recover. Make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_PCA2011_MIGRATION_NEEDED">Warning: The embedded signature of the Windows Boot Manager used by VeraCrypt (bootmgfw_ms.vc) is still issued by Microsoft Windows Production PCA 2011, although firmware db already contains Windows UEFI CA 2023. Its known CA is currently allowed, but it will no longer start after the PCA 2011 certificate is added to dbx.\n\nDo not apply the PCA 2011 revocation (AvailableUpdates bit 0x80, including combined value 0x280) yet. First complete the Windows 2023 boot-manager update while the VeraCrypt System Favorites service is enabled, then run VeraCrypt Repair/Reinstall so VeraCrypt can import a compatible serviced EFI_EX/EFI copy. Verify the embedded issuer of bootmgfw_ms.vc is Windows UEFI CA 2023 and make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
</localization>
<xs:schema attributeFormDefault="unqualified" elementFormDefault="qualified" xmlns:xs="http://www.w3.org/2001/XMLSchema">
<xs:element name="VeraCrypt">
+3 -2
View File
@@ -1690,8 +1690,9 @@
<entry lang="my" key="SYSENC_EFI_UNSUPPORTED_SECUREBOOT_CA">Secure Boot ကို ဖွင့်ထားသော်လည်း firmware ၏ Secure Boot database သည် VeraCrypt ၏ EFI bootloader က ပံ့ပိုးသော Microsoft UEFI CA အစုများထဲမှ မည်သည့်အစုကိုမျှ မယုံကြည်ပါ။ Microsoft Corporation UEFI CA 2011 ကို ဖွင့်ပါ၊ သို့မဟုတ် Microsoft UEFI CA 2023 နှင့် Microsoft Option ROM UEFI CA 2023 နှစ်ခုလုံးကို ဖွင့်ပါ၊ ထို့နောက် VeraCrypt ပြုပြင်ရန်/ပြန်ထည့်သွင်းရန် ကို လုပ်ဆောင်ပါ။ တစ်နည်းအားဖြင့် Secure Boot ကို ပိတ်ပါ။</entry>
<entry lang="my" key="MACOSX_CHECK_FILESYS">'ကောင်းပြီ' ကို နှိပ်ပြီးနောက် Terminal ဝင်းဒိုးတစ်ခု ဖွင့်လာမည်ဖြစ်ပြီး ရွေးချယ်ထားသော VeraCrypt volume ပေါ်ရှိ ဖိုင်စနစ်ကို 'diskutil' ဖြင့် စစ်ဆေးမည်။ ရလဒ်ကို ထိုဝင်းဒိုးတွင် ပြသမည်။\n\nစစ်ဆေးမှုကို စတင်၍ မရပါက Disk Utility ကို အစားထိုး ဖွင့်ပါမည်။</entry>
<entry lang="my" key="MACOSX_REPAIR_FILESYS">'ကောင်းပြီ' ကို နှိပ်ပြီးနောက် Terminal ဝင်းဒိုးတစ်ခု ဖွင့်လာမည်ဖြစ်ပြီး ရွေးချယ်ထားသော VeraCrypt volume ပေါ်ရှိ ဖိုင်စနစ်ကို 'diskutil' ဖြင့် ပြင်ဆင်ရန် ကြိုးစားမည်။ ရလဒ်ကို ထိုဝင်းဒိုးတွင် ပြသမည်။\n\nပြင်ဆင်မှုကို စတင်၍ မရပါက Disk Utility ကို အစားထိုး ဖွင့်ပါမည်။</entry>
<entry lang="en" key="SYSENC_EFI_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: Secure Boot is enabled, but the Microsoft UEFI CA that signs the installed VeraCrypt EFI bootloader was not found in the firmware Secure Boot database (db). The firmware may refuse to start VeraCrypt at the next reboot, so Windows will not start until Secure Boot is disabled or the trusted certificates/loader set are repaired.\n\nBefore restarting this computer, do not disable or remove Microsoft Corporation UEFI CA 2011 unless the firmware db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and VeraCrypt has been repaired/reinstalled so the 2023-signed loader set is installed. Enable the required Microsoft certificates in the BIOS/UEFI settings if needed, then run VeraCrypt Repair/Reinstall. Make sure you have an up-to-date VeraCrypt Rescue Disk before restarting.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: Secure Boot is enabled, but the Microsoft CA that signs the Windows Boot Manager copy used by VeraCrypt (bootmgfw_ms.vc) was not found in the firmware Secure Boot database (db). After successful pre-boot authentication, the handoff to Windows may fail and the computer may return to the VeraCrypt password prompt.\n\nBefore restarting this computer, do not disable or revoke Microsoft Windows Production PCA 2011 unless Windows Boot Manager has migrated to a Windows UEFI CA 2023-signed version and the firmware db contains Windows UEFI CA 2023. Apply the Windows Secure Boot certificate updates, then run VeraCrypt Repair/Reinstall if needed. Make sure you have an up-to-date VeraCrypt Rescue Disk before restarting.</entry>
<entry lang="en" key="SYSENC_EFI_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: VeraCrypt could not validate the installed EFI bootloader files against one complete embedded resource set and confirm that all known required signing CAs are present in db and not listed by dbx. Firmware may reject VeraCrypt when Secure Boot is enabled.\n\nBefore booting with Secure Boot enabled, restore the required Microsoft certificates and current dbx as needed, then run VeraCrypt Repair/Reinstall. Do not remove Microsoft Corporation UEFI CA 2011 until db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and the actual installed files match VeraCrypt's 2023 set. This check cannot model every image-hash or security-version revocation. Make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: VeraCrypt could not validate the embedded signature and known-CA compatibility of the Windows Boot Manager it chainloads (bootmgfw_ms.vc). The file may be missing, unreadable, not a Windows Boot Manager, have an unrecognized embedded signer, or use a known signing CA that is absent from db or listed by dbx. The handoff to Windows may fail when Secure Boot is enabled.\n\nComplete or repair the Windows Secure Boot certificate and boot-manager update, keep the VeraCrypt System Favorites service enabled, and run VeraCrypt Repair/Reinstall. Repair also checks Windows' serviced EFI_EX/EFI copies for a compatible current Boot Manager. If Windows cannot start, temporarily disable Secure Boot to recover. Make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_PCA2011_MIGRATION_NEEDED">Warning: The embedded signature of the Windows Boot Manager used by VeraCrypt (bootmgfw_ms.vc) is still issued by Microsoft Windows Production PCA 2011, although firmware db already contains Windows UEFI CA 2023. Its known CA is currently allowed, but it will no longer start after the PCA 2011 certificate is added to dbx.\n\nDo not apply the PCA 2011 revocation (AvailableUpdates bit 0x80, including combined value 0x280) yet. First complete the Windows 2023 boot-manager update while the VeraCrypt System Favorites service is enabled, then run VeraCrypt Repair/Reinstall so VeraCrypt can import a compatible serviced EFI_EX/EFI copy. Verify the embedded issuer of bootmgfw_ms.vc is Windows UEFI CA 2023 and make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
</localization>
<xs:schema xmlns:xs="http://www.w3.org/2001/XMLSchema" attributeFormDefault="unqualified" elementFormDefault="qualified">
<xs:element name="VeraCrypt">
+3 -2
View File
@@ -1688,8 +1688,9 @@
<entry lang="nb" key="SYSENC_EFI_UNSUPPORTED_SECUREBOOT_CA">Sikker oppstart (Secure Boot) er aktivert, men fastvarens database for sikker oppstart stoler ikke på noe Microsoft UEFI CA-sett som støttes av VeraCrypts EFI-oppstartslaster. Aktiver enten Microsoft Corporation UEFI CA 2011, eller både Microsoft UEFI CA 2023 og Microsoft Option ROM UEFI CA 2023, og kjør deretter VeraCrypt Reparer/Installer på nytt. Alternativt kan du deaktivere sikker oppstart.</entry>
<entry lang="nb" key="MACOSX_CHECK_FILESYS">Et terminalvindu åpnes etter at du har trykket på «OK», og filsystemet på det valgte VeraCrypt-volumet kontrolleres ved hjelp av «diskutil». Resultatet vises i det vinduet.\n\nHvis kontrollen ikke kan startes, åpnes Diskverktøy i stedet.</entry>
<entry lang="nb" key="MACOSX_REPAIR_FILESYS">Et terminalvindu åpnes etter at du har trykket på «OK», og det forsøkes å reparere filsystemet på det valgte VeraCrypt-volumet ved hjelp av «diskutil». Resultatet vises i det vinduet.\n\nHvis reparasjonen ikke kan startes, åpnes Diskverktøy i stedet.</entry>
<entry lang="en" key="SYSENC_EFI_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: Secure Boot is enabled, but the Microsoft UEFI CA that signs the installed VeraCrypt EFI bootloader was not found in the firmware Secure Boot database (db). The firmware may refuse to start VeraCrypt at the next reboot, so Windows will not start until Secure Boot is disabled or the trusted certificates/loader set are repaired.\n\nBefore restarting this computer, do not disable or remove Microsoft Corporation UEFI CA 2011 unless the firmware db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and VeraCrypt has been repaired/reinstalled so the 2023-signed loader set is installed. Enable the required Microsoft certificates in the BIOS/UEFI settings if needed, then run VeraCrypt Repair/Reinstall. Make sure you have an up-to-date VeraCrypt Rescue Disk before restarting.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: Secure Boot is enabled, but the Microsoft CA that signs the Windows Boot Manager copy used by VeraCrypt (bootmgfw_ms.vc) was not found in the firmware Secure Boot database (db). After successful pre-boot authentication, the handoff to Windows may fail and the computer may return to the VeraCrypt password prompt.\n\nBefore restarting this computer, do not disable or revoke Microsoft Windows Production PCA 2011 unless Windows Boot Manager has migrated to a Windows UEFI CA 2023-signed version and the firmware db contains Windows UEFI CA 2023. Apply the Windows Secure Boot certificate updates, then run VeraCrypt Repair/Reinstall if needed. Make sure you have an up-to-date VeraCrypt Rescue Disk before restarting.</entry>
<entry lang="en" key="SYSENC_EFI_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: VeraCrypt could not validate the installed EFI bootloader files against one complete embedded resource set and confirm that all known required signing CAs are present in db and not listed by dbx. Firmware may reject VeraCrypt when Secure Boot is enabled.\n\nBefore booting with Secure Boot enabled, restore the required Microsoft certificates and current dbx as needed, then run VeraCrypt Repair/Reinstall. Do not remove Microsoft Corporation UEFI CA 2011 until db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and the actual installed files match VeraCrypt's 2023 set. This check cannot model every image-hash or security-version revocation. Make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: VeraCrypt could not validate the embedded signature and known-CA compatibility of the Windows Boot Manager it chainloads (bootmgfw_ms.vc). The file may be missing, unreadable, not a Windows Boot Manager, have an unrecognized embedded signer, or use a known signing CA that is absent from db or listed by dbx. The handoff to Windows may fail when Secure Boot is enabled.\n\nComplete or repair the Windows Secure Boot certificate and boot-manager update, keep the VeraCrypt System Favorites service enabled, and run VeraCrypt Repair/Reinstall. Repair also checks Windows' serviced EFI_EX/EFI copies for a compatible current Boot Manager. If Windows cannot start, temporarily disable Secure Boot to recover. Make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_PCA2011_MIGRATION_NEEDED">Warning: The embedded signature of the Windows Boot Manager used by VeraCrypt (bootmgfw_ms.vc) is still issued by Microsoft Windows Production PCA 2011, although firmware db already contains Windows UEFI CA 2023. Its known CA is currently allowed, but it will no longer start after the PCA 2011 certificate is added to dbx.\n\nDo not apply the PCA 2011 revocation (AvailableUpdates bit 0x80, including combined value 0x280) yet. First complete the Windows 2023 boot-manager update while the VeraCrypt System Favorites service is enabled, then run VeraCrypt Repair/Reinstall so VeraCrypt can import a compatible serviced EFI_EX/EFI copy. Verify the embedded issuer of bootmgfw_ms.vc is Windows UEFI CA 2023 and make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
</localization>
<xs:schema attributeFormDefault="unqualified" elementFormDefault="qualified" xmlns:xs="http://www.w3.org/2001/XMLSchema">
<xs:element name="VeraCrypt">
+3 -2
View File
@@ -1688,8 +1688,9 @@
<entry lang="nl" key="SYSENC_EFI_UNSUPPORTED_SECUREBOOT_CA">Secure Boot is ingeschakeld, maar de Secure Boot-database van de firmware vertrouwt geen enkele Microsoft UEFI CA-set die door de EFI-bootloader van VeraCrypt wordt ondersteund. Schakel ofwel Microsoft Corporation UEFI CA 2011 in, ofwel zowel Microsoft UEFI CA 2023 als Microsoft Option ROM UEFI CA 2023, en voer vervolgens VeraCrypt repareren/opnieuw installeren uit. Als alternatief kan Secure Boot uitgeschakeld worden.</entry>
<entry lang="nl" key="MACOSX_CHECK_FILESYS">Nadat u op 'OK' hebt geklikt, wordt er een terminalvenster geopend waarin het bestandssysteem op het geselecteerde VeraCrypt-volume met behulp van 'diskutil' wordt gecontroleerd. Het resultaat wordt in dat venster weergegeven.\n\nAls de controle niet kan worden gestart, wordt in plaats daarvan Schijfhulpprogramma gestart.</entry>
<entry lang="nl" key="MACOSX_REPAIR_FILESYS">Nadat u op 'OK' hebt geklikt, wordt er een terminalvenster geopend en wordt er geprobeerd om het bestandssysteem op het geselecteerde VeraCrypt-volume te herstellen met behulp van 'diskutil'. Het resultaat wordt in dat venster weergegeven.\n\nAls het herstel niet kan worden gestart, wordt in plaats daarvan Schijfhulpprogramma gestart.</entry>
<entry lang="en" key="SYSENC_EFI_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: Secure Boot is enabled, but the Microsoft UEFI CA that signs the installed VeraCrypt EFI bootloader was not found in the firmware Secure Boot database (db). The firmware may refuse to start VeraCrypt at the next reboot, so Windows will not start until Secure Boot is disabled or the trusted certificates/loader set are repaired.\n\nBefore restarting this computer, do not disable or remove Microsoft Corporation UEFI CA 2011 unless the firmware db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and VeraCrypt has been repaired/reinstalled so the 2023-signed loader set is installed. Enable the required Microsoft certificates in the BIOS/UEFI settings if needed, then run VeraCrypt Repair/Reinstall. Make sure you have an up-to-date VeraCrypt Rescue Disk before restarting.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: Secure Boot is enabled, but the Microsoft CA that signs the Windows Boot Manager copy used by VeraCrypt (bootmgfw_ms.vc) was not found in the firmware Secure Boot database (db). After successful pre-boot authentication, the handoff to Windows may fail and the computer may return to the VeraCrypt password prompt.\n\nBefore restarting this computer, do not disable or revoke Microsoft Windows Production PCA 2011 unless Windows Boot Manager has migrated to a Windows UEFI CA 2023-signed version and the firmware db contains Windows UEFI CA 2023. Apply the Windows Secure Boot certificate updates, then run VeraCrypt Repair/Reinstall if needed. Make sure you have an up-to-date VeraCrypt Rescue Disk before restarting.</entry>
<entry lang="en" key="SYSENC_EFI_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: VeraCrypt could not validate the installed EFI bootloader files against one complete embedded resource set and confirm that all known required signing CAs are present in db and not listed by dbx. Firmware may reject VeraCrypt when Secure Boot is enabled.\n\nBefore booting with Secure Boot enabled, restore the required Microsoft certificates and current dbx as needed, then run VeraCrypt Repair/Reinstall. Do not remove Microsoft Corporation UEFI CA 2011 until db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and the actual installed files match VeraCrypt's 2023 set. This check cannot model every image-hash or security-version revocation. Make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: VeraCrypt could not validate the embedded signature and known-CA compatibility of the Windows Boot Manager it chainloads (bootmgfw_ms.vc). The file may be missing, unreadable, not a Windows Boot Manager, have an unrecognized embedded signer, or use a known signing CA that is absent from db or listed by dbx. The handoff to Windows may fail when Secure Boot is enabled.\n\nComplete or repair the Windows Secure Boot certificate and boot-manager update, keep the VeraCrypt System Favorites service enabled, and run VeraCrypt Repair/Reinstall. Repair also checks Windows' serviced EFI_EX/EFI copies for a compatible current Boot Manager. If Windows cannot start, temporarily disable Secure Boot to recover. Make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_PCA2011_MIGRATION_NEEDED">Warning: The embedded signature of the Windows Boot Manager used by VeraCrypt (bootmgfw_ms.vc) is still issued by Microsoft Windows Production PCA 2011, although firmware db already contains Windows UEFI CA 2023. Its known CA is currently allowed, but it will no longer start after the PCA 2011 certificate is added to dbx.\n\nDo not apply the PCA 2011 revocation (AvailableUpdates bit 0x80, including combined value 0x280) yet. First complete the Windows 2023 boot-manager update while the VeraCrypt System Favorites service is enabled, then run VeraCrypt Repair/Reinstall so VeraCrypt can import a compatible serviced EFI_EX/EFI copy. Verify the embedded issuer of bootmgfw_ms.vc is Windows UEFI CA 2023 and make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
</localization>
<xs:schema xmlns:xs="http://www.w3.org/2001/XMLSchema" attributeFormDefault="unqualified" elementFormDefault="qualified">
<xs:element name="VeraCrypt">
+3 -2
View File
@@ -1688,8 +1688,9 @@
<entry lang="nn" key="SYSENC_EFI_UNSUPPORTED_SECUREBOOT_CA">Secure Boot er slått på, men Secure Boot-databasen i fastvara stolar ikkje på noko Microsoft UEFI CA-sett som EFI-oppstartslastaren til VeraCrypt støttar. Slå på anten Microsoft Corporation UEFI CA 2011, eller både Microsoft UEFI CA 2023 og Microsoft Option ROM UEFI CA 2023, og køyr deretter Reparer/installer på nytt i VeraCrypt. Alternativt kan du slå av Secure Boot.</entry>
<entry lang="nn" key="MACOSX_CHECK_FILESYS">Eit Terminal-vindauge blir opna etter at du trykkjer på 'OK', og filsystemet på det valde VeraCrypt-volumet blir kontrollert med 'diskutil'. Resultatet blir vist i det vindauget.\n\nOm kontrollen ikkje kan startast, blir Diskverktøy starta i staden.</entry>
<entry lang="nn" key="MACOSX_REPAIR_FILESYS">Eit Terminal-vindauge blir opna etter at du trykkjer på 'OK', og det blir prøvd å reparera filsystemet på det valde VeraCrypt-volumet med 'diskutil'. Resultatet blir vist i det vindauget.\n\nOm reparasjonen ikkje kan startast, blir Diskverktøy starta i staden.</entry>
<entry lang="en" key="SYSENC_EFI_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: Secure Boot is enabled, but the Microsoft UEFI CA that signs the installed VeraCrypt EFI bootloader was not found in the firmware Secure Boot database (db). The firmware may refuse to start VeraCrypt at the next reboot, so Windows will not start until Secure Boot is disabled or the trusted certificates/loader set are repaired.\n\nBefore restarting this computer, do not disable or remove Microsoft Corporation UEFI CA 2011 unless the firmware db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and VeraCrypt has been repaired/reinstalled so the 2023-signed loader set is installed. Enable the required Microsoft certificates in the BIOS/UEFI settings if needed, then run VeraCrypt Repair/Reinstall. Make sure you have an up-to-date VeraCrypt Rescue Disk before restarting.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: Secure Boot is enabled, but the Microsoft CA that signs the Windows Boot Manager copy used by VeraCrypt (bootmgfw_ms.vc) was not found in the firmware Secure Boot database (db). After successful pre-boot authentication, the handoff to Windows may fail and the computer may return to the VeraCrypt password prompt.\n\nBefore restarting this computer, do not disable or revoke Microsoft Windows Production PCA 2011 unless Windows Boot Manager has migrated to a Windows UEFI CA 2023-signed version and the firmware db contains Windows UEFI CA 2023. Apply the Windows Secure Boot certificate updates, then run VeraCrypt Repair/Reinstall if needed. Make sure you have an up-to-date VeraCrypt Rescue Disk before restarting.</entry>
<entry lang="en" key="SYSENC_EFI_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: VeraCrypt could not validate the installed EFI bootloader files against one complete embedded resource set and confirm that all known required signing CAs are present in db and not listed by dbx. Firmware may reject VeraCrypt when Secure Boot is enabled.\n\nBefore booting with Secure Boot enabled, restore the required Microsoft certificates and current dbx as needed, then run VeraCrypt Repair/Reinstall. Do not remove Microsoft Corporation UEFI CA 2011 until db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and the actual installed files match VeraCrypt's 2023 set. This check cannot model every image-hash or security-version revocation. Make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: VeraCrypt could not validate the embedded signature and known-CA compatibility of the Windows Boot Manager it chainloads (bootmgfw_ms.vc). The file may be missing, unreadable, not a Windows Boot Manager, have an unrecognized embedded signer, or use a known signing CA that is absent from db or listed by dbx. The handoff to Windows may fail when Secure Boot is enabled.\n\nComplete or repair the Windows Secure Boot certificate and boot-manager update, keep the VeraCrypt System Favorites service enabled, and run VeraCrypt Repair/Reinstall. Repair also checks Windows' serviced EFI_EX/EFI copies for a compatible current Boot Manager. If Windows cannot start, temporarily disable Secure Boot to recover. Make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_PCA2011_MIGRATION_NEEDED">Warning: The embedded signature of the Windows Boot Manager used by VeraCrypt (bootmgfw_ms.vc) is still issued by Microsoft Windows Production PCA 2011, although firmware db already contains Windows UEFI CA 2023. Its known CA is currently allowed, but it will no longer start after the PCA 2011 certificate is added to dbx.\n\nDo not apply the PCA 2011 revocation (AvailableUpdates bit 0x80, including combined value 0x280) yet. First complete the Windows 2023 boot-manager update while the VeraCrypt System Favorites service is enabled, then run VeraCrypt Repair/Reinstall so VeraCrypt can import a compatible serviced EFI_EX/EFI copy. Verify the embedded issuer of bootmgfw_ms.vc is Windows UEFI CA 2023 and make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
</localization>
<xs:schema attributeFormDefault="unqualified" elementFormDefault="qualified" xmlns:xs="http://www.w3.org/2001/XMLSchema">
<xs:element name="VeraCrypt">
+4 -3
View File
@@ -1685,11 +1685,12 @@
<entry lang="pl" key="MACOSX_APFS_EROFS_HINT">System macOS zgłosił wybrane urządzenie jako tylko do odczytu. Jeśli jest to dysk APFS, upewnij się, że wybrano fizyczną partycję magazynu APFS, a nie wolumen syntezowany przez APFS. Użyj narzędzia dyskowego lub polecenia „diskutil list”, aby zidentyfikować partycję fizyczną, a następnie spróbuj ponownie.</entry>
<entry lang="pl" key="FAVORITE_PIM_OR_KDF_CHANGED">Ten wolumen jest zarejestrowany jako ulubiony wolumen systemu, a jego ustawienia PIM i/lub KDF zostały zmienione.\nCzy chcesz, aby VeraCrypt automatycznie zaktualizował konfigurację ulubionego wolumenu systemu (wymagane są uprawnienia administratora)?\n\nPamiętaj, że jeśli wybierzesz „Nie”, musisz ręcznie zaktualizować ulubiony wolumen systemu.</entry>
<entry lang="pl" key="PIM_RESET_ON_KDF_CHANGE_CONFIRM">Wybrany algorytm KDF używa innych parametrów PIM, więc VeraCrypt nie użyje ponownie bieżącego, niestandardowego PIM. Nowy nagłówek wolumenu będzie używał domyślnego PIM dla wybranego algorytmu KDF, chyba że wybierzesz „Użyj PIM” w sekcji „Nowe” i wpiszesz niestandardową wartość.\n\nCzy chcesz kontynuować?</entry>
<entry lang="pl" key="SYSENC_EFI_UNSUPPORTED_SECUREBOOT_CA">Funkcja Secure Boot jest włączona, ale baza danych oprogramowania układowego Secure Boot nie ufa żadnemu zestawowi certyfikatów Microsoft UEFI CA obsługiwanemu przez program rozruchowy EFI VeraCrypt. Włącz albo certyfikat Microsoft Corporation UEFI CA 2011, albo zarówno certyfikat Microsoft UEFI CA 2023, jak i certyfikat Microsoft Option ROM UEFI CA 2023, a następnie uruchom naprawę lub ponowną instalację VeraCrypt. Ewentualnie wyłącz funkcję Secure Boot.</entry>
<entry lang="pl" key="SYSENC_EFI_UNSUPPORTED_SECUREBOOT_CA">VeraCrypt nie może potwierdzić zgodności zestawu programu rozruchowego EFI z bieżącą konfiguracją Secure Boot. Wymagany urząd certyfikacji Microsoft może być nieobecny w db lub wymieniony w dbx, albo zmienna oprogramowania układowego może być nieczytelna lub uszkodzona. Brak zmiennej dbx jest prawidłowy; niezerowy błąd diagnostyczny dbx — nie.\n\nWłącz Microsoft Corporation UEFI CA 2011 albo oba certyfikaty Microsoft UEFI CA 2023 i Microsoft Option ROM UEFI CA 2023, a następnie uruchom naprawę/ponowną instalację VeraCrypt. Nie włączaj Secure Boot, dopóki diagnostyka nie wykaże pełnej zgodności.</entry>
<entry lang="pl" key="MACOSX_CHECK_FILESYS">Po kliknięciu przycisku „OK” otworzy się okno Terminala, w którym zostanie przeprowadzone sprawdzanie systemu plików na wybranym wolumenie VeraCrypt za pomocą polecenia „diskutil”. Wynik zostanie wyświetlony w tym oknie.\n\nJeśli nie uda się uruchomić sprawdzania, zamiast tego uruchomi się Narzędzie dyskowe.</entry>
<entry lang="pl" key="MACOSX_REPAIR_FILESYS">Po kliknięciu przycisku „OK” otworzy się okno Terminala, w którym zostanie podjęta próba naprawy systemu plików na wybranym wolumenie VeraCrypt za pomocą polecenia „diskutil”. Wynik zostanie wyświetlony w tym oknie.\n\nJeśli nie uda się uruchomić naprawy, zamiast tego uruchomi się Narzędzie dyskowe.</entry>
<entry lang="pl" key="SYSENC_EFI_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Ostrzeżenie: Funkcja Secure Boot jest włączona, ale urząd certyfikacji Microsoft UEFI CA, który podpisuje zainstalowany program rozruchowy EFI VeraCrypt, nie został znaleziony w bazie danych (db) oprogramowania układowego funkcji Secure Boot. Oprogramowanie układowe może odmówić uruchomienia VeraCrypt przy następnym ponownym uruchomieniu, więc system Windows nie uruchomi się, dopóki funkcja Secure Boot nie zostanie wyłączona lub zestaw zaufanych certyfikatów/programu rozruchowego nie zostanie naprawiony.\n\nPrzed ponownym uruchomieniem komputera nie wyłączaj ani nie usuwaj certyfikatu Microsoft Corporation UEFI CA 2011, chyba że baza danych oprogramowania układowego zawiera zarówno certyfikat Microsoft UEFI CA 2023, jak i certyfikat Microsoft Option ROM UEFI CA 2023, a VeraCrypt został naprawiony/ponownie zainstalowany, więc zestaw podpisany w roku 2023 jest zainstalowany. W razie potrzeby włącz wymagane certyfikaty Microsoftu w ustawieniach BIOS/UEFI, a następnie uruchom narzędzie naprawy/ponownej instalacji VeraCrypt. Przed ponownym uruchomieniem komputera upewnij się, że masz aktualną płytę ratunkową VeraCrypt.</entry>
<entry lang="pl" key="SYSENC_EFI_WINDOWS_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Ostrzeżenie: Funkcja Secure Boot jest włączona, ale urząd certyfikacji Microsoft CA, który podpisuje kopię menedżera rozruchu systemu Windows używaną przez VeraCrypt (bootmgfw_ms.vc), nie został znaleziony w bazie danych (db) oprogramowania układowego funkcji Secure Boot. Po pomyślnym uwierzytelnieniu przed rozruchem przekazanie do systemu Windows może się nie powieść, a komputer może powrócić do monitu o hasło VeraCrypt.\n\nPrzed ponownym uruchomieniem komputera nie wyłączaj ani nie odwołuj certyfikatu Microsoft Windows Production PCA 2011, chyba że menedżer rozruchu systemu Windows został zaktualizowany do wersji podpisanej certyfikatem Windows UEFI CA 2023, a baza danych oprogramowania układowego zawiera certyfikat Windows UEFI CA 2023. Zastosuj aktualizacje certyfikatu funkcji Secure Boot systemu Windows, a następnie w razie potrzeby uruchom narzędzie naprawy/ponownej instalacji VeraCrypt. Przed ponownym uruchomieniem komputera upewnij się, że masz aktualną płytę ratunkową VeraCrypt.</entry>
<entry lang="pl" key="SYSENC_EFI_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Ostrzeżenie: VeraCrypt nie może zweryfikować zainstalowanych plików programu rozruchowego EFI względem jednego pełnego osadzonego zestawu zasobów ani potwierdzić, że wszystkie znane wymagane urzędy certyfikacji znajdują się w db i nie są wymienione w dbx. Oprogramowanie układowe może odrzucić VeraCrypt po włączeniu Secure Boot.\n\nPrzed uruchomieniem z włączonym Secure Boot przywróć wymagane certyfikaty Microsoft i aktualną dbx, a następnie uruchom naprawę/ponowną instalację VeraCrypt. Nie usuwaj Microsoft Corporation UEFI CA 2011, dopóki db nie zawiera obu certyfikatów Microsoft UEFI CA 2023 i Microsoft Option ROM UEFI CA 2023, a faktycznie zainstalowane pliki nie odpowiadają zestawowi VeraCrypt 2023. To sprawdzenie nie obejmuje wszystkich odwołań skrótów obrazów ani wersji zabezpieczeń. Upewnij się, że masz aktualny Dysk Ratunkowy VeraCrypt.</entry>
<entry lang="pl" key="SYSENC_EFI_WINDOWS_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Ostrzeżenie: VeraCrypt nie może zweryfikować osadzonego podpisu ani zgodności znanych CA Menedżera rozruchu Windows używanego do przekazania sterowania (bootmgfw_ms.vc). Plik może nie istnieć, być nieczytelny lub nie być Menedżerem rozruchu Windows; jego osadzony podpisujący może być nierozpoznany albo znany CA podpisujący może być nieobecny w db lub wymieniony w dbx. Przekazanie sterowania do Windows może się nie powieść po włączeniu Secure Boot.\n\nDokończ lub napraw aktualizację certyfikatów Secure Boot i Menedżera rozruchu Windows, pozostaw włączoną usługę VeraCrypt System Favorites i uruchom naprawę/ponowną instalację VeraCrypt. Naprawa sprawdza również obsługiwane przez Windows kopie EFI_EX/EFI w poszukiwaniu zgodnego aktualnego Menedżera rozruchu. Jeśli Windows nie uruchamia się, tymczasowo wyłącz Secure Boot. Upewnij się, że masz aktualny Dysk Ratunkowy VeraCrypt.</entry>
<entry lang="pl" key="SYSENC_EFI_WINDOWS_LOADER_PCA2011_MIGRATION_NEEDED">Ostrzeżenie: Osadzony podpis Menedżera rozruchu Windows używanego przez VeraCrypt (bootmgfw_ms.vc) jest nadal wystawiony przez Microsoft Windows Production PCA 2011, mimo że db oprogramowania układowego zawiera już Windows UEFI CA 2023. Znany CA jest obecnie dozwolony, lecz plik przestanie się uruchamiać po dodaniu certyfikatu PCA 2011 do dbx.\n\nNie stosuj jeszcze odwołania PCA 2011 (bit 0x80 wartości AvailableUpdates, również w połączonej wartości 0x280). Najpierw dokończ aktualizację Menedżera rozruchu Windows 2023 przy włączonej usłudze VeraCrypt System Favorites, a następnie uruchom naprawę/ponowną instalację VeraCrypt, aby program mógł zaimportować zgodną obsługiwaną kopię EFI_EX/EFI. Sprawdź, czy osadzonym wystawcą bootmgfw_ms.vc jest Windows UEFI CA 2023, i upewnij się, że masz aktualny Dysk Ratunkowy VeraCrypt.</entry>
</localization>
<xs:schema attributeFormDefault="unqualified" elementFormDefault="qualified" xmlns:xs="http://www.w3.org/2001/XMLSchema">
<xs:element name="VeraCrypt">
+3 -2
View File
@@ -1688,8 +1688,9 @@
<entry lang="pt-br" key="SYSENC_EFI_UNSUPPORTED_SECUREBOOT_CA">A Inicialização Segura (Secure Boot) está ativada, mas o banco de dados de Secure Boot do firmware não confia em nenhum conjunto de CA UEFI da Microsoft compatível com o carregador de inicialização EFI do VeraCrypt. Ative Microsoft Corporation UEFI CA 2011 ou tanto Microsoft UEFI CA 2023 quanto Microsoft Option ROM UEFI CA 2023, e então execute a opção Reparar/Reinstalar do VeraCrypt. Como alternativa, desative o Secure Boot.</entry>
<entry lang="pt-br" key="MACOSX_CHECK_FILESYS">Após você pressionar 'OK', uma janela do Terminal será aberta para verificar o sistema de arquivos do volume VeraCrypt selecionado usando 'diskutil'. O resultado será mostrado nessa janela.\n\nSe a verificação não puder ser iniciada, o Utilitário de Disco será iniciado em seu lugar.</entry>
<entry lang="pt-br" key="MACOSX_REPAIR_FILESYS">Após você pressionar 'OK', uma janela do Terminal será aberta para tentar reparar o sistema de arquivos do volume VeraCrypt selecionado usando 'diskutil'. O resultado será mostrado nessa janela.\n\nSe o reparo não puder ser iniciado, o Utilitário de Disco será iniciado em seu lugar.</entry>
<entry lang="en" key="SYSENC_EFI_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: Secure Boot is enabled, but the Microsoft UEFI CA that signs the installed VeraCrypt EFI bootloader was not found in the firmware Secure Boot database (db). The firmware may refuse to start VeraCrypt at the next reboot, so Windows will not start until Secure Boot is disabled or the trusted certificates/loader set are repaired.\n\nBefore restarting this computer, do not disable or remove Microsoft Corporation UEFI CA 2011 unless the firmware db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and VeraCrypt has been repaired/reinstalled so the 2023-signed loader set is installed. Enable the required Microsoft certificates in the BIOS/UEFI settings if needed, then run VeraCrypt Repair/Reinstall. Make sure you have an up-to-date VeraCrypt Rescue Disk before restarting.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: Secure Boot is enabled, but the Microsoft CA that signs the Windows Boot Manager copy used by VeraCrypt (bootmgfw_ms.vc) was not found in the firmware Secure Boot database (db). After successful pre-boot authentication, the handoff to Windows may fail and the computer may return to the VeraCrypt password prompt.\n\nBefore restarting this computer, do not disable or revoke Microsoft Windows Production PCA 2011 unless Windows Boot Manager has migrated to a Windows UEFI CA 2023-signed version and the firmware db contains Windows UEFI CA 2023. Apply the Windows Secure Boot certificate updates, then run VeraCrypt Repair/Reinstall if needed. Make sure you have an up-to-date VeraCrypt Rescue Disk before restarting.</entry>
<entry lang="en" key="SYSENC_EFI_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: VeraCrypt could not validate the installed EFI bootloader files against one complete embedded resource set and confirm that all known required signing CAs are present in db and not listed by dbx. Firmware may reject VeraCrypt when Secure Boot is enabled.\n\nBefore booting with Secure Boot enabled, restore the required Microsoft certificates and current dbx as needed, then run VeraCrypt Repair/Reinstall. Do not remove Microsoft Corporation UEFI CA 2011 until db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and the actual installed files match VeraCrypt's 2023 set. This check cannot model every image-hash or security-version revocation. Make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: VeraCrypt could not validate the embedded signature and known-CA compatibility of the Windows Boot Manager it chainloads (bootmgfw_ms.vc). The file may be missing, unreadable, not a Windows Boot Manager, have an unrecognized embedded signer, or use a known signing CA that is absent from db or listed by dbx. The handoff to Windows may fail when Secure Boot is enabled.\n\nComplete or repair the Windows Secure Boot certificate and boot-manager update, keep the VeraCrypt System Favorites service enabled, and run VeraCrypt Repair/Reinstall. Repair also checks Windows' serviced EFI_EX/EFI copies for a compatible current Boot Manager. If Windows cannot start, temporarily disable Secure Boot to recover. Make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_PCA2011_MIGRATION_NEEDED">Warning: The embedded signature of the Windows Boot Manager used by VeraCrypt (bootmgfw_ms.vc) is still issued by Microsoft Windows Production PCA 2011, although firmware db already contains Windows UEFI CA 2023. Its known CA is currently allowed, but it will no longer start after the PCA 2011 certificate is added to dbx.\n\nDo not apply the PCA 2011 revocation (AvailableUpdates bit 0x80, including combined value 0x280) yet. First complete the Windows 2023 boot-manager update while the VeraCrypt System Favorites service is enabled, then run VeraCrypt Repair/Reinstall so VeraCrypt can import a compatible serviced EFI_EX/EFI copy. Verify the embedded issuer of bootmgfw_ms.vc is Windows UEFI CA 2023 and make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
</localization>
<xs:schema attributeFormDefault="unqualified" elementFormDefault="qualified" xmlns:xs="http://www.w3.org/2001/XMLSchema">
<xs:element name="VeraCrypt">
+3 -2
View File
@@ -1688,8 +1688,9 @@
<entry lang="ro" key="SYSENC_EFI_UNSUPPORTED_SECUREBOOT_CA">Secure Boot este activat, dar baza de date Secure Boot din firmware nu consideră de încredere niciun set Microsoft UEFI CA acceptat de încărcătorul EFI al VeraCrypt. Activați fie Microsoft Corporation UEFI CA 2011, fie atât Microsoft UEFI CA 2023, cât și Microsoft Option ROM UEFI CA 2023, apoi rulați opțiunea Reparare/Reinstalare din VeraCrypt. Alternativ, dezactivați Secure Boot.</entry>
<entry lang="ro" key="MACOSX_CHECK_FILESYS">După ce apăsați pe „OK”, se va deschide o fereastră a aplicației Terminal, iar sistemul de fișiere de pe volumul VeraCrypt selectat va fi verificat folosind „diskutil”. Rezultatul va fi afișat în acea fereastră.\n\nDacă verificarea nu poate fi pornită, se va lansa în schimb „Utilitar disc”.</entry>
<entry lang="ro" key="MACOSX_REPAIR_FILESYS">După ce apăsați pe „OK”, se va deschide o fereastră a aplicației Terminal, iar folosind „diskutil” se va încerca repararea sistemului de fișiere de pe volumul VeraCrypt selectat. Rezultatul va fi afișat în acea fereastră.\n\nDacă repararea nu poate fi pornită, se va lansa în schimb „Utilitar disc”.</entry>
<entry lang="en" key="SYSENC_EFI_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: Secure Boot is enabled, but the Microsoft UEFI CA that signs the installed VeraCrypt EFI bootloader was not found in the firmware Secure Boot database (db). The firmware may refuse to start VeraCrypt at the next reboot, so Windows will not start until Secure Boot is disabled or the trusted certificates/loader set are repaired.\n\nBefore restarting this computer, do not disable or remove Microsoft Corporation UEFI CA 2011 unless the firmware db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and VeraCrypt has been repaired/reinstalled so the 2023-signed loader set is installed. Enable the required Microsoft certificates in the BIOS/UEFI settings if needed, then run VeraCrypt Repair/Reinstall. Make sure you have an up-to-date VeraCrypt Rescue Disk before restarting.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: Secure Boot is enabled, but the Microsoft CA that signs the Windows Boot Manager copy used by VeraCrypt (bootmgfw_ms.vc) was not found in the firmware Secure Boot database (db). After successful pre-boot authentication, the handoff to Windows may fail and the computer may return to the VeraCrypt password prompt.\n\nBefore restarting this computer, do not disable or revoke Microsoft Windows Production PCA 2011 unless Windows Boot Manager has migrated to a Windows UEFI CA 2023-signed version and the firmware db contains Windows UEFI CA 2023. Apply the Windows Secure Boot certificate updates, then run VeraCrypt Repair/Reinstall if needed. Make sure you have an up-to-date VeraCrypt Rescue Disk before restarting.</entry>
<entry lang="en" key="SYSENC_EFI_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: VeraCrypt could not validate the installed EFI bootloader files against one complete embedded resource set and confirm that all known required signing CAs are present in db and not listed by dbx. Firmware may reject VeraCrypt when Secure Boot is enabled.\n\nBefore booting with Secure Boot enabled, restore the required Microsoft certificates and current dbx as needed, then run VeraCrypt Repair/Reinstall. Do not remove Microsoft Corporation UEFI CA 2011 until db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and the actual installed files match VeraCrypt's 2023 set. This check cannot model every image-hash or security-version revocation. Make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: VeraCrypt could not validate the embedded signature and known-CA compatibility of the Windows Boot Manager it chainloads (bootmgfw_ms.vc). The file may be missing, unreadable, not a Windows Boot Manager, have an unrecognized embedded signer, or use a known signing CA that is absent from db or listed by dbx. The handoff to Windows may fail when Secure Boot is enabled.\n\nComplete or repair the Windows Secure Boot certificate and boot-manager update, keep the VeraCrypt System Favorites service enabled, and run VeraCrypt Repair/Reinstall. Repair also checks Windows' serviced EFI_EX/EFI copies for a compatible current Boot Manager. If Windows cannot start, temporarily disable Secure Boot to recover. Make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_PCA2011_MIGRATION_NEEDED">Warning: The embedded signature of the Windows Boot Manager used by VeraCrypt (bootmgfw_ms.vc) is still issued by Microsoft Windows Production PCA 2011, although firmware db already contains Windows UEFI CA 2023. Its known CA is currently allowed, but it will no longer start after the PCA 2011 certificate is added to dbx.\n\nDo not apply the PCA 2011 revocation (AvailableUpdates bit 0x80, including combined value 0x280) yet. First complete the Windows 2023 boot-manager update while the VeraCrypt System Favorites service is enabled, then run VeraCrypt Repair/Reinstall so VeraCrypt can import a compatible serviced EFI_EX/EFI copy. Verify the embedded issuer of bootmgfw_ms.vc is Windows UEFI CA 2023 and make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
</localization>
<xs:schema attributeFormDefault="unqualified" elementFormDefault="qualified" xmlns:xs="http://www.w3.org/2001/XMLSchema">
<xs:element name="VeraCrypt">
+3 -2
View File
@@ -1688,8 +1688,9 @@
<entry lang="ru" key="SYSENC_EFI_UNSUPPORTED_SECUREBOOT_CA">Secure Boot включён, но база данных Secure Boot в микропрограмме не доверяет ни одному набору Microsoft UEFI CA, поддерживаемому EFI-загрузчиком VeraCrypt. Включите либо Microsoft Corporation UEFI CA 2011, либо одновременно Microsoft UEFI CA 2023 и Microsoft Option ROM UEFI CA 2023, затем выполните восстановление/переустановку VeraCrypt. Либо отключите Secure Boot.</entry>
<entry lang="ru" key="MACOSX_CHECK_FILESYS">После нажатия 'OK' откроется окно Терминала, в котором с помощью 'diskutil' будет проверена файловая система выбранного тома VeraCrypt. Результат будет показан в этом окне.\n\nЕсли проверку не удастся запустить, вместо неё будет запущена Дисковая утилита.</entry>
<entry lang="ru" key="MACOSX_REPAIR_FILESYS">После нажатия 'OK' откроется окно Терминала, в котором с помощью 'diskutil' будет выполнена попытка исправить файловую систему выбранного тома VeraCrypt. Результат будет показан в этом окне.\n\nЕсли исправление не удастся запустить, вместо него будет запущена Дисковая утилита.</entry>
<entry lang="en" key="SYSENC_EFI_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: Secure Boot is enabled, but the Microsoft UEFI CA that signs the installed VeraCrypt EFI bootloader was not found in the firmware Secure Boot database (db). The firmware may refuse to start VeraCrypt at the next reboot, so Windows will not start until Secure Boot is disabled or the trusted certificates/loader set are repaired.\n\nBefore restarting this computer, do not disable or remove Microsoft Corporation UEFI CA 2011 unless the firmware db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and VeraCrypt has been repaired/reinstalled so the 2023-signed loader set is installed. Enable the required Microsoft certificates in the BIOS/UEFI settings if needed, then run VeraCrypt Repair/Reinstall. Make sure you have an up-to-date VeraCrypt Rescue Disk before restarting.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: Secure Boot is enabled, but the Microsoft CA that signs the Windows Boot Manager copy used by VeraCrypt (bootmgfw_ms.vc) was not found in the firmware Secure Boot database (db). After successful pre-boot authentication, the handoff to Windows may fail and the computer may return to the VeraCrypt password prompt.\n\nBefore restarting this computer, do not disable or revoke Microsoft Windows Production PCA 2011 unless Windows Boot Manager has migrated to a Windows UEFI CA 2023-signed version and the firmware db contains Windows UEFI CA 2023. Apply the Windows Secure Boot certificate updates, then run VeraCrypt Repair/Reinstall if needed. Make sure you have an up-to-date VeraCrypt Rescue Disk before restarting.</entry>
<entry lang="en" key="SYSENC_EFI_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: VeraCrypt could not validate the installed EFI bootloader files against one complete embedded resource set and confirm that all known required signing CAs are present in db and not listed by dbx. Firmware may reject VeraCrypt when Secure Boot is enabled.\n\nBefore booting with Secure Boot enabled, restore the required Microsoft certificates and current dbx as needed, then run VeraCrypt Repair/Reinstall. Do not remove Microsoft Corporation UEFI CA 2011 until db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and the actual installed files match VeraCrypt's 2023 set. This check cannot model every image-hash or security-version revocation. Make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: VeraCrypt could not validate the embedded signature and known-CA compatibility of the Windows Boot Manager it chainloads (bootmgfw_ms.vc). The file may be missing, unreadable, not a Windows Boot Manager, have an unrecognized embedded signer, or use a known signing CA that is absent from db or listed by dbx. The handoff to Windows may fail when Secure Boot is enabled.\n\nComplete or repair the Windows Secure Boot certificate and boot-manager update, keep the VeraCrypt System Favorites service enabled, and run VeraCrypt Repair/Reinstall. Repair also checks Windows' serviced EFI_EX/EFI copies for a compatible current Boot Manager. If Windows cannot start, temporarily disable Secure Boot to recover. Make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_PCA2011_MIGRATION_NEEDED">Warning: The embedded signature of the Windows Boot Manager used by VeraCrypt (bootmgfw_ms.vc) is still issued by Microsoft Windows Production PCA 2011, although firmware db already contains Windows UEFI CA 2023. Its known CA is currently allowed, but it will no longer start after the PCA 2011 certificate is added to dbx.\n\nDo not apply the PCA 2011 revocation (AvailableUpdates bit 0x80, including combined value 0x280) yet. First complete the Windows 2023 boot-manager update while the VeraCrypt System Favorites service is enabled, then run VeraCrypt Repair/Reinstall so VeraCrypt can import a compatible serviced EFI_EX/EFI copy. Verify the embedded issuer of bootmgfw_ms.vc is Windows UEFI CA 2023 and make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
</localization>
<xs:schema attributeFormDefault="unqualified" elementFormDefault="qualified" xmlns:xs="http://www.w3.org/2001/XMLSchema">
<xs:element name="VeraCrypt">
+3 -2
View File
@@ -1688,8 +1688,9 @@
<entry lang="sk" key="SYSENC_EFI_UNSUPPORTED_SECUREBOOT_CA">Secure Boot je povolený, ale databáza Secure Boot vo firmvéri nedôveruje žiadnej sade Microsoft UEFI CA podporovanej EFI zavádzačom VeraCrypt. Povoľte buď Microsoft Corporation UEFI CA 2011, alebo súčasne Microsoft UEFI CA 2023 a Microsoft Option ROM UEFI CA 2023, potom spustite vo VeraCrypte možnosť "Oprava/opätovná inštalácia". Prípadne zakážte Secure Boot.</entry>
<entry lang="sk" key="MACOSX_CHECK_FILESYS">Po stlačení tlačidla 'OK' sa otvorí okno Terminálu a pomocou 'diskutil' sa skontroluje systém súborov na vybranom zväzku VeraCrypt. Výsledok sa zobrazí v tomto okne.\n\nAk kontrolu nemožno spustiť, namiesto toho sa spustí Disková utilita.</entry>
<entry lang="sk" key="MACOSX_REPAIR_FILESYS">Po stlačení tlačidla 'OK' sa otvorí okno Terminálu a pomocou 'diskutil' sa vykoná pokus o opravu systému súborov na vybranom zväzku VeraCrypt. Výsledok sa zobrazí v tomto okne.\n\nAk opravu nemožno spustiť, namiesto toho sa spustí Disková utilita.</entry>
<entry lang="en" key="SYSENC_EFI_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: Secure Boot is enabled, but the Microsoft UEFI CA that signs the installed VeraCrypt EFI bootloader was not found in the firmware Secure Boot database (db). The firmware may refuse to start VeraCrypt at the next reboot, so Windows will not start until Secure Boot is disabled or the trusted certificates/loader set are repaired.\n\nBefore restarting this computer, do not disable or remove Microsoft Corporation UEFI CA 2011 unless the firmware db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and VeraCrypt has been repaired/reinstalled so the 2023-signed loader set is installed. Enable the required Microsoft certificates in the BIOS/UEFI settings if needed, then run VeraCrypt Repair/Reinstall. Make sure you have an up-to-date VeraCrypt Rescue Disk before restarting.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: Secure Boot is enabled, but the Microsoft CA that signs the Windows Boot Manager copy used by VeraCrypt (bootmgfw_ms.vc) was not found in the firmware Secure Boot database (db). After successful pre-boot authentication, the handoff to Windows may fail and the computer may return to the VeraCrypt password prompt.\n\nBefore restarting this computer, do not disable or revoke Microsoft Windows Production PCA 2011 unless Windows Boot Manager has migrated to a Windows UEFI CA 2023-signed version and the firmware db contains Windows UEFI CA 2023. Apply the Windows Secure Boot certificate updates, then run VeraCrypt Repair/Reinstall if needed. Make sure you have an up-to-date VeraCrypt Rescue Disk before restarting.</entry>
<entry lang="en" key="SYSENC_EFI_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: VeraCrypt could not validate the installed EFI bootloader files against one complete embedded resource set and confirm that all known required signing CAs are present in db and not listed by dbx. Firmware may reject VeraCrypt when Secure Boot is enabled.\n\nBefore booting with Secure Boot enabled, restore the required Microsoft certificates and current dbx as needed, then run VeraCrypt Repair/Reinstall. Do not remove Microsoft Corporation UEFI CA 2011 until db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and the actual installed files match VeraCrypt's 2023 set. This check cannot model every image-hash or security-version revocation. Make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: VeraCrypt could not validate the embedded signature and known-CA compatibility of the Windows Boot Manager it chainloads (bootmgfw_ms.vc). The file may be missing, unreadable, not a Windows Boot Manager, have an unrecognized embedded signer, or use a known signing CA that is absent from db or listed by dbx. The handoff to Windows may fail when Secure Boot is enabled.\n\nComplete or repair the Windows Secure Boot certificate and boot-manager update, keep the VeraCrypt System Favorites service enabled, and run VeraCrypt Repair/Reinstall. Repair also checks Windows' serviced EFI_EX/EFI copies for a compatible current Boot Manager. If Windows cannot start, temporarily disable Secure Boot to recover. Make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_PCA2011_MIGRATION_NEEDED">Warning: The embedded signature of the Windows Boot Manager used by VeraCrypt (bootmgfw_ms.vc) is still issued by Microsoft Windows Production PCA 2011, although firmware db already contains Windows UEFI CA 2023. Its known CA is currently allowed, but it will no longer start after the PCA 2011 certificate is added to dbx.\n\nDo not apply the PCA 2011 revocation (AvailableUpdates bit 0x80, including combined value 0x280) yet. First complete the Windows 2023 boot-manager update while the VeraCrypt System Favorites service is enabled, then run VeraCrypt Repair/Reinstall so VeraCrypt can import a compatible serviced EFI_EX/EFI copy. Verify the embedded issuer of bootmgfw_ms.vc is Windows UEFI CA 2023 and make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
</localization>
<xs:schema attributeFormDefault="unqualified" elementFormDefault="qualified" xmlns:xs="http://www.w3.org/2001/XMLSchema">
<xs:element name="VeraCrypt">
+3 -2
View File
@@ -1688,8 +1688,9 @@
<entry lang="sl" key="SYSENC_EFI_UNSUPPORTED_SECUREBOOT_CA">Secure Boot je omogočen, vendar zbirka podatkov Secure Boot v vdelani programski opremi ne zaupa nobenemu naboru Microsoft UEFI CA, ki ga podpira VeraCryptov zagonski nalagalnik EFI. Omogoči Microsoft Corporation UEFI CA 2011 ali pa tako Microsoft UEFI CA 2023 kot Microsoft Option ROM UEFI CA 2023, nato v VeraCryptu zaženi možnost Popravi/ponovno namesti. Lahko pa onemogočiš Secure Boot.</entry>
<entry lang="sl" key="MACOSX_CHECK_FILESYS">Ko pritisneš 'V redu', se bo odprlo okno Terminala, v katerem se bo z ukazom 'diskutil' preveril datotečni sistem izbranega nosilca VeraCrypt. Rezultat bo prikazan v tem oknu.\n\nČe preverjanja ni mogoče zagnati, se bo namesto tega zagnal Disk Utility.</entry>
<entry lang="sl" key="MACOSX_REPAIR_FILESYS">Ko pritisneš 'V redu', se bo odprlo okno Terminala, v katerem se bo z ukazom 'diskutil' poskusilo popraviti datotečni sistem izbranega nosilca VeraCrypt. Rezultat bo prikazan v tem oknu.\n\nČe popravila ni mogoče zagnati, se bo namesto tega zagnal Disk Utility.</entry>
<entry lang="en" key="SYSENC_EFI_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: Secure Boot is enabled, but the Microsoft UEFI CA that signs the installed VeraCrypt EFI bootloader was not found in the firmware Secure Boot database (db). The firmware may refuse to start VeraCrypt at the next reboot, so Windows will not start until Secure Boot is disabled or the trusted certificates/loader set are repaired.\n\nBefore restarting this computer, do not disable or remove Microsoft Corporation UEFI CA 2011 unless the firmware db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and VeraCrypt has been repaired/reinstalled so the 2023-signed loader set is installed. Enable the required Microsoft certificates in the BIOS/UEFI settings if needed, then run VeraCrypt Repair/Reinstall. Make sure you have an up-to-date VeraCrypt Rescue Disk before restarting.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: Secure Boot is enabled, but the Microsoft CA that signs the Windows Boot Manager copy used by VeraCrypt (bootmgfw_ms.vc) was not found in the firmware Secure Boot database (db). After successful pre-boot authentication, the handoff to Windows may fail and the computer may return to the VeraCrypt password prompt.\n\nBefore restarting this computer, do not disable or revoke Microsoft Windows Production PCA 2011 unless Windows Boot Manager has migrated to a Windows UEFI CA 2023-signed version and the firmware db contains Windows UEFI CA 2023. Apply the Windows Secure Boot certificate updates, then run VeraCrypt Repair/Reinstall if needed. Make sure you have an up-to-date VeraCrypt Rescue Disk before restarting.</entry>
<entry lang="en" key="SYSENC_EFI_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: VeraCrypt could not validate the installed EFI bootloader files against one complete embedded resource set and confirm that all known required signing CAs are present in db and not listed by dbx. Firmware may reject VeraCrypt when Secure Boot is enabled.\n\nBefore booting with Secure Boot enabled, restore the required Microsoft certificates and current dbx as needed, then run VeraCrypt Repair/Reinstall. Do not remove Microsoft Corporation UEFI CA 2011 until db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and the actual installed files match VeraCrypt's 2023 set. This check cannot model every image-hash or security-version revocation. Make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: VeraCrypt could not validate the embedded signature and known-CA compatibility of the Windows Boot Manager it chainloads (bootmgfw_ms.vc). The file may be missing, unreadable, not a Windows Boot Manager, have an unrecognized embedded signer, or use a known signing CA that is absent from db or listed by dbx. The handoff to Windows may fail when Secure Boot is enabled.\n\nComplete or repair the Windows Secure Boot certificate and boot-manager update, keep the VeraCrypt System Favorites service enabled, and run VeraCrypt Repair/Reinstall. Repair also checks Windows' serviced EFI_EX/EFI copies for a compatible current Boot Manager. If Windows cannot start, temporarily disable Secure Boot to recover. Make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_PCA2011_MIGRATION_NEEDED">Warning: The embedded signature of the Windows Boot Manager used by VeraCrypt (bootmgfw_ms.vc) is still issued by Microsoft Windows Production PCA 2011, although firmware db already contains Windows UEFI CA 2023. Its known CA is currently allowed, but it will no longer start after the PCA 2011 certificate is added to dbx.\n\nDo not apply the PCA 2011 revocation (AvailableUpdates bit 0x80, including combined value 0x280) yet. First complete the Windows 2023 boot-manager update while the VeraCrypt System Favorites service is enabled, then run VeraCrypt Repair/Reinstall so VeraCrypt can import a compatible serviced EFI_EX/EFI copy. Verify the embedded issuer of bootmgfw_ms.vc is Windows UEFI CA 2023 and make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
</localization>
<xs:schema attributeFormDefault="unqualified" elementFormDefault="qualified" xmlns:xs="http://www.w3.org/2001/XMLSchema">
<xs:element name="VeraCrypt">
+3 -2
View File
@@ -1688,8 +1688,9 @@
<entry lang="sv" key="SYSENC_EFI_UNSUPPORTED_SECUREBOOT_CA">Secure Boot är aktiverat, men firmwarens Secure Boot-databas litar inte på någon Microsoft UEFI CA-uppsättning som stöds av VeraCrypts EFI-startinläsare. Aktivera antingen Microsoft Corporation UEFI CA 2011 eller både Microsoft UEFI CA 2023 och Microsoft Option ROM UEFI CA 2023, och kör sedan alternativet Reparera/installera om i VeraCrypt. Alternativt kan du inaktivera Secure Boot.</entry>
<entry lang="sv" key="MACOSX_CHECK_FILESYS">Ett Terminal-fönster öppnas när du trycker på "OK" och kontrollerar filsystemet på den valda VeraCrypt-volymen med "diskutil". Resultatet visas i fönstret.\n\nOm kontrollen inte kan startas öppnas Skivverktyg i stället.</entry>
<entry lang="sv" key="MACOSX_REPAIR_FILESYS">Ett Terminal-fönster öppnas när du trycker på "OK" och försöker reparera filsystemet på den valda VeraCrypt-volymen med "diskutil". Resultatet visas i fönstret.\n\nOm reparationen inte kan startas öppnas Skivverktyg i stället.</entry>
<entry lang="en" key="SYSENC_EFI_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: Secure Boot is enabled, but the Microsoft UEFI CA that signs the installed VeraCrypt EFI bootloader was not found in the firmware Secure Boot database (db). The firmware may refuse to start VeraCrypt at the next reboot, so Windows will not start until Secure Boot is disabled or the trusted certificates/loader set are repaired.\n\nBefore restarting this computer, do not disable or remove Microsoft Corporation UEFI CA 2011 unless the firmware db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and VeraCrypt has been repaired/reinstalled so the 2023-signed loader set is installed. Enable the required Microsoft certificates in the BIOS/UEFI settings if needed, then run VeraCrypt Repair/Reinstall. Make sure you have an up-to-date VeraCrypt Rescue Disk before restarting.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: Secure Boot is enabled, but the Microsoft CA that signs the Windows Boot Manager copy used by VeraCrypt (bootmgfw_ms.vc) was not found in the firmware Secure Boot database (db). After successful pre-boot authentication, the handoff to Windows may fail and the computer may return to the VeraCrypt password prompt.\n\nBefore restarting this computer, do not disable or revoke Microsoft Windows Production PCA 2011 unless Windows Boot Manager has migrated to a Windows UEFI CA 2023-signed version and the firmware db contains Windows UEFI CA 2023. Apply the Windows Secure Boot certificate updates, then run VeraCrypt Repair/Reinstall if needed. Make sure you have an up-to-date VeraCrypt Rescue Disk before restarting.</entry>
<entry lang="en" key="SYSENC_EFI_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: VeraCrypt could not validate the installed EFI bootloader files against one complete embedded resource set and confirm that all known required signing CAs are present in db and not listed by dbx. Firmware may reject VeraCrypt when Secure Boot is enabled.\n\nBefore booting with Secure Boot enabled, restore the required Microsoft certificates and current dbx as needed, then run VeraCrypt Repair/Reinstall. Do not remove Microsoft Corporation UEFI CA 2011 until db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and the actual installed files match VeraCrypt's 2023 set. This check cannot model every image-hash or security-version revocation. Make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: VeraCrypt could not validate the embedded signature and known-CA compatibility of the Windows Boot Manager it chainloads (bootmgfw_ms.vc). The file may be missing, unreadable, not a Windows Boot Manager, have an unrecognized embedded signer, or use a known signing CA that is absent from db or listed by dbx. The handoff to Windows may fail when Secure Boot is enabled.\n\nComplete or repair the Windows Secure Boot certificate and boot-manager update, keep the VeraCrypt System Favorites service enabled, and run VeraCrypt Repair/Reinstall. Repair also checks Windows' serviced EFI_EX/EFI copies for a compatible current Boot Manager. If Windows cannot start, temporarily disable Secure Boot to recover. Make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_PCA2011_MIGRATION_NEEDED">Warning: The embedded signature of the Windows Boot Manager used by VeraCrypt (bootmgfw_ms.vc) is still issued by Microsoft Windows Production PCA 2011, although firmware db already contains Windows UEFI CA 2023. Its known CA is currently allowed, but it will no longer start after the PCA 2011 certificate is added to dbx.\n\nDo not apply the PCA 2011 revocation (AvailableUpdates bit 0x80, including combined value 0x280) yet. First complete the Windows 2023 boot-manager update while the VeraCrypt System Favorites service is enabled, then run VeraCrypt Repair/Reinstall so VeraCrypt can import a compatible serviced EFI_EX/EFI copy. Verify the embedded issuer of bootmgfw_ms.vc is Windows UEFI CA 2023 and make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
</localization>
<xs:schema attributeFormDefault="unqualified" elementFormDefault="qualified" xmlns:xs="http://www.w3.org/2001/XMLSchema">
<xs:element name="VeraCrypt">
+3 -2
View File
@@ -1688,8 +1688,9 @@
<entry lang="th" key="SYSENC_EFI_UNSUPPORTED_SECUREBOOT_CA">Secure Boot เปิดใช้งานอยู่ แต่ฐานข้อมูล Secure Boot ของเฟิร์มแวร์ไม่เชื่อถือชุด Microsoft UEFI CA ใด ๆ ที่ตัวโหลดบูต EFI ของ VeraCrypt รองรับ เปิดใช้งาน Microsoft Corporation UEFI CA 2011 หรือเปิดใช้งานทั้ง Microsoft UEFI CA 2023 และ Microsoft Option ROM UEFI CA 2023 จากนั้นเรียกใช้ตัวเลือกซ่อมแซม/ติดตั้งใหม่ของ VeraCrypt หรือปิดใช้งาน Secure Boot แทน</entry>
<entry lang="th" key="MACOSX_CHECK_FILESYS">หน้าต่าง Terminal จะเปิดขึ้นหลังจากคุณกด 'ตกลง' และจะตรวจสอบระบบไฟล์บนวอลุ่ม VeraCrypt ที่เลือกโดยใช้ 'diskutil' ผลลัพธ์จะแสดงในหน้าต่างนั้น\n\nหากไม่สามารถเริ่มการตรวจสอบได้ Disk Utility จะถูกเปิดแทน</entry>
<entry lang="th" key="MACOSX_REPAIR_FILESYS">หน้าต่าง Terminal จะเปิดขึ้นหลังจากคุณกด 'ตกลง' และจะพยายามซ่อมแซมระบบไฟล์บนวอลุ่ม VeraCrypt ที่เลือกโดยใช้ 'diskutil' ผลลัพธ์จะแสดงในหน้าต่างนั้น\n\nหากไม่สามารถเริ่มการซ่อมแซมได้ Disk Utility จะถูกเปิดแทน</entry>
<entry lang="en" key="SYSENC_EFI_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: Secure Boot is enabled, but the Microsoft UEFI CA that signs the installed VeraCrypt EFI bootloader was not found in the firmware Secure Boot database (db). The firmware may refuse to start VeraCrypt at the next reboot, so Windows will not start until Secure Boot is disabled or the trusted certificates/loader set are repaired.\n\nBefore restarting this computer, do not disable or remove Microsoft Corporation UEFI CA 2011 unless the firmware db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and VeraCrypt has been repaired/reinstalled so the 2023-signed loader set is installed. Enable the required Microsoft certificates in the BIOS/UEFI settings if needed, then run VeraCrypt Repair/Reinstall. Make sure you have an up-to-date VeraCrypt Rescue Disk before restarting.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: Secure Boot is enabled, but the Microsoft CA that signs the Windows Boot Manager copy used by VeraCrypt (bootmgfw_ms.vc) was not found in the firmware Secure Boot database (db). After successful pre-boot authentication, the handoff to Windows may fail and the computer may return to the VeraCrypt password prompt.\n\nBefore restarting this computer, do not disable or revoke Microsoft Windows Production PCA 2011 unless Windows Boot Manager has migrated to a Windows UEFI CA 2023-signed version and the firmware db contains Windows UEFI CA 2023. Apply the Windows Secure Boot certificate updates, then run VeraCrypt Repair/Reinstall if needed. Make sure you have an up-to-date VeraCrypt Rescue Disk before restarting.</entry>
<entry lang="en" key="SYSENC_EFI_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: VeraCrypt could not validate the installed EFI bootloader files against one complete embedded resource set and confirm that all known required signing CAs are present in db and not listed by dbx. Firmware may reject VeraCrypt when Secure Boot is enabled.\n\nBefore booting with Secure Boot enabled, restore the required Microsoft certificates and current dbx as needed, then run VeraCrypt Repair/Reinstall. Do not remove Microsoft Corporation UEFI CA 2011 until db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and the actual installed files match VeraCrypt's 2023 set. This check cannot model every image-hash or security-version revocation. Make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: VeraCrypt could not validate the embedded signature and known-CA compatibility of the Windows Boot Manager it chainloads (bootmgfw_ms.vc). The file may be missing, unreadable, not a Windows Boot Manager, have an unrecognized embedded signer, or use a known signing CA that is absent from db or listed by dbx. The handoff to Windows may fail when Secure Boot is enabled.\n\nComplete or repair the Windows Secure Boot certificate and boot-manager update, keep the VeraCrypt System Favorites service enabled, and run VeraCrypt Repair/Reinstall. Repair also checks Windows' serviced EFI_EX/EFI copies for a compatible current Boot Manager. If Windows cannot start, temporarily disable Secure Boot to recover. Make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_PCA2011_MIGRATION_NEEDED">Warning: The embedded signature of the Windows Boot Manager used by VeraCrypt (bootmgfw_ms.vc) is still issued by Microsoft Windows Production PCA 2011, although firmware db already contains Windows UEFI CA 2023. Its known CA is currently allowed, but it will no longer start after the PCA 2011 certificate is added to dbx.\n\nDo not apply the PCA 2011 revocation (AvailableUpdates bit 0x80, including combined value 0x280) yet. First complete the Windows 2023 boot-manager update while the VeraCrypt System Favorites service is enabled, then run VeraCrypt Repair/Reinstall so VeraCrypt can import a compatible serviced EFI_EX/EFI copy. Verify the embedded issuer of bootmgfw_ms.vc is Windows UEFI CA 2023 and make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
</localization>
<xs:schema attributeFormDefault="unqualified" elementFormDefault="qualified" xmlns:xs="http://www.w3.org/2001/XMLSchema">
<xs:element name="VeraCrypt">
+3 -2
View File
@@ -1688,8 +1688,9 @@
<entry lang="tr" key="SYSENC_EFI_UNSUPPORTED_SECUREBOOT_CA">Secure Boot etkin, ancak makine yazılımının Secure Boot veri tabanı VeraCrypt'in EFI başlatma yükleyicisinin desteklediği hiçbir Microsoft UEFI CA kümesine güvenmiyor. Microsoft Corporation UEFI CA 2011 ya da hem Microsoft UEFI CA 2023 hem de Microsoft Option ROM UEFI CA 2023 öğelerini etkinleştirin, ardından VeraCrypt Onar/Yeniden kur işlemini çalıştırın. Alternatif olarak Secure Boot özelliğini devre dışı bırakın.</entry>
<entry lang="tr" key="MACOSX_CHECK_FILESYS">'Tamam' üzerine tıkladıktan sonra bir Terminal penceresi açılacak ve 'diskutil' kullanılarak seçilmiş VeraCrypt biriminin dosya sistemi denetlenecek. Sonuç bu pencerede görüntülenecek.\n\nDenetim başlatılamazsa, bunun yerine Disk İzlencesi başlatılacak.</entry>
<entry lang="tr" key="MACOSX_REPAIR_FILESYS">'Tamam' üzerine tıkladıktan sonra bir Terminal penceresi açılacak ve 'diskutil' kullanılarak seçilmiş VeraCrypt biriminin dosya sistemi onarılmaya çalışılacak. Sonuç bu pencerede görüntülenecek.\n\nOnarım başlatılamazsa, bunun yerine Disk İzlencesi başlatılacak.</entry>
<entry lang="en" key="SYSENC_EFI_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: Secure Boot is enabled, but the Microsoft UEFI CA that signs the installed VeraCrypt EFI bootloader was not found in the firmware Secure Boot database (db). The firmware may refuse to start VeraCrypt at the next reboot, so Windows will not start until Secure Boot is disabled or the trusted certificates/loader set are repaired.\n\nBefore restarting this computer, do not disable or remove Microsoft Corporation UEFI CA 2011 unless the firmware db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and VeraCrypt has been repaired/reinstalled so the 2023-signed loader set is installed. Enable the required Microsoft certificates in the BIOS/UEFI settings if needed, then run VeraCrypt Repair/Reinstall. Make sure you have an up-to-date VeraCrypt Rescue Disk before restarting.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: Secure Boot is enabled, but the Microsoft CA that signs the Windows Boot Manager copy used by VeraCrypt (bootmgfw_ms.vc) was not found in the firmware Secure Boot database (db). After successful pre-boot authentication, the handoff to Windows may fail and the computer may return to the VeraCrypt password prompt.\n\nBefore restarting this computer, do not disable or revoke Microsoft Windows Production PCA 2011 unless Windows Boot Manager has migrated to a Windows UEFI CA 2023-signed version and the firmware db contains Windows UEFI CA 2023. Apply the Windows Secure Boot certificate updates, then run VeraCrypt Repair/Reinstall if needed. Make sure you have an up-to-date VeraCrypt Rescue Disk before restarting.</entry>
<entry lang="en" key="SYSENC_EFI_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: VeraCrypt could not validate the installed EFI bootloader files against one complete embedded resource set and confirm that all known required signing CAs are present in db and not listed by dbx. Firmware may reject VeraCrypt when Secure Boot is enabled.\n\nBefore booting with Secure Boot enabled, restore the required Microsoft certificates and current dbx as needed, then run VeraCrypt Repair/Reinstall. Do not remove Microsoft Corporation UEFI CA 2011 until db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and the actual installed files match VeraCrypt's 2023 set. This check cannot model every image-hash or security-version revocation. Make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: VeraCrypt could not validate the embedded signature and known-CA compatibility of the Windows Boot Manager it chainloads (bootmgfw_ms.vc). The file may be missing, unreadable, not a Windows Boot Manager, have an unrecognized embedded signer, or use a known signing CA that is absent from db or listed by dbx. The handoff to Windows may fail when Secure Boot is enabled.\n\nComplete or repair the Windows Secure Boot certificate and boot-manager update, keep the VeraCrypt System Favorites service enabled, and run VeraCrypt Repair/Reinstall. Repair also checks Windows' serviced EFI_EX/EFI copies for a compatible current Boot Manager. If Windows cannot start, temporarily disable Secure Boot to recover. Make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_PCA2011_MIGRATION_NEEDED">Warning: The embedded signature of the Windows Boot Manager used by VeraCrypt (bootmgfw_ms.vc) is still issued by Microsoft Windows Production PCA 2011, although firmware db already contains Windows UEFI CA 2023. Its known CA is currently allowed, but it will no longer start after the PCA 2011 certificate is added to dbx.\n\nDo not apply the PCA 2011 revocation (AvailableUpdates bit 0x80, including combined value 0x280) yet. First complete the Windows 2023 boot-manager update while the VeraCrypt System Favorites service is enabled, then run VeraCrypt Repair/Reinstall so VeraCrypt can import a compatible serviced EFI_EX/EFI copy. Verify the embedded issuer of bootmgfw_ms.vc is Windows UEFI CA 2023 and make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
</localization>
<xs:schema attributeFormDefault="unqualified" elementFormDefault="qualified" xmlns:xs="http://www.w3.org/2001/XMLSchema">
<xs:element name="VeraCrypt">
+3 -2
View File
@@ -1688,8 +1688,9 @@
<entry lang="uk" key="SYSENC_EFI_UNSUPPORTED_SECUREBOOT_CA">Secure Boot увімкнено, але база даних Secure Boot у мікропрограмі не довіряє жодному набору Microsoft UEFI CA, підтримуваному EFI-завантажувачем VeraCrypt. Увімкніть або Microsoft Corporation UEFI CA 2011, або одночасно Microsoft UEFI CA 2023 і Microsoft Option ROM UEFI CA 2023, потім виконайте відновлення/перевстановлення VeraCrypt. Або вимкніть Secure Boot.</entry>
<entry lang="uk" key="MACOSX_CHECK_FILESYS">Після натискання 'Гаразд' відкриється вікно Термінала, у якому за допомогою 'diskutil' буде перевірено файлову систему вибраного тому VeraCrypt. Результат буде показано в цьому вікні.\n\nЯкщо перевірку неможливо запустити, натомість буде запущено Дискову утиліту.</entry>
<entry lang="uk" key="MACOSX_REPAIR_FILESYS">Після натискання 'Гаразд' відкриється вікно Термінала, у якому за допомогою 'diskutil' буде виконано спробу виправити файлову систему вибраного тому VeraCrypt. Результат буде показано в цьому вікні.\n\nЯкщо виправлення неможливо запустити, натомість буде запущено Дискову утиліту.</entry>
<entry lang="en" key="SYSENC_EFI_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: Secure Boot is enabled, but the Microsoft UEFI CA that signs the installed VeraCrypt EFI bootloader was not found in the firmware Secure Boot database (db). The firmware may refuse to start VeraCrypt at the next reboot, so Windows will not start until Secure Boot is disabled or the trusted certificates/loader set are repaired.\n\nBefore restarting this computer, do not disable or remove Microsoft Corporation UEFI CA 2011 unless the firmware db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and VeraCrypt has been repaired/reinstalled so the 2023-signed loader set is installed. Enable the required Microsoft certificates in the BIOS/UEFI settings if needed, then run VeraCrypt Repair/Reinstall. Make sure you have an up-to-date VeraCrypt Rescue Disk before restarting.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: Secure Boot is enabled, but the Microsoft CA that signs the Windows Boot Manager copy used by VeraCrypt (bootmgfw_ms.vc) was not found in the firmware Secure Boot database (db). After successful pre-boot authentication, the handoff to Windows may fail and the computer may return to the VeraCrypt password prompt.\n\nBefore restarting this computer, do not disable or revoke Microsoft Windows Production PCA 2011 unless Windows Boot Manager has migrated to a Windows UEFI CA 2023-signed version and the firmware db contains Windows UEFI CA 2023. Apply the Windows Secure Boot certificate updates, then run VeraCrypt Repair/Reinstall if needed. Make sure you have an up-to-date VeraCrypt Rescue Disk before restarting.</entry>
<entry lang="en" key="SYSENC_EFI_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: VeraCrypt could not validate the installed EFI bootloader files against one complete embedded resource set and confirm that all known required signing CAs are present in db and not listed by dbx. Firmware may reject VeraCrypt when Secure Boot is enabled.\n\nBefore booting with Secure Boot enabled, restore the required Microsoft certificates and current dbx as needed, then run VeraCrypt Repair/Reinstall. Do not remove Microsoft Corporation UEFI CA 2011 until db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and the actual installed files match VeraCrypt's 2023 set. This check cannot model every image-hash or security-version revocation. Make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: VeraCrypt could not validate the embedded signature and known-CA compatibility of the Windows Boot Manager it chainloads (bootmgfw_ms.vc). The file may be missing, unreadable, not a Windows Boot Manager, have an unrecognized embedded signer, or use a known signing CA that is absent from db or listed by dbx. The handoff to Windows may fail when Secure Boot is enabled.\n\nComplete or repair the Windows Secure Boot certificate and boot-manager update, keep the VeraCrypt System Favorites service enabled, and run VeraCrypt Repair/Reinstall. Repair also checks Windows' serviced EFI_EX/EFI copies for a compatible current Boot Manager. If Windows cannot start, temporarily disable Secure Boot to recover. Make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_PCA2011_MIGRATION_NEEDED">Warning: The embedded signature of the Windows Boot Manager used by VeraCrypt (bootmgfw_ms.vc) is still issued by Microsoft Windows Production PCA 2011, although firmware db already contains Windows UEFI CA 2023. Its known CA is currently allowed, but it will no longer start after the PCA 2011 certificate is added to dbx.\n\nDo not apply the PCA 2011 revocation (AvailableUpdates bit 0x80, including combined value 0x280) yet. First complete the Windows 2023 boot-manager update while the VeraCrypt System Favorites service is enabled, then run VeraCrypt Repair/Reinstall so VeraCrypt can import a compatible serviced EFI_EX/EFI copy. Verify the embedded issuer of bootmgfw_ms.vc is Windows UEFI CA 2023 and make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
</localization>
<xs:schema attributeFormDefault="unqualified" elementFormDefault="qualified" xmlns:xs="http://www.w3.org/2001/XMLSchema">
<xs:element name="VeraCrypt">
+3 -2
View File
@@ -1688,8 +1688,9 @@
<entry lang="uz" key="SYSENC_EFI_UNSUPPORTED_SECUREBOOT_CA">Secure Boot ёқилган, аммо микродастурнинг Secure Boot маълумотлар базаси VeraCrypt EFI юклагичи қўллаб-қувватлайдиган Microsoft UEFI CA тўпламларининг ҳеч бирига ишонмайди. Microsoft Corporation UEFI CA 2011 ни ёки Microsoft UEFI CA 2023 ва Microsoft Option ROM UEFI CA 2023 иккаласини ёқинг, сўнг VeraCrypt "Таъмирлаш/қайта ўрнатиш" ни ишга туширинг. Ёки Secure Boot ни ўчиринг.</entry>
<entry lang="uz" key="MACOSX_CHECK_FILESYS">'OK' тугмасини босганингиздан сўнг Терминал ойнаси очилади ва танланган VeraCrypt томидаги файл тизими 'diskutil' ёрдамида текширилади. Натижа шу ойнада кўрсатилади.\n\nАгар текширувни бошлаб бўлмаса, унинг ўрнига Диск утилитаси ишга туширилади.</entry>
<entry lang="uz" key="MACOSX_REPAIR_FILESYS">'OK' тугмасини босганингиздан сўнг Терминал ойнаси очилади ва танланган VeraCrypt томидаги файл тизимини 'diskutil' ёрдамида тузатишга уриниб кўрилади. Натижа шу ойнада кўрсатилади.\n\nАгар тузатишни бошлаб бўлмаса, унинг ўрнига Диск утилитаси ишга туширилади.</entry>
<entry lang="en" key="SYSENC_EFI_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: Secure Boot is enabled, but the Microsoft UEFI CA that signs the installed VeraCrypt EFI bootloader was not found in the firmware Secure Boot database (db). The firmware may refuse to start VeraCrypt at the next reboot, so Windows will not start until Secure Boot is disabled or the trusted certificates/loader set are repaired.\n\nBefore restarting this computer, do not disable or remove Microsoft Corporation UEFI CA 2011 unless the firmware db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and VeraCrypt has been repaired/reinstalled so the 2023-signed loader set is installed. Enable the required Microsoft certificates in the BIOS/UEFI settings if needed, then run VeraCrypt Repair/Reinstall. Make sure you have an up-to-date VeraCrypt Rescue Disk before restarting.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: Secure Boot is enabled, but the Microsoft CA that signs the Windows Boot Manager copy used by VeraCrypt (bootmgfw_ms.vc) was not found in the firmware Secure Boot database (db). After successful pre-boot authentication, the handoff to Windows may fail and the computer may return to the VeraCrypt password prompt.\n\nBefore restarting this computer, do not disable or revoke Microsoft Windows Production PCA 2011 unless Windows Boot Manager has migrated to a Windows UEFI CA 2023-signed version and the firmware db contains Windows UEFI CA 2023. Apply the Windows Secure Boot certificate updates, then run VeraCrypt Repair/Reinstall if needed. Make sure you have an up-to-date VeraCrypt Rescue Disk before restarting.</entry>
<entry lang="en" key="SYSENC_EFI_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: VeraCrypt could not validate the installed EFI bootloader files against one complete embedded resource set and confirm that all known required signing CAs are present in db and not listed by dbx. Firmware may reject VeraCrypt when Secure Boot is enabled.\n\nBefore booting with Secure Boot enabled, restore the required Microsoft certificates and current dbx as needed, then run VeraCrypt Repair/Reinstall. Do not remove Microsoft Corporation UEFI CA 2011 until db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and the actual installed files match VeraCrypt's 2023 set. This check cannot model every image-hash or security-version revocation. Make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: VeraCrypt could not validate the embedded signature and known-CA compatibility of the Windows Boot Manager it chainloads (bootmgfw_ms.vc). The file may be missing, unreadable, not a Windows Boot Manager, have an unrecognized embedded signer, or use a known signing CA that is absent from db or listed by dbx. The handoff to Windows may fail when Secure Boot is enabled.\n\nComplete or repair the Windows Secure Boot certificate and boot-manager update, keep the VeraCrypt System Favorites service enabled, and run VeraCrypt Repair/Reinstall. Repair also checks Windows' serviced EFI_EX/EFI copies for a compatible current Boot Manager. If Windows cannot start, temporarily disable Secure Boot to recover. Make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_PCA2011_MIGRATION_NEEDED">Warning: The embedded signature of the Windows Boot Manager used by VeraCrypt (bootmgfw_ms.vc) is still issued by Microsoft Windows Production PCA 2011, although firmware db already contains Windows UEFI CA 2023. Its known CA is currently allowed, but it will no longer start after the PCA 2011 certificate is added to dbx.\n\nDo not apply the PCA 2011 revocation (AvailableUpdates bit 0x80, including combined value 0x280) yet. First complete the Windows 2023 boot-manager update while the VeraCrypt System Favorites service is enabled, then run VeraCrypt Repair/Reinstall so VeraCrypt can import a compatible serviced EFI_EX/EFI copy. Verify the embedded issuer of bootmgfw_ms.vc is Windows UEFI CA 2023 and make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
</localization>
<xs:schema attributeFormDefault="unqualified" elementFormDefault="qualified" xmlns:xs="http://www.w3.org/2001/XMLSchema">
<xs:element name="VeraCrypt">
+3 -2
View File
@@ -1688,8 +1688,9 @@
<entry lang="vi" key="SYSENC_EFI_UNSUPPORTED_SECUREBOOT_CA">Secure Boot đang được bật, nhưng cơ sở dữ liệu Secure Boot của chương trình cơ sở không tin cậy bất kỳ bộ Microsoft UEFI CA nào được bộ tải khởi động EFI của VeraCrypt hỗ trợ. Hãy bật Microsoft Corporation UEFI CA 2011, hoặc bật cả Microsoft UEFI CA 2023 và Microsoft Option ROM UEFI CA 2023, sau đó chạy tùy chọn Sửa chữa/Cài đặt lại của VeraCrypt. Hoặc, hãy tắt Secure Boot.</entry>
<entry lang="vi" key="MACOSX_CHECK_FILESYS">Một cửa sổ Terminal sẽ mở sau khi bạn bấm 'Đồng ý' và kiểm tra hệ thống tập tin trên tập đĩa VeraCrypt đã chọn bằng 'diskutil'. Kết quả sẽ được hiển thị trong cửa sổ đó.\n\nNếu không thể bắt đầu kiểm tra, Tiện ích Ổ đĩa sẽ được khởi chạy thay thế.</entry>
<entry lang="vi" key="MACOSX_REPAIR_FILESYS">Một cửa sổ Terminal sẽ mở sau khi bạn bấm 'Đồng ý' và thử sửa chữa hệ thống tập tin trên tập đĩa VeraCrypt đã chọn bằng 'diskutil'. Kết quả sẽ được hiển thị trong cửa sổ đó.\n\nNếu không thể bắt đầu sửa chữa, Tiện ích Ổ đĩa sẽ được khởi chạy thay thế.</entry>
<entry lang="en" key="SYSENC_EFI_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: Secure Boot is enabled, but the Microsoft UEFI CA that signs the installed VeraCrypt EFI bootloader was not found in the firmware Secure Boot database (db). The firmware may refuse to start VeraCrypt at the next reboot, so Windows will not start until Secure Boot is disabled or the trusted certificates/loader set are repaired.\n\nBefore restarting this computer, do not disable or remove Microsoft Corporation UEFI CA 2011 unless the firmware db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and VeraCrypt has been repaired/reinstalled so the 2023-signed loader set is installed. Enable the required Microsoft certificates in the BIOS/UEFI settings if needed, then run VeraCrypt Repair/Reinstall. Make sure you have an up-to-date VeraCrypt Rescue Disk before restarting.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: Secure Boot is enabled, but the Microsoft CA that signs the Windows Boot Manager copy used by VeraCrypt (bootmgfw_ms.vc) was not found in the firmware Secure Boot database (db). After successful pre-boot authentication, the handoff to Windows may fail and the computer may return to the VeraCrypt password prompt.\n\nBefore restarting this computer, do not disable or revoke Microsoft Windows Production PCA 2011 unless Windows Boot Manager has migrated to a Windows UEFI CA 2023-signed version and the firmware db contains Windows UEFI CA 2023. Apply the Windows Secure Boot certificate updates, then run VeraCrypt Repair/Reinstall if needed. Make sure you have an up-to-date VeraCrypt Rescue Disk before restarting.</entry>
<entry lang="en" key="SYSENC_EFI_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: VeraCrypt could not validate the installed EFI bootloader files against one complete embedded resource set and confirm that all known required signing CAs are present in db and not listed by dbx. Firmware may reject VeraCrypt when Secure Boot is enabled.\n\nBefore booting with Secure Boot enabled, restore the required Microsoft certificates and current dbx as needed, then run VeraCrypt Repair/Reinstall. Do not remove Microsoft Corporation UEFI CA 2011 until db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and the actual installed files match VeraCrypt's 2023 set. This check cannot model every image-hash or security-version revocation. Make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: VeraCrypt could not validate the embedded signature and known-CA compatibility of the Windows Boot Manager it chainloads (bootmgfw_ms.vc). The file may be missing, unreadable, not a Windows Boot Manager, have an unrecognized embedded signer, or use a known signing CA that is absent from db or listed by dbx. The handoff to Windows may fail when Secure Boot is enabled.\n\nComplete or repair the Windows Secure Boot certificate and boot-manager update, keep the VeraCrypt System Favorites service enabled, and run VeraCrypt Repair/Reinstall. Repair also checks Windows' serviced EFI_EX/EFI copies for a compatible current Boot Manager. If Windows cannot start, temporarily disable Secure Boot to recover. Make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_PCA2011_MIGRATION_NEEDED">Warning: The embedded signature of the Windows Boot Manager used by VeraCrypt (bootmgfw_ms.vc) is still issued by Microsoft Windows Production PCA 2011, although firmware db already contains Windows UEFI CA 2023. Its known CA is currently allowed, but it will no longer start after the PCA 2011 certificate is added to dbx.\n\nDo not apply the PCA 2011 revocation (AvailableUpdates bit 0x80, including combined value 0x280) yet. First complete the Windows 2023 boot-manager update while the VeraCrypt System Favorites service is enabled, then run VeraCrypt Repair/Reinstall so VeraCrypt can import a compatible serviced EFI_EX/EFI copy. Verify the embedded issuer of bootmgfw_ms.vc is Windows UEFI CA 2023 and make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
</localization>
<xs:schema attributeFormDefault="unqualified" elementFormDefault="qualified" xmlns:xs="http://www.w3.org/2001/XMLSchema">
<xs:element name="VeraCrypt">
+3 -2
View File
@@ -1689,8 +1689,9 @@
<entry lang="zh-cn" key="SYSENC_EFI_UNSUPPORTED_SECUREBOOT_CA">安全启动已启用,但固件的安全启动数据库不信任 VeraCrypt EFI 引导加载程序支持的任何 Microsoft UEFI CA 集合。请启用 Microsoft Corporation UEFI CA 2011,或同时启用 Microsoft UEFI CA 2023 和 Microsoft Option ROM UEFI CA 2023,然后运行 VeraCrypt 的“修复/重新安装”。或者,请禁用安全启动。</entry>
<entry lang="zh-cn" key="MACOSX_CHECK_FILESYS">按下“确定”后,将打开“终端”窗口,并使用 'diskutil' 检查所选 VeraCrypt 卷上的文件系统。结果将显示在该窗口中。\n\n如果无法开始检查,则将改为启动“磁盘工具”。</entry>
<entry lang="zh-cn" key="MACOSX_REPAIR_FILESYS">按下“确定”后,将打开“终端”窗口,并尝试使用 'diskutil' 修复所选 VeraCrypt 卷上的文件系统。结果将显示在该窗口中。\n\n如果无法开始修复,则将改为启动“磁盘工具”。</entry>
<entry lang="en" key="SYSENC_EFI_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: Secure Boot is enabled, but the Microsoft UEFI CA that signs the installed VeraCrypt EFI bootloader was not found in the firmware Secure Boot database (db). The firmware may refuse to start VeraCrypt at the next reboot, so Windows will not start until Secure Boot is disabled or the trusted certificates/loader set are repaired.\n\nBefore restarting this computer, do not disable or remove Microsoft Corporation UEFI CA 2011 unless the firmware db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and VeraCrypt has been repaired/reinstalled so the 2023-signed loader set is installed. Enable the required Microsoft certificates in the BIOS/UEFI settings if needed, then run VeraCrypt Repair/Reinstall. Make sure you have an up-to-date VeraCrypt Rescue Disk before restarting.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: Secure Boot is enabled, but the Microsoft CA that signs the Windows Boot Manager copy used by VeraCrypt (bootmgfw_ms.vc) was not found in the firmware Secure Boot database (db). After successful pre-boot authentication, the handoff to Windows may fail and the computer may return to the VeraCrypt password prompt.\n\nBefore restarting this computer, do not disable or revoke Microsoft Windows Production PCA 2011 unless Windows Boot Manager has migrated to a Windows UEFI CA 2023-signed version and the firmware db contains Windows UEFI CA 2023. Apply the Windows Secure Boot certificate updates, then run VeraCrypt Repair/Reinstall if needed. Make sure you have an up-to-date VeraCrypt Rescue Disk before restarting.</entry>
<entry lang="en" key="SYSENC_EFI_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: VeraCrypt could not validate the installed EFI bootloader files against one complete embedded resource set and confirm that all known required signing CAs are present in db and not listed by dbx. Firmware may reject VeraCrypt when Secure Boot is enabled.\n\nBefore booting with Secure Boot enabled, restore the required Microsoft certificates and current dbx as needed, then run VeraCrypt Repair/Reinstall. Do not remove Microsoft Corporation UEFI CA 2011 until db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and the actual installed files match VeraCrypt's 2023 set. This check cannot model every image-hash or security-version revocation. Make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: VeraCrypt could not validate the embedded signature and known-CA compatibility of the Windows Boot Manager it chainloads (bootmgfw_ms.vc). The file may be missing, unreadable, not a Windows Boot Manager, have an unrecognized embedded signer, or use a known signing CA that is absent from db or listed by dbx. The handoff to Windows may fail when Secure Boot is enabled.\n\nComplete or repair the Windows Secure Boot certificate and boot-manager update, keep the VeraCrypt System Favorites service enabled, and run VeraCrypt Repair/Reinstall. Repair also checks Windows' serviced EFI_EX/EFI copies for a compatible current Boot Manager. If Windows cannot start, temporarily disable Secure Boot to recover. Make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_PCA2011_MIGRATION_NEEDED">Warning: The embedded signature of the Windows Boot Manager used by VeraCrypt (bootmgfw_ms.vc) is still issued by Microsoft Windows Production PCA 2011, although firmware db already contains Windows UEFI CA 2023. Its known CA is currently allowed, but it will no longer start after the PCA 2011 certificate is added to dbx.\n\nDo not apply the PCA 2011 revocation (AvailableUpdates bit 0x80, including combined value 0x280) yet. First complete the Windows 2023 boot-manager update while the VeraCrypt System Favorites service is enabled, then run VeraCrypt Repair/Reinstall so VeraCrypt can import a compatible serviced EFI_EX/EFI copy. Verify the embedded issuer of bootmgfw_ms.vc is Windows UEFI CA 2023 and make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
</localization>
<xs:schema attributeFormDefault="unqualified" elementFormDefault="qualified" xmlns:xs="http://www.w3.org/2001/XMLSchema">
<xs:element name="VeraCrypt">
+3 -2
View File
@@ -1688,8 +1688,9 @@
<entry lang="zh-hk" key="SYSENC_EFI_UNSUPPORTED_SECUREBOOT_CA">Secure Boot 已啟用,但韌體的 Secure Boot 資料庫不信任 VeraCrypt EFI 開機載入程式所支援的任何 Microsoft UEFI CA 集合。請啟用 Microsoft Corporation UEFI CA 2011,或同時啟用 Microsoft UEFI CA 2023 和 Microsoft Option ROM UEFI CA 2023,然後執行 VeraCrypt 修復或重新安裝。或者,請停用 Secure Boot。</entry>
<entry lang="zh-hk" key="MACOSX_CHECK_FILESYS">按下 [確定] 後,將會開啟「終端機」視窗,並使用 'diskutil' 檢查所選 VeraCrypt 加密區上的檔案系統。結果會顯示在該視窗中。\n\n如果無法開始檢查,將會改為啟動「磁碟工具程式」。</entry>
<entry lang="zh-hk" key="MACOSX_REPAIR_FILESYS">按下 [確定] 後,將會開啟「終端機」視窗,並使用 'diskutil' 嘗試修復所選 VeraCrypt 加密區上的檔案系統。結果會顯示在該視窗中。\n\n如果無法開始修復,將會改為啟動「磁碟工具程式」。</entry>
<entry lang="en" key="SYSENC_EFI_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: Secure Boot is enabled, but the Microsoft UEFI CA that signs the installed VeraCrypt EFI bootloader was not found in the firmware Secure Boot database (db). The firmware may refuse to start VeraCrypt at the next reboot, so Windows will not start until Secure Boot is disabled or the trusted certificates/loader set are repaired.\n\nBefore restarting this computer, do not disable or remove Microsoft Corporation UEFI CA 2011 unless the firmware db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and VeraCrypt has been repaired/reinstalled so the 2023-signed loader set is installed. Enable the required Microsoft certificates in the BIOS/UEFI settings if needed, then run VeraCrypt Repair/Reinstall. Make sure you have an up-to-date VeraCrypt Rescue Disk before restarting.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: Secure Boot is enabled, but the Microsoft CA that signs the Windows Boot Manager copy used by VeraCrypt (bootmgfw_ms.vc) was not found in the firmware Secure Boot database (db). After successful pre-boot authentication, the handoff to Windows may fail and the computer may return to the VeraCrypt password prompt.\n\nBefore restarting this computer, do not disable or revoke Microsoft Windows Production PCA 2011 unless Windows Boot Manager has migrated to a Windows UEFI CA 2023-signed version and the firmware db contains Windows UEFI CA 2023. Apply the Windows Secure Boot certificate updates, then run VeraCrypt Repair/Reinstall if needed. Make sure you have an up-to-date VeraCrypt Rescue Disk before restarting.</entry>
<entry lang="en" key="SYSENC_EFI_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: VeraCrypt could not validate the installed EFI bootloader files against one complete embedded resource set and confirm that all known required signing CAs are present in db and not listed by dbx. Firmware may reject VeraCrypt when Secure Boot is enabled.\n\nBefore booting with Secure Boot enabled, restore the required Microsoft certificates and current dbx as needed, then run VeraCrypt Repair/Reinstall. Do not remove Microsoft Corporation UEFI CA 2011 until db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and the actual installed files match VeraCrypt's 2023 set. This check cannot model every image-hash or security-version revocation. Make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: VeraCrypt could not validate the embedded signature and known-CA compatibility of the Windows Boot Manager it chainloads (bootmgfw_ms.vc). The file may be missing, unreadable, not a Windows Boot Manager, have an unrecognized embedded signer, or use a known signing CA that is absent from db or listed by dbx. The handoff to Windows may fail when Secure Boot is enabled.\n\nComplete or repair the Windows Secure Boot certificate and boot-manager update, keep the VeraCrypt System Favorites service enabled, and run VeraCrypt Repair/Reinstall. Repair also checks Windows' serviced EFI_EX/EFI copies for a compatible current Boot Manager. If Windows cannot start, temporarily disable Secure Boot to recover. Make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_PCA2011_MIGRATION_NEEDED">Warning: The embedded signature of the Windows Boot Manager used by VeraCrypt (bootmgfw_ms.vc) is still issued by Microsoft Windows Production PCA 2011, although firmware db already contains Windows UEFI CA 2023. Its known CA is currently allowed, but it will no longer start after the PCA 2011 certificate is added to dbx.\n\nDo not apply the PCA 2011 revocation (AvailableUpdates bit 0x80, including combined value 0x280) yet. First complete the Windows 2023 boot-manager update while the VeraCrypt System Favorites service is enabled, then run VeraCrypt Repair/Reinstall so VeraCrypt can import a compatible serviced EFI_EX/EFI copy. Verify the embedded issuer of bootmgfw_ms.vc is Windows UEFI CA 2023 and make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
</localization>
<xs:schema attributeFormDefault="unqualified" elementFormDefault="qualified" xmlns:xs="http://www.w3.org/2001/XMLSchema">
<xs:element name="VeraCrypt">
+3 -2
View File
@@ -1688,8 +1688,9 @@
<entry lang="zh-tw" key="SYSENC_EFI_UNSUPPORTED_SECUREBOOT_CA">Secure Boot 已啟用,但韌體的 Secure Boot 資料庫不信任 VeraCrypt EFI 開機載入程式所支援的任何 Microsoft UEFI CA 集合。請啟用 Microsoft Corporation UEFI CA 2011,或同時啟用 Microsoft UEFI CA 2023 和 Microsoft Option ROM UEFI CA 2023,然後執行 VeraCrypt 修復/重新安裝。或者,請停用 Secure Boot。</entry>
<entry lang="zh-tw" key="MACOSX_CHECK_FILESYS">按下「確定」後,將會開啟「終端機」視窗,並使用「diskutil」檢查所選 VeraCrypt 加密區上的檔案系統。結果會顯示在該視窗中。\n\n如果無法開始檢查,將會改為啟動「磁碟工具程式」。</entry>
<entry lang="zh-tw" key="MACOSX_REPAIR_FILESYS">按下「確定」後,將會開啟「終端機」視窗,並使用「diskutil」嘗試修復所選 VeraCrypt 加密區上的檔案系統。結果會顯示在該視窗中。\n\n如果無法開始修復,將會改為啟動「磁碟工具程式」。</entry>
<entry lang="en" key="SYSENC_EFI_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: Secure Boot is enabled, but the Microsoft UEFI CA that signs the installed VeraCrypt EFI bootloader was not found in the firmware Secure Boot database (db). The firmware may refuse to start VeraCrypt at the next reboot, so Windows will not start until Secure Boot is disabled or the trusted certificates/loader set are repaired.\n\nBefore restarting this computer, do not disable or remove Microsoft Corporation UEFI CA 2011 unless the firmware db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and VeraCrypt has been repaired/reinstalled so the 2023-signed loader set is installed. Enable the required Microsoft certificates in the BIOS/UEFI settings if needed, then run VeraCrypt Repair/Reinstall. Make sure you have an up-to-date VeraCrypt Rescue Disk before restarting.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: Secure Boot is enabled, but the Microsoft CA that signs the Windows Boot Manager copy used by VeraCrypt (bootmgfw_ms.vc) was not found in the firmware Secure Boot database (db). After successful pre-boot authentication, the handoff to Windows may fail and the computer may return to the VeraCrypt password prompt.\n\nBefore restarting this computer, do not disable or revoke Microsoft Windows Production PCA 2011 unless Windows Boot Manager has migrated to a Windows UEFI CA 2023-signed version and the firmware db contains Windows UEFI CA 2023. Apply the Windows Secure Boot certificate updates, then run VeraCrypt Repair/Reinstall if needed. Make sure you have an up-to-date VeraCrypt Rescue Disk before restarting.</entry>
<entry lang="en" key="SYSENC_EFI_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: VeraCrypt could not validate the installed EFI bootloader files against one complete embedded resource set and confirm that all known required signing CAs are present in db and not listed by dbx. Firmware may reject VeraCrypt when Secure Boot is enabled.\n\nBefore booting with Secure Boot enabled, restore the required Microsoft certificates and current dbx as needed, then run VeraCrypt Repair/Reinstall. Do not remove Microsoft Corporation UEFI CA 2011 until db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and the actual installed files match VeraCrypt's 2023 set. This check cannot model every image-hash or security-version revocation. Make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: VeraCrypt could not validate the embedded signature and known-CA compatibility of the Windows Boot Manager it chainloads (bootmgfw_ms.vc). The file may be missing, unreadable, not a Windows Boot Manager, have an unrecognized embedded signer, or use a known signing CA that is absent from db or listed by dbx. The handoff to Windows may fail when Secure Boot is enabled.\n\nComplete or repair the Windows Secure Boot certificate and boot-manager update, keep the VeraCrypt System Favorites service enabled, and run VeraCrypt Repair/Reinstall. Repair also checks Windows' serviced EFI_EX/EFI copies for a compatible current Boot Manager. If Windows cannot start, temporarily disable Secure Boot to recover. Make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_PCA2011_MIGRATION_NEEDED">Warning: The embedded signature of the Windows Boot Manager used by VeraCrypt (bootmgfw_ms.vc) is still issued by Microsoft Windows Production PCA 2011, although firmware db already contains Windows UEFI CA 2023. Its known CA is currently allowed, but it will no longer start after the PCA 2011 certificate is added to dbx.\n\nDo not apply the PCA 2011 revocation (AvailableUpdates bit 0x80, including combined value 0x280) yet. First complete the Windows 2023 boot-manager update while the VeraCrypt System Favorites service is enabled, then run VeraCrypt Repair/Reinstall so VeraCrypt can import a compatible serviced EFI_EX/EFI copy. Verify the embedded issuer of bootmgfw_ms.vc is Windows UEFI CA 2023 and make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
</localization>
<xs:schema attributeFormDefault="unqualified" elementFormDefault="qualified" xmlns:xs="http://www.w3.org/2001/XMLSchema">
<xs:element name="VeraCrypt">
+68 -18
View File
@@ -53,7 +53,7 @@ Since version 1.26.29, VeraCrypt ships two complete sets of Microsoft-signed EFI
</li>
</ul>
<div style="text-align:left; margin-top:19px; margin-bottom:19px; padding-top:0px; padding-bottom:0px">
At installation, upgrade, repair and system encryption time, VeraCrypt reads the firmware db and selects the loader set whose signing CAs are trusted. If the 2023 CA pair is present, the 2023 set is preferred; otherwise the 2011 set is used when <em>Microsoft Corporation UEFI CA 2011</em> is trusted. If Secure Boot is enabled and neither set is trusted by the firmware, VeraCrypt refuses to install its bootloader and displays an error instead of installing a loader that the firmware would reject at the next reboot.
At installation, upgrade, repair and system encryption time, VeraCrypt reads the firmware db and dbx and selects a loader set whose known signing CAs are present in db and not listed in dbx. The optional dbx variable may legitimately be absent (especially on custom-key systems); VeraCrypt treats that state as an empty forbidden database, while a genuine read or parse failure remains an error when Secure Boot is enabled. If the 2023 CA pair is available, the 2023 set is preferred; otherwise the 2011 set is used when <em>Microsoft Corporation UEFI CA 2011</em> is available. If Secure Boot is enabled and neither set is compatible with the known CA policy, VeraCrypt refuses to install its bootloader rather than knowingly installing a loader whose CA the firmware will reject.
</div>
<div style="text-align:left; margin-top:19px; margin-bottom:19px; padding-top:0px; padding-bottom:0px">
Changing the firmware Secure Boot configuration (for example enabling additional certificates in the BIOS setup) does not by itself rewrite the files already installed on the EFI System Partition. Run VeraCrypt Setup in <em>Repair/Reinstall</em> mode after changing the firmware Secure Boot database, or let the VeraCrypt System Favorites service refresh the loader automatically (it re-evaluates the selection at Windows startup, session logon/unlock, resume from sleep, and shutdown).
@@ -68,10 +68,27 @@ HKEY_LOCAL_MACHINE\SOFTWARE\VeraCrypt\Diagnostics\EfiBootLoader
EfiBootLoaderResourceSet REG_DWORD 2011 (0x7db) or 2023 (0x7e7)
EfiBootLoaderSelectionReason REG_SZ human readable selection reason
EfiBootLoaderFirmwareDbLastError REG_DWORD last firmware db read/parse error (0 = none)
EfiBootLoaderFirmwareDbxLastError REG_DWORD last firmware dbx read/parse error (0 = none)
EfiBootLoaderSelectionTimeUtc REG_SZ time of the last selection
EfiBootChainStatusKnown REG_DWORD db/dbx known-CA assessment is available
EfiBootChainLastError REG_DWORD last incomplete-assessment error (0 = none)
SecureBootEnabled REG_DWORD Secure Boot state at the last assessment
FirmwareDbxPresent REG_DWORD dbx exists (0 is valid: optional variable absent)
VeraCryptLoaderFilesValid REG_DWORD installed DCS files match one embedded set
VeraCryptLoaderKnownCaAllowed REG_DWORD known required CAs are in db and not in dbx
VeraCryptLoaderKnownCaRevoked REG_DWORD a known required VeraCrypt CA is in dbx
EfiBootLoaderInstalledResourceSet REG_DWORD set identified from the actual ESP files
EfiBootLoaderRecordedResourceSet REG_DWORD set recorded at the last successful refresh
WindowsLoaderInspectionSucceeded REG_DWORD embedded PE signature was parsed
WindowsLoaderPresent REG_DWORD bootmgfw_ms.vc was found
WindowsLoaderSigner REG_DWORD 0 (unknown), 2011, or 2023
WindowsLoaderKnownCaAllowed REG_DWORD known signing CA is in db and not in dbx
WindowsLoaderKnownCaRevoked REG_DWORD known Windows loader signing CA is in dbx
WindowsLoaderMigrationRecommended REG_DWORD PCA 2011 copy remains while CA 2023 is available
EfiBootChainCheckTimeUtc REG_SZ time of the last attempted chain check
</pre>
<div style="text-align:left; margin-top:19px; margin-bottom:19px; padding-top:0px; padding-bottom:0px">
The following commands, run from an elevated PowerShell prompt, show which Microsoft certificates are present in the firmware db (note that on some firmware the names may not be visible in this simple text search even when the certificates are present):
The following commands, run from an elevated PowerShell prompt, provide additional evidence. The text search is only a convenience and may not expose certificate names on every firmware. An absent dbx is valid; any other exception needs investigation.
</div>
<pre>
reg query HKLM\SOFTWARE\VeraCrypt\Diagnostics\EfiBootLoader /s
@@ -83,9 +100,33 @@ $t = [Text.Encoding]::ASCII.GetString((Get-SecureBootUEFI db).Bytes)
'Microsoft UEFI CA 2023',
'Microsoft Option ROM UEFI CA 2023' |
ForEach-Object { "$_ : $($t -match [regex]::Escape($_))" }
try {
$dbx = (Get-SecureBootUEFI dbx).Bytes
'Windows PCA 2011 in dbx: ' +
([Text.Encoding]::ASCII.GetString($dbx) -match
'Microsoft Windows Production PCA 2011')
} catch {
'dbx is absent or could not be read; check FirmwareDbxPresent and EfiBootLoaderFirmwareDbxLastError'
}
# After mounting the EFI System Partition as S:, inspect the embedded signer.
# Do not use Get-AuthenticodeSignature here: it may report a catalog signer.
Get-PfxCertificate -FilePath S:\EFI\Microsoft\Boot\bootmgfw_ms.vc |
Select-Object Subject,Issuer,Thumbprint
Get-WinEvent -FilterHashtable @{
LogName='System'
ProviderName='Microsoft-Windows-TPM-WMI'
Id=@(1036,1037,1043,1044,1045,1797,1798,1799,1800,1801,1802,1803)
StartTime=(Get-Date).AddDays(-30)
} | Select-Object TimeCreated,Id,LevelDisplayName,Message
</pre>
<div style="text-align:left; margin-top:19px; margin-bottom:19px; padding-top:0px; padding-bottom:0px">
In addition, the VeraCrypt System Favorites service writes a warning to the Windows Application event log (source <em>VeraCryptSystemFavorites</em>) when it detects that the active Secure Boot db no longer trusts a component of the installed boot chain.
In addition, the VeraCrypt System Favorites service writes a warning to the Windows Application event log (source <em>VeraCryptSystemFavorites</em>) when installed DCS files do not match an embedded set, the chainloaded Windows Boot Manager is missing or its embedded signer cannot be identified, a known required CA is absent from db or listed in dbx, or a PCA 2011-signed Windows Boot Manager should be migrated before revocation.
</div>
<div style="text-align:left; margin-top:19px; margin-bottom:19px; padding-top:0px; padding-bottom:0px">
These values are deliberately described as a <em>known-CA compatibility assessment</em>, not proof that firmware will accept an image. UEFI dbx can also contain individual image hashes, certificate TBS hashes and security-version revocations that this diagnostic does not fully evaluate. A successful controlled reboot with Secure Boot enabled remains the final validation.
</div>
<h2>The Microsoft 2023 certificate transition</h2>
@@ -97,10 +138,10 @@ Two important points for VeraCrypt users:
</div>
<ul style="text-align:left; margin-top:18px; margin-bottom:19px; padding-top:0px; padding-bottom:0px">
<li style="text-align:left; margin-top:0px; margin-bottom:0px; padding-top:0px; padding-bottom:0px">
<strong>Certificate expiration does not stop already-installed loaders from booting.</strong> UEFI firmware does not evaluate certificate validity periods during Secure Boot verification, so bootloaders signed through the 2011 CAs continue to load after the expiration dates on virtually all firmware implementations. The expiration means that <em>new</em> binaries can no longer be signed through the 2011 CAs, and that systems which never receive the 2023 certificates will stop receiving boot-chain security updates.
<strong>Certificate expiration does not normally stop already-installed loaders from booting.</strong> UEFI Secure Boot image verification does not normally enforce the signing certificate's validity period, so a loader signed through a 2011 CA is not rejected merely because that CA certificate has expired. Expiration is nevertheless the end of the signing ecosystem for new binaries; systems that never receive the 2023 certificates cannot continue receiving boot-chain updates signed through the replacement CAs.
</li>
<li style="text-align:left; margin-top:0px; margin-bottom:0px; padding-top:0px; padding-bottom:0px">
<strong>A future revocation of the 2011 CAs would stop them from booting.</strong> Microsoft has announced that, at a later stage of the transition (not yet scheduled), the 2011 CAs may be revoked via the Secure Boot forbidden signature database (dbx) on systems that have completed the transition. Migrating to the 2023 loader set before that stage is therefore recommended.
<strong>Expiration and revocation are separate.</strong> Microsoft provides a separate, deliberate mitigation that adds <em>Microsoft Windows Production PCA 2011</em> to the Secure Boot forbidden signature database (dbx); once applied, every Windows Boot Manager signed through that CA is rejected. This Windows PCA revocation is not part of the <code>0x5944</code> certificate/Boot Manager migration described below. As of July 2026, <a href="https://techcommunity.microsoft.com/blog/linuxandopensourceblog/what-it-teams-need-to-know-about-linux-secure-boot-certificates-expiring-in-2026/4530725">Microsoft states that it has no plan to revoke Microsoft Corporation UEFI CA 2011</a>, the third-party CA used by the VeraCrypt 2011 loader set. Nevertheless, migrating both the VeraCrypt and Windows portions of the chain to their 2023 CAs is recommended before applying any Windows PCA 2011 revocation.
</li>
</ul>
@@ -114,10 +155,13 @@ If the firmware provides no way to trust a Microsoft third-party CA, VeraCrypt s
<h2>Updating an existing system to the 2023 certificates</h2>
<div style="text-align:left; margin-top:19px; margin-bottom:19px; padding-top:0px; padding-bottom:0px">
Windows deploys the 2023 certificates through a staged, telemetry-driven rollout. Devices are updated automatically only once Microsoft has high confidence in their hardware/firmware combination. Because a system-encrypted VeraCrypt machine boots through a non-standard boot chain (the VeraCrypt loader occupies the Windows Boot Manager location), such machines are typically not classified for automatic update and the rollout does not trigger on its own. The Windows Security app may report that there is <em>&quot;not yet enough data to classify your device&quot;</em>. For the same reason, opting into the Microsoft-managed rollout (the <code>MicrosoftUpdateManagedOptIn</code> registry value) may not be sufficient on these machines.
Windows deploys the 2023 certificates through a staged, telemetry-driven rollout. Devices are updated automatically only once Microsoft has sufficient confidence in their hardware/firmware combination. A VeraCrypt system-encrypted machine has a non-standard boot chain because the VeraCrypt loader occupies the standard Windows Boot Manager location; this may affect servicing checks, but Microsoft does not document VeraCrypt as a categorical exclusion from the rollout. A Windows Security report that there is <em>&quot;not yet enough data to classify your device&quot;</em> describes the current rollout state, not proof that VeraCrypt caused it.
</div>
<div style="text-align:left; margin-top:19px; margin-bottom:19px; padding-top:0px; padding-bottom:0px">
Microsoft documents a registry value that triggers the update explicitly (see Microsoft KB5068202, <em>&quot;Registry key updates for Secure Boot&quot;</em>). From an elevated command prompt:
The <code>MicrosoftUpdateManagedOptIn</code> value is a separate opt-in to Microsoft's asynchronous managed rollout. It requires the applicable Windows diagnostic-data configuration and does not guarantee immediate deployment. Do not mix that method with a manual <code>AvailableUpdates</code> deployment; choose one method and monitor it to completion.
</div>
<div style="text-align:left; margin-top:19px; margin-bottom:19px; padding-top:0px; padding-bottom:0px">
For an administrator performing a controlled manual deployment, Microsoft documents <code>0x5944</code> as the explicit request for the 2023 CA, KEK, and Windows Boot Manager migration (see <a href="https://support.microsoft.com/en-us/topic/registry-key-updates-for-secure-boot-windows-devices-with-it-managed-updates-a7be69c9-4634-42e1-9ca1-df06f43f360d">Microsoft's registry-key guidance for Secure Boot</a>). It does <strong>not</strong> apply the Windows PCA 2011 dbx revocation. VeraCrypt does not set this registry value automatically. On a fully updated Windows installation, after reviewing the precautions below:
</div>
<pre>
reg add HKLM\SYSTEM\CurrentControlSet\Control\Secureboot /v AvailableUpdates /t REG_DWORD /d 0x5944 /f
@@ -126,7 +170,7 @@ rem optionally run the servicing task immediately (it otherwise runs every 12 ho
schtasks /Run /TN "\Microsoft\Windows\PI\Secure-Boot-Update"
</pre>
<div style="text-align:left; margin-top:19px; margin-bottom:19px; padding-top:0px; padding-bottom:0px">
Progress can be monitored under <code>HKLM\SYSTEM\CurrentControlSet\Control\Secureboot\Servicing</code> (values <code>UEFICA2023Status</code> and <code>UEFICA2023Error</code>) and through Secure Boot servicing events in the Windows event log. The db update adds <em>Windows UEFI CA 2023</em>, and, on systems that already trust <em>Microsoft Corporation UEFI CA 2011</em> (which is the case on every VeraCrypt Secure Boot system), it also adds <em>Microsoft UEFI CA 2023</em> and <em>Microsoft Option ROM UEFI CA 2023</em>.
Progress can be monitored under <code>HKLM\SYSTEM\CurrentControlSet\Control\SecureBoot</code> and its <code>Servicing</code> subkey, and through the Secure Boot servicing events shown above. The expected <code>AvailableUpdates</code> progression is <code>0x5944</code>, then <code>0x4100</code>, and finally the terminal modifier <code>0x4000</code> after the required task runs and restarts. <code>UEFICA2023Status=Updated</code> is useful Windows-servicing evidence, but it may remain incomplete when VeraCrypt intentionally occupies the standard ESP path. Conversely, <code>0x4000</code> alone does not prove that VeraCrypt's <code>bootmgfw_ms.vc</code> was refreshed. Verify the firmware CAs, the actual installed DCS resource set, the embedded signer of <code>bootmgfw_ms.vc</code>, and the absence of unresolved servicing errors. The db update adds <em>Windows UEFI CA 2023</em>. It conditionally adds <em>Microsoft UEFI CA 2023</em> and <em>Microsoft Option ROM UEFI CA 2023</em> on systems that already trust <em>Microsoft Corporation UEFI CA 2011</em>; not every system on which VeraCrypt can be installed necessarily has that legacy third-party CA.
</div>
<div style="text-align:left; margin-top:19px; margin-bottom:19px; padding-top:0px; padding-bottom:0px">
Before triggering the update on a VeraCrypt system-encrypted machine, take the following precautions:
@@ -139,7 +183,10 @@ Before triggering the update on a VeraCrypt system-encrypted machine, take the f
<strong>Create or update your VeraCrypt Rescue Disk first</strong>, and verify that it boots.
</li>
<li style="text-align:left; margin-top:0px; margin-bottom:0px; padding-top:0px; padding-bottom:0px">
Do not disable the <em>VeraCrypt System Favorites</em> service or its bootloader update function. When the Windows servicing task installs the 2023-signed Windows Boot Manager at the standard location, this service is what preserves the VeraCrypt boot chain: it saves the new boot manager as <code>bootmgfw_ms.vc</code> (the copy VeraCrypt chainloads after pre-boot authentication) and restores the VeraCrypt loader.
Record the existing <code>AvailableUpdates</code> value and make sure the device is not already managed by another Secure Boot deployment policy. Setting <code>0x5944</code> requests authenticated firmware db/KEK writes and a boot-file replacement. Firmware defects, a missing OEM-authorized KEK, interruption during servicing, or overwriting another pending deployment value can leave the transition incomplete. Use the computer manufacturer's recovery procedure if a firmware variable update fails.
</li>
<li style="text-align:left; margin-top:0px; margin-bottom:0px; padding-top:0px; padding-bottom:0px">
Do not disable the <em>VeraCrypt System Favorites</em> service or its bootloader update function. When Windows installs a new Boot Manager at the standard ESP location, the service saves it as <code>bootmgfw_ms.vc</code> and restores the VeraCrypt loader. If Windows leaves the standard path unchanged, current VeraCrypt versions also inspect Windows' serviced copies under <code>%SystemRoot%\Boot\EFI_EX</code> and <code>%SystemRoot%\Boot\EFI</code>, verify the embedded signer, and atomically refresh <code>bootmgfw_ms.vc</code> with the best copy permitted by the known firmware CA policy.
</li>
<li style="text-align:left; margin-top:0px; margin-bottom:0px; padding-top:0px; padding-bottom:0px">
<strong>Hidden operating system users should not trigger the update from the hidden OS.</strong> The automatic boot-chain preservation is disabled when a hidden OS is running.
@@ -148,23 +195,26 @@ Do not disable the <em>VeraCrypt System Favorites</em> service or its bootloader
Avoid forced power-off between the moment Windows replaces the boot manager and the next normal restart or shutdown. On most systems the VeraCrypt boot entry keeps the machine bootable during this window, but firmware that ignores the boot order could boot the plain Windows Boot Manager, which cannot start an encrypted Windows (recoverable with the Rescue Disk).
</li>
<li style="text-align:left; margin-top:0px; margin-bottom:0px; padding-top:0px; padding-bottom:0px">
Expect Windows to keep reporting the Secure Boot certificate servicing as not fully completed even after everything works. Windows checks whether the file at the standard boot manager location is the 2023-signed Microsoft Boot Manager; on a VeraCrypt system that location holds the VeraCrypt loader by design. This status is cosmetic and does not affect the security or operation of the system.
Windows may continue reporting the transition as incomplete because the standard Windows Boot Manager location contains the VeraCrypt loader by design. Treat this as a possible servicing false negative only after the firmware db contains the required 2023 CAs, <code>EfiBootLoaderInstalledResourceSet</code> identifies the actual 2023 DCS files, the <em>embedded</em> issuer of <code>bootmgfw_ms.vc</code> is <em>Windows UEFI CA 2023</em>, and the event log contains no unresolved Secure Boot servicing failure.
</li>
</ul>
<div style="text-align:left; margin-top:19px; margin-bottom:19px; padding-top:0px; padding-bottom:0px">
After the db update has been applied, VeraCrypt automatically switches to the 2023 loader set the next time the bootloader is refreshed (Repair/Reinstall, upgrade, or one of the automatic refresh points of the System Favorites service). You can verify the result in the diagnostics registry key described above and recreate the Rescue Disk when prompted.
After the db update has been applied, VeraCrypt automatically switches to the 2023 DCS set and attempts to import the current 2023-signed Windows Boot Manager the next time the bootloader is refreshed (Repair/Reinstall, upgrade, or one of the automatic refresh points of the System Favorites service). Verify the actual result in the diagnostics registry key and recreate the Rescue Disk when prompted.
</div>
<div style="text-align:left; margin-top:19px; margin-bottom:19px; padding-top:0px; padding-bottom:0px">
The Windows PCA 2011 dbx revocation is a later, separate operation documented in <a href="https://support.microsoft.com/en-us/topic/how-to-manage-the-windows-boot-manager-revocations-for-secure-boot-changes-associated-with-cve-2023-24932-41a975df-beb2-40c1-99a3-b3ff139f832d">Microsoft KB5025885</a>. Do not request its <code>0x80</code> bit (or the combined <code>0x280</code> value, which also requests the SVN update) until <code>bootmgfw_ms.vc</code> is confirmed to be signed by <em>Windows UEFI CA 2023</em>, recovery media are current, and a controlled reboot with Secure Boot enabled has succeeded. VeraCrypt never enables this revocation automatically.
</div>
<h2>Recovering from a Secure Boot boot failure</h2>
<div style="text-align:left; margin-top:19px; margin-bottom:19px; padding-top:0px; padding-bottom:0px">
Two distinct failures can occur when the firmware Secure Boot configuration no longer trusts a component of the boot chain:
Two distinct failures can occur when the firmware Secure Boot policy rejects a component of the boot chain (because of a missing CA, a CA or image revocation, or another policy restriction):
</div>
<ul style="text-align:left; margin-top:18px; margin-bottom:19px; padding-top:0px; padding-bottom:0px">
<li style="text-align:left; margin-top:0px; margin-bottom:0px; padding-top:0px; padding-bottom:0px">
<strong>Before the password prompt</strong> (message such as <em>&quot;Secure Boot Violation&quot;</em> or an immediate return to the firmware): the firmware does not trust the CA that signs the installed VeraCrypt loader.
<strong>Before the password prompt</strong> (message such as <em>&quot;Secure Boot Violation&quot;</em> or an immediate return to the firmware): the firmware policy rejects the installed VeraCrypt loader.
</li>
<li style="text-align:left; margin-top:0px; margin-bottom:0px; padding-top:0px; padding-bottom:0px">
<strong>After successful password entry</strong> (an explicit Secure Boot error message from the VeraCrypt loader, or on older loader versions a return to the password prompt): the firmware does not trust the CA that signs the Windows Boot Manager copy (<code>bootmgfw_ms.vc</code>) that VeraCrypt chainloads.
<strong>After successful password entry</strong> (an explicit Secure Boot error message from the VeraCrypt loader, or on older loader versions a return to the password prompt): the firmware policy rejects the Windows Boot Manager copy (<code>bootmgfw_ms.vc</code>) that VeraCrypt chainloads.
</li>
</ul>
<div style="text-align:left; margin-top:19px; margin-bottom:19px; padding-top:0px; padding-bottom:0px">
@@ -172,19 +222,19 @@ In both cases, the recovery procedure is:
</div>
<ol style="text-align:left; margin-top:18px; margin-bottom:19px; padding-top:0px; padding-bottom:0px">
<li style="text-align:left; margin-top:0px; margin-bottom:0px; padding-top:0px; padding-bottom:0px">
Temporarily disable Secure Boot in the firmware setup and start Windows normally (VeraCrypt pre-boot authentication works with Secure Boot disabled), or boot the VeraCrypt Rescue Disk and use <em>&quot;Restore VeraCrypt loader binaries to system disk&quot;</em>.
Temporarily disable Secure Boot in the firmware setup and start Windows normally (VeraCrypt pre-boot authentication works with Secure Boot disabled). The VeraCrypt Rescue Disk can restore VeraCrypt loader components when they are missing or damaged, but it cannot manufacture a current Windows Boot Manager or make a PCA 2011-signed <code>bootmgfw_ms.vc</code> acceptable after that CA has been added to dbx; it is not a substitute for completing the Windows migration.
</li>
<li style="text-align:left; margin-top:0px; margin-bottom:0px; padding-top:0px; padding-bottom:0px">
In Windows, adjust the firmware/Windows Secure Boot certificates as needed (enable the third-party CAs in the firmware setup, or apply the Windows Secure Boot certificate updates as described above), then run VeraCrypt Setup in Repair/Reinstall mode.
In Windows, adjust the firmware/Windows Secure Boot policy as needed (enable the third-party CAs in firmware setup, restore a valid dbx if a custom-key workflow removed it, or apply the Windows Secure Boot certificate updates as described above), then run VeraCrypt Setup in Repair/Reinstall mode. Repair now checks Windows' serviced <code>EFI_EX</code>/<code>EFI</code> copies and can install a compatible current Windows Boot Manager even while the standard ESP path contains VeraCrypt.
</li>
<li style="text-align:left; margin-top:0px; margin-bottom:0px; padding-top:0px; padding-bottom:0px">
Re-enable Secure Boot.
Review the VeraCrypt diagnostics and embedded signer as described above, then re-enable Secure Boot and perform a controlled reboot. Do not re-enable it while VeraCrypt reports an incomplete policy assessment or incompatible loader files.
</li>
</ol>
<h2>Legacy custom-key procedure (deprecated)</h2>
<div style="text-align:left; margin-top:19px; margin-bottom:19px; padding-top:0px; padding-bottom:0px">
Older VeraCrypt versions documented a custom-key procedure (the VeraCrypt-DCS <em>SecureBoot</em> script, <code>sb_set_siglists.ps1</code>) that replaced the firmware Secure Boot databases with a custom platform key and the 2011-era Microsoft certificates. This procedure is <strong>deprecated and must not be used</strong> on systems using the 2023 certificate chain: it removes trust for the 2023-signed Windows Boot Manager and breaks the Windows boot process after VeraCrypt pre-boot authentication. Systems where it was applied should restore the manufacturer Secure Boot keys, then follow the normal procedure described on this page.
Older VeraCrypt versions documented a custom-key procedure (the VeraCrypt-DCS <em>SecureBoot</em> script, <code>sb_set_siglists.ps1</code>) that replaced PK, KEK, db and dbx with a custom platform key, 2011-era Microsoft certificates and an obsolete bundled dbx. This procedure is <strong>deprecated and must not be used</strong> on systems using the 2023 certificate chain: it removes trust for the 2023-signed Windows Boot Manager, discards current revocations and can break the Windows handoff after VeraCrypt pre-boot authentication. Systems where it was applied should restore the manufacturer Secure Boot keys and current dbx, then follow the normal procedure described on this page.
</div>
<div style="text-align:left; margin-top:19px; margin-bottom:19px; padding-top:0px; padding-bottom:0px">
+1 -1
View File
@@ -73,7 +73,7 @@ Thus, when setting or entering your password, it's crucial to type it manually u
<p>Note: By default, Windows 7 and later boot from a special small partition. The partition contains files that are required to boot the system. Windows allows only applications that have administrator privileges to write to the partition (when the system is
running). In EFI boot mode, which is the default on modern PCs, VeraCrypt can not encrypt this partition since it must remain unencrypted so that the BIOS can load the EFI bootloader from it. This in turn implies that in EFI boot mode, VeraCrypt offers only to encrypt the system partition where Windows is installed (the user can later manually encrypt other data partitions using VeraCrypt).
In MBR legacy boot mode, VeraCrypt encrypts the partition only if you choose to encrypt the whole system drive (as opposed to choosing to encrypt only the partition where Windows is installed).</p>
<p>In EFI boot mode with Secure Boot enabled, VeraCrypt selects a Microsoft UEFI CA-signed bootloader set trusted by the active firmware Secure Boot db during install, repair, upgrade, or Windows PostOOBE repair. The 2023 VeraCrypt loader set requires both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023, while the 2011 loader set requires Microsoft Corporation UEFI CA 2011. If the active db trusts neither supported set, VeraCrypt aborts instead of installing a loader that firmware will reject. If you manually change firmware Secure Boot db entries, run VeraCrypt repair or reinstall to refresh the installed bootloader set. For details, including the Microsoft 2023 certificate transition and recovery procedures, see <a href="EFISecureBoot.html" style="text-align:left; color:#0080c0; text-decoration:none">EFI Secure Boot</a>.</p>
<p>In EFI boot mode with Secure Boot enabled, VeraCrypt selects a Microsoft UEFI CA-signed bootloader set allowed by the active firmware Secure Boot policy during install, repair, upgrade, or Windows PostOOBE repair: every required CA must be present in the allowed database (db) and absent from the forbidden database (dbx). The 2023 VeraCrypt loader set requires both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023, while the 2011 loader set requires Microsoft Corporation UEFI CA 2011. If the active db/dbx policy permits neither supported set, VeraCrypt aborts instead of installing a loader that firmware will reject. If you manually change firmware Secure Boot db or dbx entries, run VeraCrypt repair or reinstall to refresh the installed bootloader set. For details, including the Microsoft 2023 certificate transition and recovery procedures, see <a href="EFISecureBoot.html" style="text-align:left; color:#0080c0; text-decoration:none">EFI Secure Boot</a>.</p>
<p>&nbsp;</p>
<p><a href="Hidden%20Operating%20System.html" style="text-align:left; color:#0080c0; text-decoration:none; font-weight:bold">Next Section &gt;&gt;</a></p>
</div>
+25 -13
View File
@@ -53,7 +53,7 @@
</li>
</ul>
<div style="text-align:left; margin-top:19px; margin-bottom:19px; padding-top:0px; padding-bottom:0px">
При установке, обновлении, восстановлении/переустановке и запуске шифрования системы VeraCrypt считывает базу данных подписей прошивки (db) и выбирает набор загрузчиков, чьим подписывающим центрам сертификации доверяет прошивка. Если присутствует пара центров сертификации 2023 года, предпочтение отдаётся набору 2023 года; в противном случае используется набор 2011 года, если прошивка доверяет <em>Microsoft Corporation UEFI CA 2011</em>. Если Secure Boot включён и прошивка не доверяет ни одному набору, VeraCrypt отказывается устанавливать свой загрузчик и выводит ошибку, вместо того чтобы установить загрузчик, который прошивка отклонит при следующей перезагрузке.
При установке, обновлении, восстановлении/переустановке и запуске шифрования системы VeraCrypt считывает db и dbx прошивки и выбирает набор загрузчиков, известные подписывающие CA которого присутствуют в db и не перечислены в dbx. Необязательная переменная dbx может отсутствовать (особенно при пользовательских ключах); это считается пустой базой запретов, тогда как реальная ошибка чтения или разбора остаётся ошибкой при включённом Secure Boot. Если доступна пара CA 2023 года, предпочтение отдаётся набору 2023 года; иначе используется набор 2011 года при наличии <em>Microsoft Corporation UEFI CA 2011</em>.
</div>
<div style="text-align:left; margin-top:19px; margin-bottom:19px; padding-top:0px; padding-bottom:0px">
Изменение конфигурации Secure Boot в прошивке (например, включение дополнительных сертификатов в настройках BIOS) само по себе не перезаписывает файлы, уже установленные в системном разделе EFI. После изменения базы данных Secure Boot в прошивке запустите установщик VeraCrypt в режиме <em>Восстановить/переустановить</em> или позвольте службе VeraCrypt System Favorites автоматически обновить загрузчик (она повторно оценивает выбор при запуске Windows, входе в сеанс или разблокировке, выходе из сна и завершении работы).
@@ -68,6 +68,11 @@ HKEY_LOCAL_MACHINE\SOFTWARE\VeraCrypt\Diagnostics\EfiBootLoader
EfiBootLoaderResourceSet REG_DWORD 2011 (0x7db) или 2023 (0x7e7)
EfiBootLoaderSelectionReason REG_SZ понятная человеку причина выбора
EfiBootLoaderFirmwareDbLastError REG_DWORD последняя ошибка чтения/разбора db прошивки (0 = нет)
EfiBootLoaderFirmwareDbxLastError REG_DWORD последняя ошибка чтения/разбора dbx (0 = нет)
FirmwareDbxPresent REG_DWORD наличие dbx (0 допустим: переменная отсутствует)
EfiBootLoaderInstalledResourceSet REG_DWORD набор, определённый по фактическим файлам ESP
VeraCryptLoaderFilesValid REG_DWORD файлы DCS совпадают со встроенным набором
WindowsLoaderSigner REG_DWORD встроенная подпись: 0, 2011 или 2023
EfiBootLoaderSelectionTimeUtc REG_SZ время последнего выбора
</pre>
<div style="text-align:left; margin-top:19px; margin-bottom:19px; padding-top:0px; padding-bottom:0px">
@@ -83,9 +88,13 @@ $t = [Text.Encoding]::ASCII.GetString((Get-SecureBootUEFI db).Bytes)
'Microsoft UEFI CA 2023',
'Microsoft Option ROM UEFI CA 2023' |
ForEach-Object { "$_ : $($t -match [regex]::Escape($_))" }
# После подключения ESP как S: проверяйте встроенную подпись, а не подпись каталога.
Get-PfxCertificate -FilePath S:\EFI\Microsoft\Boot\bootmgfw_ms.vc |
Select-Object Subject,Issuer,Thumbprint
</pre>
<div style="text-align:left; margin-top:19px; margin-bottom:19px; padding-top:0px; padding-bottom:0px">
Кроме того, служба VeraCrypt System Favorites записывает предупреждение в журнал приложений Windows (источник <em>VeraCryptSystemFavorites</em>), когда обнаруживает, что активная db Secure Boot больше не доверяет одному из компонентов установленной цепочки загрузки.
Кроме того, служба VeraCrypt System Favorites предупреждает о несовпадении фактических файлов DCS со встроенным набором, отсутствующей или нераспознанной встроенной подписи Windows Boot Manager, известных CA, отсутствующих в db или перечисленных в dbx, и необходимости миграции копии PCA 2011. Это проверка совместимости известных CA, а не доказательство полного доверия: dbx может также отзывать хэши образов, TBS-хэши сертификатов и версии безопасности.
</div>
<h2>Переход на сертификаты Microsoft 2023 года</h2>
@@ -97,10 +106,10 @@ $t = [Text.Encoding]::ASCII.GetString((Get-SecureBootUEFI db).Bytes)
</div>
<ul style="text-align:left; margin-top:18px; margin-bottom:19px; padding-top:0px; padding-bottom:0px">
<li style="text-align:left; margin-top:0px; margin-bottom:0px; padding-top:0px; padding-bottom:0px">
<strong>Истечение срока действия сертификатов не мешает загрузке уже установленных загрузчиков.</strong> UEFI-прошивка не проверяет сроки действия сертификатов во время проверки Secure Boot, поэтому загрузчики, подписанные с помощью CA 2011 года, продолжают загружаться после дат истечения срока действия практически на всех реализациях прошивки. Истечение срока действия означает, что <em>новые</em> двоичные файлы больше нельзя подписывать с помощью CA 2011 года, а системы, которые так и не получат сертификаты 2023 года, перестанут получать обновления безопасности цепочки загрузки.
<strong>Истечение срока действия сертификатов обычно не мешает загрузке уже установленных загрузчиков.</strong> Проверка образа UEFI Secure Boot обычно не применяет срок действия подписывающего сертификата, поэтому сам факт истечения CA 2011 не вызывает отказ загрузчика. Однако новые двоичные файлы больше нельзя подписывать в этой экосистеме, а системы без сертификатов 2023 года не смогут получать обновления цепочки загрузки, подписанные заменяющими CA.
</li>
<li style="text-align:left; margin-top:0px; margin-bottom:0px; padding-top:0px; padding-bottom:0px">
<strong>Будущий отзыв CA 2011 года не позволит загружать подписанные ими загрузчики.</strong> Microsoft объявила, что на более позднем этапе перехода (пока не запланированном) CA 2011 года могут быть отозваны через базу данных запрещённых подписей Secure Boot (dbx) на системах, завершивших переход. Поэтому рекомендуется заранее перейти на набор загрузчиков 2023 года.
<strong>Истечение срока действия и отзыв — разные события.</strong> Microsoft предоставляет отдельную, выполняемую намеренно меру защиты, которая добавляет <em>Microsoft Windows Production PCA 2011</em> в базу запрещённых подписей Secure Boot (dbx). После её применения все Windows Boot Manager, подписанные этим CA, отклоняются. Этот отзыв Windows PCA не является частью миграции сертификатов и Boot Manager с помощью <code>0x5944</code>. По состоянию на июль 2026 года <a href="https://techcommunity.microsoft.com/blog/linuxandopensourceblog/what-it-teams-need-to-know-about-linux-secure-boot-certificates-expiring-in-2026/4530725">Microsoft сообщает, что не планирует отзывать Microsoft Corporation UEFI CA 2011</a> — сторонний CA, используемый набором загрузчиков VeraCrypt 2011 года. Тем не менее перед применением отзыва Windows PCA 2011 рекомендуется перевести на CA 2023 года как часть VeraCrypt, так и часть Windows в цепочке загрузки.
</li>
</ul>
@@ -114,10 +123,10 @@ $t = [Text.Encoding]::ASCII.GetString((Get-SecureBootUEFI db).Bytes)
<h2>Обновление существующей системы до сертификатов 2023 года</h2>
<div style="text-align:left; margin-top:19px; margin-bottom:19px; padding-top:0px; padding-bottom:0px">
Windows распространяет сертификаты 2023 года поэтапно, на основе телеметрии. Устройства обновляются автоматически только после того, как Microsoft получает достаточную уверенность в конкретном сочетании оборудования и прошивки. Поскольку компьютер с системным шифрованием VeraCrypt загружается через нестандартную цепочку загрузки (загрузчик VeraCrypt занимает место Windows Boot Manager), такие компьютеры обычно не классифицируются для автоматического обновления, и развёртывание не запускается само. Приложение "Безопасность Windows" может сообщать, что <em>&quot;not yet enough data to classify your device&quot;</em>. По той же причине участия в управляемом Microsoft развёртывании (значение реестра <code>MicrosoftUpdateManagedOptIn</code>) на таких компьютерах может оказаться недостаточно.
Windows распространяет сертификаты 2023 года поэтапно, на основе телеметрии. Устройства обновляются автоматически только после того, как Microsoft получает достаточную уверенность в конкретном сочетании оборудования и прошивки. Компьютер с системным шифрованием VeraCrypt использует нестандартную цепочку загрузки, поскольку загрузчик VeraCrypt занимает стандартное расположение Windows Boot Manager; это может влиять на проверки обслуживания, однако Microsoft не указывает VeraCrypt как безусловное исключение из развёртывания. Сообщение <em>&quot;not yet enough data to classify your device&quot;</em> описывает текущее состояние развёртывания, а не доказывает, что его причиной является VeraCrypt. Значение <code>MicrosoftUpdateManagedOptIn</code> отдельно включает асинхронное управляемое Microsoft развёртывание, требует разрешённой передачи диагностических данных и не гарантирует немедленное обновление. Не сочетайте этот способ с ручным применением <code>AvailableUpdates</code>.
</div>
<div style="text-align:left; margin-top:19px; margin-bottom:19px; padding-top:0px; padding-bottom:0px">
Microsoft документирует значение реестра для явного запуска обновления (см. Microsoft KB5068202, <em>&quot;Registry key updates for Secure Boot&quot;</em>). Из командной строки с повышенными правами:
Для контролируемого ручного развёртывания Microsoft документирует <code>0x5944</code> как явный запрос миграции CA 2023, KEK и Windows Boot Manager (см. <a href="https://support.microsoft.com/en-us/topic/registry-key-updates-for-secure-boot-windows-devices-with-it-managed-updates-a7be69c9-4634-42e1-9ca1-df06f43f360d">руководство Microsoft по ключам реестра Secure Boot</a>). Это значение <strong>не</strong> применяет отзыв Windows PCA 2011 через dbx, и VeraCrypt никогда не задаёт его автоматически. Используйте его на полностью обновлённой Windows только после изучения мер предосторожности ниже:
</div>
<pre>
reg add HKLM\SYSTEM\CurrentControlSet\Control\Secureboot /v AvailableUpdates /t REG_DWORD /d 0x5944 /f
@@ -126,7 +135,7 @@ rem при необходимости запустите задачу обслу
schtasks /Run /TN "\Microsoft\Windows\PI\Secure-Boot-Update"
</pre>
<div style="text-align:left; margin-top:19px; margin-bottom:19px; padding-top:0px; padding-bottom:0px">
Ход выполнения можно отслеживать в <code>HKLM\SYSTEM\CurrentControlSet\Control\Secureboot\Servicing</code> (значения <code>UEFICA2023Status</code> и <code>UEFICA2023Error</code>) и по событиям обслуживания Secure Boot в журнале событий Windows. Обновление db добавляет <em>Windows UEFI CA 2023</em>, а на системах, которые уже доверяют <em>Microsoft Corporation UEFI CA 2011</em> (что верно для каждой системы VeraCrypt с Secure Boot), также добавляет <em>Microsoft UEFI CA 2023</em> и <em>Microsoft Option ROM UEFI CA 2023</em>.
Ход выполнения можно отслеживать в <code>HKLM\SYSTEM\CurrentControlSet\Control\SecureBoot</code> и его подразделе <code>Servicing</code>, а также по событиям обслуживания Secure Boot. Ожидаемая последовательность <code>AvailableUpdates</code>: <code>0x5944</code>, затем <code>0x4100</code> и после требуемых запусков задачи и перезагрузок — конечный модификатор <code>0x4000</code>. Дополнительно проверьте <code>UEFICA2023Status=Updated</code> и фактические файлы загрузки: одно значение <code>0x4000</code> не доказывает, что файл VeraCrypt <code>bootmgfw_ms.vc</code> обновлён. Обновление db добавляет <em>Windows UEFI CA 2023</em>. На системах, уже доверяющих <em>Microsoft Corporation UEFI CA 2011</em>, оно условно добавляет <em>Microsoft UEFI CA 2023</em> и <em>Microsoft Option ROM UEFI CA 2023</em>; этот устаревший сторонний CA присутствует не на каждой системе, где можно установить VeraCrypt.
</div>
<div style="text-align:left; margin-top:19px; margin-bottom:19px; padding-top:0px; padding-bottom:0px">
Перед запуском обновления на машине с системным шифрованием VeraCrypt примите следующие меры предосторожности:
@@ -139,7 +148,7 @@ schtasks /Run /TN "\Microsoft\Windows\PI\Secure-Boot-Update"
<strong>Сначала создайте или обновите Диск восстановления VeraCrypt</strong> и убедитесь, что он загружается.
</li>
<li style="text-align:left; margin-top:0px; margin-bottom:0px; padding-top:0px; padding-bottom:0px">
Не отключайте службу <em>VeraCrypt System Favorites</em> или её функцию обновления загрузчика. Когда задача обслуживания Windows устанавливает Windows Boot Manager, подписанный сертификатом 2023 года, в стандартное расположение, именно эта служба сохраняет цепочку загрузки VeraCrypt: она сохраняет новый загрузчик как <code>bootmgfw_ms.vc</code> (копию, на которую VeraCrypt передаёт управление после предзагрузочной аутентификации) и восстанавливает загрузчик VeraCrypt.
Не отключайте службу <em>VeraCrypt System Favorites</em> или её функцию обновления загрузчика. Если Windows заменяет Boot Manager в стандартном расположении ESP, служба сохраняет его как <code>bootmgfw_ms.vc</code> и восстанавливает загрузчик VeraCrypt. Если стандартный путь не изменяется, текущая VeraCrypt также проверяет обслуживаемые Windows копии в <code>%SystemRoot%\Boot\EFI_EX</code> и <code>%SystemRoot%\Boot\EFI</code>, проверяет встроенную подпись и атомарно обновляет <code>bootmgfw_ms.vc</code> лучшей копией, совместимой с известной политикой CA.
</li>
<li style="text-align:left; margin-top:0px; margin-bottom:0px; padding-top:0px; padding-bottom:0px">
<strong>Пользователям скрытой операционной системы не следует запускать обновление из скрытой ОС.</strong> Автоматическое сохранение цепочки загрузки отключено, когда работает скрытая ОС.
@@ -148,12 +157,15 @@ schtasks /Run /TN "\Microsoft\Windows\PI\Secure-Boot-Update"
Избегайте принудительного отключения питания между моментом, когда Windows заменяет загрузчик, и следующей обычной перезагрузкой или выключением. На большинстве систем загрузочная запись VeraCrypt сохраняет возможность загрузки компьютера в этот промежуток, но прошивка, игнорирующая порядок загрузки, может загрузить обычный Windows Boot Manager, который не сможет запустить зашифрованную Windows (восстанавливается с помощью Диска восстановления).
</li>
<li style="text-align:left; margin-top:0px; margin-bottom:0px; padding-top:0px; padding-bottom:0px">
Ожидайте, что Windows будет продолжать сообщать о не полностью завершённом обслуживании сертификатов Secure Boot даже после того, как всё работает. Windows проверяет, является ли файл в стандартном расположении загрузчика Microsoft Boot Manager, подписанным сертификатом 2023 года; в системе VeraCrypt это расположение по замыслу занимает загрузчик VeraCrypt. Это состояние носит косметический характер и не влияет на безопасность или работу системы.
Windows может продолжать сообщать о незавершённом переходе, поскольку стандартное расположение Windows Boot Manager по замыслу занимает загрузчик VeraCrypt. Считайте это возможным ложным отрицательным результатом обслуживания только после появления требуемых CA 2023 в db, определения фактических файлов как <code>EfiBootLoaderInstalledResourceSet=2023</code>, подтверждения <em>встроенного</em> издателя <code>bootmgfw_ms.vc</code> как <em>Windows UEFI CA 2023</em> и отсутствия неустранённых ошибок обслуживания.
</li>
</ul>
<div style="text-align:left; margin-top:19px; margin-bottom:19px; padding-top:0px; padding-bottom:0px">
После применения обновления db VeraCrypt автоматически переключится на набор загрузчиков 2023 года при следующем обновлении загрузчика (<em>Восстановить/переустановить</em>, обновление версии или одна из автоматических точек обновления службы System Favorites). Результат можно проверить в описанном выше ключе реестра диагностики и заново создать Диск восстановления, когда появится соответствующее приглашение.
</div>
<div style="text-align:left; margin-top:19px; margin-bottom:19px; padding-top:0px; padding-bottom:0px">
Отзыв Windows PCA 2011 через dbx — отдельная последующая операция, описанная в <a href="https://support.microsoft.com/en-us/topic/how-to-manage-the-windows-boot-manager-revocations-for-secure-boot-changes-associated-with-cve-2023-24932-41a975df-beb2-40c1-99a3-b3ff139f832d">Microsoft KB5025885</a>. Не запрашивайте бит <code>0x80</code> (или объединённое значение <code>0x280</code>, которое также запрашивает обновление SVN), пока не подтверждено, что <code>bootmgfw_ms.vc</code> подписан <em>Windows UEFI CA 2023</em>, носители восстановления актуальны и контрольная перезагрузка с включённым Secure Boot прошла успешно. VeraCrypt никогда не включает этот отзыв автоматически.
</div>
<h2>Восстановление после сбоя загрузки Secure Boot</h2>
<div style="text-align:left; margin-top:19px; margin-bottom:19px; padding-top:0px; padding-bottom:0px">
@@ -172,19 +184,19 @@ schtasks /Run /TN "\Microsoft\Windows\PI\Secure-Boot-Update"
</div>
<ol style="text-align:left; margin-top:18px; margin-bottom:19px; padding-top:0px; padding-bottom:0px">
<li style="text-align:left; margin-top:0px; margin-bottom:0px; padding-top:0px; padding-bottom:0px">
Временно отключите Secure Boot в настройках прошивки и запустите Windows обычным образом (предзагрузочная аутентификация VeraCrypt работает и с отключённым Secure Boot) или загрузите Диск восстановления VeraCrypt и используйте <em>&quot;Restore VeraCrypt loader binaries to system disk&quot;</em>.
Временно отключите Secure Boot в настройках прошивки и запустите Windows обычным образом (предзагрузочная аутентификация VeraCrypt работает и с отключённым Secure Boot). Диск восстановления VeraCrypt может восстановить отсутствующие или повреждённые компоненты загрузчика VeraCrypt, но не может создать актуальный Windows Boot Manager или сделать подписанный PCA 2011 файл <code>bootmgfw_ms.vc</code> допустимым после добавления этого CA в dbx; он не заменяет завершение миграции Windows.
</li>
<li style="text-align:left; margin-top:0px; margin-bottom:0px; padding-top:0px; padding-bottom:0px">
В Windows настройте сертификаты Secure Boot в прошивке/Windows по необходимости (включите сторонние центры сертификации в настройках прошивки или примените обновления сертификатов Windows Secure Boot, как описано выше), затем запустите установщик VeraCrypt в режиме <em>Восстановить/переустановить</em>.
В Windows исправьте политику Secure Boot (включите сторонние CA, восстановите актуальную dbx после пользовательской процедуры либо примените обновления Windows), затем запустите VeraCrypt в режиме <em>Восстановить/переустановить</em>. Восстановление проверит обслуживаемые копии <code>EFI_EX</code>/<code>EFI</code> и сможет установить совместимый актуальный Windows Boot Manager.
</li>
<li style="text-align:left; margin-top:0px; margin-bottom:0px; padding-top:0px; padding-bottom:0px">
Снова включите Secure Boot.
Проверьте диагностику VeraCrypt и встроенную подпись, затем включите Secure Boot и выполните одну контролируемую перезагрузку. Не включайте его при неполной оценке политики или несовместимых файлах загрузчика.
</li>
</ol>
<h2>Устаревшая процедура с пользовательскими ключами (не рекомендуется)</h2>
<div style="text-align:left; margin-top:19px; margin-bottom:19px; padding-top:0px; padding-bottom:0px">
В более старых версиях VeraCrypt была задокументирована процедура с пользовательскими ключами (скрипт VeraCrypt-DCS <em>SecureBoot</em>, <code>sb_set_siglists.ps1</code>), которая заменяла базы Secure Boot прошивки пользовательским ключом платформы и сертификатами Microsoft эпохи 2011 года. Эта процедура <strong>устарела и не должна использоваться</strong> на системах с цепочкой сертификатов 2023 года: она удаляет доверие к Windows Boot Manager, подписанному сертификатом 2023 года, и нарушает загрузку Windows после предзагрузочной аутентификации VeraCrypt. Системы, где она применялась, должны восстановить заводские ключи Secure Boot производителя, а затем следовать обычной процедуре, описанной на этой странице.
В более старых версиях VeraCrypt была задокументирована процедура с пользовательскими ключами (скрипт VeraCrypt-DCS <em>SecureBoot</em>, <code>sb_set_siglists.ps1</code>), которая заменяла PK, KEK, db и dbx пользовательскими ключами, сертификатами Microsoft 2011 года и устаревшей копией dbx 2018 года. Эта процедура <strong>устарела и не должна использоваться</strong> с цепочкой 2023 года: она удаляет доверие к новому Windows Boot Manager, отбрасывает современные отзывы и может нарушить передачу управления Windows. Восстановите заводские ключи производителя и актуальную dbx.
</div>
<div style="text-align:left; margin-top:19px; margin-bottom:19px; padding-top:0px; padding-bottom:0px">
+1 -1
View File
@@ -96,7 +96,7 @@ XTS</a> (см. раздел <a href="Modes%20of%20Operation.html" style="text-al
(позже пользователь может вручную зашифровать другие разделы с данными с помощью VeraCrypt).
В устаревшем режиме загрузки MBR программа выполняет шифрование этого раздела, только если вы выбрали
шифрование всего системного диска (а не шифрование только раздела, в котором установлена Windows).</p>
<p>В режиме загрузки EFI с включённым Secure Boot при установке, восстановлении/переустановке, обновлении или восстановлении после Windows PostOOBE VeraCrypt выбирает набор загрузчиков, подписанный Microsoft UEFI CA, которому доверяет активная база данных Secure Boot прошивки (db). Для набора загрузчиков VeraCrypt 2023 года требуются Microsoft UEFI CA 2023 и Microsoft Option ROM UEFI CA 2023, а для набора 2011 года — Microsoft Corporation UEFI CA 2011. Если активная db не доверяет ни одному поддерживаемому набору, VeraCrypt прерывает операцию и не устанавливает загрузчик, который прошивка отклонит при следующей перезагрузке. Если вы вручную изменили записи db Secure Boot в прошивке, запустите восстановление/переустановку VeraCrypt, чтобы обновить установленный набор загрузчиков. Подробности, включая переход на сертификаты Microsoft 2023 года и процедуры восстановления, см. в разделе <a href="EFISecureBoot.html" style="text-align:left; color:#0080c0; text-decoration:none">EFI Secure Boot</a>.</p>
<p>В режиме загрузки EFI с включённым Secure Boot при установке, восстановлении/переустановке, обновлении или восстановлении после Windows PostOOBE VeraCrypt выбирает набор загрузчиков, подписанный Microsoft UEFI CA и разрешённый активной политикой Secure Boot прошивки: каждый требуемый CA должен присутствовать в базе разрешённых подписей (db) и отсутствовать в базе запрещённых подписей (dbx). Для набора загрузчиков VeraCrypt 2023 года требуются Microsoft UEFI CA 2023 и Microsoft Option ROM UEFI CA 2023, а для набора 2011 года — Microsoft Corporation UEFI CA 2011. Если активная политика db/dbx не разрешает ни один поддерживаемый набор, VeraCrypt прерывает операцию и не устанавливает загрузчик, который прошивка отклонит при следующей перезагрузке. Если вы вручную изменили записи db или dbx Secure Boot в прошивке, запустите восстановление/переустановку VeraCrypt, чтобы обновить установленный набор загрузчиков. Подробности, включая переход на сертификаты Microsoft 2023 года и процедуры восстановления, см. в разделе <a href="EFISecureBoot.html" style="text-align:left; color:#0080c0; text-decoration:none">EFI Secure Boot</a>.</p>
<p>&nbsp;</p>
<p><a href="Hidden%20Operating%20System.html" style="text-align:left; color:#0080c0; text-decoration:none; font-weight:bold">Следующий раздел &gt;&gt;</a></p>
</div>
+25 -13
View File
@@ -53,7 +53,7 @@ VeraCrypt系统加密兼容EFI Secure Boot(安全启动):VeraCrypt EFI引
</li>
</ul>
<div style="text-align:left; margin-top:19px; margin-bottom:19px; padding-top:0px; padding-bottom:0px">
在安装、升级、修复/重新安装以及开始系统加密时,VeraCrypt会读取固件db,并选择签名CA受固件信任的引导加载程序套件。如果存在2023 CA对则优先使用2023套件否则<em>Microsoft Corporation UEFI CA 2011</em> 受信任时使用2011套件。如果启用安全启动且固件不信任任何套件,VeraCrypt会拒绝安装其引导加载程序并显示错误,而不会安装一个在下次重启时会被固件拒绝的加载程序。
在安装、升级、修复/重新安装以及开始系统加密时,VeraCrypt会读取固件db和dbx,并选择其已知签名CA存在于db且未列入dbx的套件。可选的dbx变量可以合法地不存在(自定义密钥系统尤其如此);此状态按空禁止数据库处理,而启用安全启动时真正的读取或解析错误仍会导致拒绝安装。若2023 CA对可用则优先选择2023套件否则在存<em>Microsoft Corporation UEFI CA 2011</em> 时使用2011套件。
</div>
<div style="text-align:left; margin-top:19px; margin-bottom:19px; padding-top:0px; padding-bottom:0px">
更改固件安全启动配置(例如在BIOS设置中启用其他证书)本身不会重写已经安装到EFI系统分区上的文件。更改固件安全启动数据库后,请以 <em>修复/重新安装</em> 模式运行VeraCrypt安装程序,或让VeraCrypt System Favorites服务自动刷新引导加载程序(它会在Windows启动、会话登录或解锁、从睡眠恢复以及关机时重新评估选择)。
@@ -68,6 +68,11 @@ HKEY_LOCAL_MACHINE\SOFTWARE\VeraCrypt\Diagnostics\EfiBootLoader
EfiBootLoaderResourceSet REG_DWORD 2011 (0x7db) 或 2023 (0x7e7)
EfiBootLoaderSelectionReason REG_SZ 可读的选择原因
EfiBootLoaderFirmwareDbLastError REG_DWORD 上次读取/解析固件db的错误(0 = 无)
EfiBootLoaderFirmwareDbxLastError REG_DWORD 上次读取/解析dbx的错误(0 = 无)
FirmwareDbxPresent REG_DWORD dbx是否存在(0可为合法缺失)
EfiBootLoaderInstalledResourceSet REG_DWORD 由ESP实际文件识别的套件
VeraCryptLoaderFilesValid REG_DWORD DCS文件与一个内嵌套件完全匹配
WindowsLoaderSigner REG_DWORD 内嵌签名:0、2011或2023
EfiBootLoaderSelectionTimeUtc REG_SZ 上次选择的时间
</pre>
<div style="text-align:left; margin-top:19px; margin-bottom:19px; padding-top:0px; padding-bottom:0px">
@@ -83,9 +88,13 @@ $t = [Text.Encoding]::ASCII.GetString((Get-SecureBootUEFI db).Bytes)
'Microsoft UEFI CA 2023',
'Microsoft Option ROM UEFI CA 2023' |
ForEach-Object { "$_ : $($t -match [regex]::Escape($_))" }
# 将ESP挂载为S:后检查内嵌签名;不要依赖可能返回目录签名的命令。
Get-PfxCertificate -FilePath S:\EFI\Microsoft\Boot\bootmgfw_ms.vc |
Select-Object Subject,Issuer,Thumbprint
</pre>
<div style="text-align:left; margin-top:19px; margin-bottom:19px; padding-top:0px; padding-bottom:0px">
此外,VeraCrypt System Favorites服务检测到当前安全启动db不再信任已安装启动链中的某个组件时,会向Windows应用程序事件日志(源 <em>VeraCryptSystemFavorites</em>)写入警告
此外,VeraCrypt System Favorites服务会针对实际DCS文件与内嵌套件不匹配、Windows启动管理器缺失或其内嵌签名无法识别、已知所需CA不在db或被列入dbx,以及PCA 2011副本需要迁移等情况写入警告。这只是“已知CA兼容性”评估,并非固件一定接受映像的证明;dbx还可撤销映像哈希、证书TBS哈希和安全版本
</div>
<h2>Microsoft 2023证书过渡</h2>
@@ -97,10 +106,10 @@ VeraCrypt用户需要注意两点:
</div>
<ul style="text-align:left; margin-top:18px; margin-bottom:19px; padding-top:0px; padding-bottom:0px">
<li style="text-align:left; margin-top:0px; margin-bottom:0px; padding-top:0px; padding-bottom:0px">
<strong>证书到期不会阻止已安装的引导加载程序启动。</strong> UEFI固件在安全启动验证期间不会评估证书有效期,因此通过2011 CA签名的引导加载程序在到期日期之后仍会在几乎所有固件实现上继续加载。到期意味着 <em>新的</em> 二进制文件不能再通过2011 CA签名,并且从未收到2023证书的系统将停止接收启动链安全更新。
<strong>证书到期通常不会阻止已安装的引导加载程序启动。</strong> UEFI安全启动映像验证通常不强制执行签名证书有效期,因此仅因2011 CA到期并不会拒绝加载程序。但新的二进制文件无法继续通过该签名体系签发,未获得2023证书的系统也无法接收由替代CA签名的启动链更新。
</li>
<li style="text-align:left; margin-top:0px; margin-bottom:0px; padding-top:0px; padding-bottom:0px">
<strong>未来撤销2011 CA会阻止通过它们签名的引导加载程序启动。</strong> Microsoft已宣布,在过渡的后续阶段(尚未排期),可能会通过安全启动禁止签名数据库(dbx)在已完成过渡的系统上撤销2011 CA。因此建议在该阶段之前迁移到2023引导加载程序套件
<strong>证书到期与撤销是两回事。</strong> Microsoft提供了一项需明确执行的独立缓解措施,将 <em>Microsoft Windows Production PCA 2011</em> 添加到安全启动禁止签名数据库(dbx);应用后,所有通过该CA签名的Windows启动管理器都会被拒绝。此Windows PCA撤销不属于下文由 <code>0x5944</code> 执行的证书/启动管理器迁移。截至2026年7月,<a href="https://techcommunity.microsoft.com/blog/linuxandopensourceblog/what-it-teams-need-to-know-about-linux-secure-boot-certificates-expiring-in-2026/4530725">Microsoft表示目前没有撤销Microsoft Corporation UEFI CA 2011的计划</a>;该第三方CA用于VeraCrypt 2011引导加载程序套件。尽管如此,在应用任何Windows PCA 2011撤销之前,仍建议将启动链中的VeraCrypt和Windows部分都迁移到相应的2023 CA
</li>
</ul>
@@ -114,10 +123,10 @@ VeraCrypt用户需要注意两点:
<h2>将现有系统更新到2023证书</h2>
<div style="text-align:left; margin-top:19px; margin-bottom:19px; padding-top:0px; padding-bottom:0px">
Windows通过基于遥测的分阶段部署流程分发2023证书。只有在Microsoft对设备硬件/固件组合有足够信心后,设备才会自动更新。由于VeraCrypt系统加密计算机通过非标准启动链启动(VeraCrypt引导加载程序占用Windows启动管理器的位置),此类计算机通常不会被归类为自动更新对象,因此部署流程不会自行触发。Windows安全中心可能报告 <em>&quot;not yet enough data to classify your device&quot;</em>。同样,选择加入Microsoft管理的部署流程(<code>MicrosoftUpdateManagedOptIn</code> 注册表值)在这些计算机上可能仍不足以触发更新
Windows通过基于遥测的分阶段部署流程分发2023证书。只有在Microsoft对设备硬件/固件组合有足够信心后,设备才会自动更新。VeraCrypt系统加密计算机采用非标准启动链,因为VeraCrypt引导加载程序占用Windows启动管理器的标准位置;这可能影响维护检查,但Microsoft并未将VeraCrypt列为必然排除在部署之外的条件。Windows安全中心显示 <em>&quot;not yet enough data to classify your device&quot;</em> 只表示当前部署状态,不能证明原因是VeraCrypt。<code>MicrosoftUpdateManagedOptIn</code> 是加入Microsoft异步托管部署的另一种方式,需要允许发送相应的诊断数据,也不保证立即部署。不要把该方式与手动设置 <code>AvailableUpdates</code> 混用
</div>
<div style="text-align:left; margin-top:19px; margin-bottom:19px; padding-top:0px; padding-bottom:0px">
Microsoft文档提供了一个用于显式触发更新的注册表值(参见Microsoft KB5068202<em>&quot;Registry key updates for Secure Boot&quot;</em>)。在以管理员身份打开的命令提示符中运行
对于受控的手动部署,Microsoft将 <code>0x5944</code> 记录为显式请求2023 CA、KEK和Windows启动管理器迁移的值(参见<a href="https://support.microsoft.com/en-us/topic/registry-key-updates-for-secure-boot-windows-devices-with-it-managed-updates-a7be69c9-4634-42e1-9ca1-df06f43f360d">Microsoft安全启动注册表指导</a>)。<strong>不会</strong>应用Windows PCA 2011的dbx撤销,VeraCrypt也绝不会自动设置此值。阅读下述预防措施后,才应在完全更新的Windows上使用
</div>
<pre>
reg add HKLM\SYSTEM\CurrentControlSet\Control\Secureboot /v AvailableUpdates /t REG_DWORD /d 0x5944 /f
@@ -126,7 +135,7 @@ rem 可选:立即运行维护任务(否则它每 12 小时运行一次):
schtasks /Run /TN "\Microsoft\Windows\PI\Secure-Boot-Update"
</pre>
<div style="text-align:left; margin-top:19px; margin-bottom:19px; padding-top:0px; padding-bottom:0px">
可在 <code>HKLM\SYSTEM\CurrentControlSet\Control\Secureboot\Servicing</code> 下监视进度(值 <code>UEFICA2023Status</code> <code>UEFICA2023Error</code>),也可通过Windows事件日志中的安全启动维护事件监视。db更新会添加 <em>Windows UEFI CA 2023</em>;在已经信任 <em>Microsoft Corporation UEFI CA 2011</em> 的系统上(每台启用安全启动的VeraCrypt系统都是如此),还会添加 <em>Microsoft UEFI CA 2023</em><em>Microsoft Option ROM UEFI CA 2023</em>
可在 <code>HKLM\SYSTEM\CurrentControlSet\Control\SecureBoot</code> 及其 <code>Servicing</code> 子项下监视进度,也可查看安全启动维护事件。<code>AvailableUpdates</code> 的预期变化顺序为 <code>0x5944</code><code>0x4100</code>,在所需任务运行和重启后最终为修饰值 <code>0x4000</code>。还应确认 <code>UEFICA2023Status=Updated</code> 并检查实际启动文件;仅有 <code>0x4000</code> 不能证明VeraCrypt的 <code>bootmgfw_ms.vc</code> 已刷新。db更新会添加 <em>Windows UEFI CA 2023</em>。对于已经信任 <em>Microsoft Corporation UEFI CA 2011</em> 的系统,它会有条件地添加 <em>Microsoft UEFI CA 2023</em><em>Microsoft Option ROM UEFI CA 2023</em>;并非所有可安装VeraCrypt的系统都具有该旧版第三方CA
</div>
<div style="text-align:left; margin-top:19px; margin-bottom:19px; padding-top:0px; padding-bottom:0px">
在VeraCrypt系统加密机器上触发更新之前,请采取以下预防措施:
@@ -139,7 +148,7 @@ schtasks /Run /TN "\Microsoft\Windows\PI\Secure-Boot-Update"
<strong>首先创建或更新VeraCrypt救援盘</strong>,并验证它能够启动。
</li>
<li style="text-align:left; margin-top:0px; margin-bottom:0px; padding-top:0px; padding-bottom:0px">
不要禁用 <em>VeraCrypt System Favorites</em> 服务或其引导加载程序更新功能。Windows维护任务在标准位置安装2023证书签名的Windows启动管理器,该服务负责保留VeraCrypt启动链:它将新的启动管理器保存为 <code>bootmgfw_ms.vc</code>VeraCrypt在预启动身份验证后链式加载的副本),并恢复VeraCrypt引导加载程序
不要禁用 <em>VeraCrypt System Favorites</em> 服务或其引导加载程序更新功能。如果Windows替换标准ESP位置的启动管理器,该服务会将其保存为 <code>bootmgfw_ms.vc</code> 并恢复VeraCrypt加载程序。如果标准路径保持不变,当前VeraCrypt还会检查 <code>%SystemRoot%\Boot\EFI_EX</code><code>%SystemRoot%\Boot\EFI</code> 中Windows维护的副本,验证内嵌签名,并用已知固件CA策略允许的最佳副本原子刷新 <code>bootmgfw_ms.vc</code>
</li>
<li style="text-align:left; margin-top:0px; margin-bottom:0px; padding-top:0px; padding-bottom:0px">
<strong>隐藏操作系统用户不应从隐藏操作系统触发更新。</strong> 运行隐藏操作系统时,自动启动链保留功能被禁用。
@@ -148,12 +157,15 @@ schtasks /Run /TN "\Microsoft\Windows\PI\Secure-Boot-Update"
避免在Windows替换启动管理器到下一次正常重启或关机之间强制断电。在大多数系统上,VeraCrypt启动项会在这个时间窗口内保持计算机可启动,但忽略启动顺序的固件可能会启动普通Windows启动管理器,而它无法启动加密的Windows(可用救援盘恢复)。
</li>
<li style="text-align:left; margin-top:0px; margin-bottom:0px; padding-top:0px; padding-bottom:0px">
即使一切正常,也应预期Windows仍会报告安全启动证书维护未完全完成。Windows会检查标准启动管理器位置的文件是否为2023证书签名的Microsoft Boot Manager;在VeraCrypt系统上,该位置按设计保存VeraCrypt引导加载程序。此状态仅为显示问题,不影响系统安全性或运行
由于标准Windows启动管理器位置按设计保存VeraCrypt加载程序,Windows可能仍报告迁移未完成。只有在固件db包含所需2023 CA、<code>EfiBootLoaderInstalledResourceSet</code> 从实际文件识别出2023套件、<code>bootmgfw_ms.vc</code><em>内嵌</em>签发者为 <em>Windows UEFI CA 2023</em> 且事件日志无未解决维护错误后,才可将其视为可能的维护误报
</li>
</ul>
<div style="text-align:left; margin-top:19px; margin-bottom:19px; padding-top:0px; padding-bottom:0px">
应用db更新后,VeraCrypt会在下次刷新引导加载程序时自动切换到2023引导加载程序套件(<em>修复/重新安装</em>、升级,或System Favorites服务的某个自动刷新点)。您可以在上文所述的诊断注册表键中验证结果,并在提示时重新创建救援盘。
</div>
<div style="text-align:left; margin-top:19px; margin-bottom:19px; padding-top:0px; padding-bottom:0px">
Windows PCA 2011的dbx撤销是后续的独立操作,详见 <a href="https://support.microsoft.com/en-us/topic/how-to-manage-the-windows-boot-manager-revocations-for-secure-boot-changes-associated-with-cve-2023-24932-41a975df-beb2-40c1-99a3-b3ff139f832d">Microsoft KB5025885</a>。在确认 <code>bootmgfw_ms.vc</code><em>Windows UEFI CA 2023</em> 签名、恢复介质已更新,并且启用安全启动的受控重启成功之前,不要请求其 <code>0x80</code> 位(或还会请求SVN更新的组合值 <code>0x280</code>)。VeraCrypt绝不会自动启用此撤销。
</div>
<h2>从安全启动故障中恢复</h2>
<div style="text-align:left; margin-top:19px; margin-bottom:19px; padding-top:0px; padding-bottom:0px">
@@ -172,19 +184,19 @@ schtasks /Run /TN "\Microsoft\Windows\PI\Secure-Boot-Update"
</div>
<ol style="text-align:left; margin-top:18px; margin-bottom:19px; padding-top:0px; padding-bottom:0px">
<li style="text-align:left; margin-top:0px; margin-bottom:0px; padding-top:0px; padding-bottom:0px">
暂时在固件设置中禁用安全启动并正常启动Windows(禁用安全启动时VeraCrypt预启动身份验证仍可工作),或启动VeraCrypt救援盘并使用 <em>&quot;VeraCrypt加载程序二进制文件恢复到系统磁盘&quot;</em>
暂时在固件设置中禁用安全启动并正常启动Windows(禁用安全启动时VeraCrypt预启动身份验证仍可工作)VeraCrypt救援盘可以恢复缺失或损坏的VeraCrypt引导加载程序组件,但无法生成当前的Windows启动管理器,也无法在PCA 2011 CA被加入dbx后使由其签名的 <code>bootmgfw_ms.vc</code> 重新获得信任;它不能替代完成Windows迁移
</li>
<li style="text-align:left; margin-top:0px; margin-bottom:0px; padding-top:0px; padding-bottom:0px">
在Windows中,根据需要调整固件/Windows安全启动证书(在固件设置中启用第三方CA,或按上文所述应用Windows安全启动证书更新),然后以 <em>修复/重新安装</em> 模式运行VeraCrypt安装程序
在Windows中修复固件/Windows安全启动策略(启用第三方CA、自定义密钥流程后恢复当前dbx,或应用上述Windows更新),然后以 <em>修复/重新安装</em> 模式运行VeraCrypt。修复会检查Windows维护的 <code>EFI_EX</code>/<code>EFI</code> 副本,并可安装兼容的当前Windows启动管理器
</li>
<li style="text-align:left; margin-top:0px; margin-bottom:0px; padding-top:0px; padding-bottom:0px">
重新启用安全启动
检查VeraCrypt诊断和内嵌签名,然后重新启用安全启动并执行一次受控重启。策略评估不完整或加载程序文件不兼容时不要重新启用。
</li>
</ol>
<h2>旧版自定义密钥步骤(已弃用)</h2>
<div style="text-align:left; margin-top:19px; margin-bottom:19px; padding-top:0px; padding-bottom:0px">
较旧VeraCrypt版本记录一种自定义密钥流程(VeraCrypt-DCS <em>SecureBoot</em> 脚本<code>sb_set_siglists.ps1</code>,它用自定义平台密钥2011版Microsoft证书替换固件安全启动数据库。此流程<strong>已经弃用,在使用2023证书链系统上不得使用</strong>:它会移除对2023证书签名的Windows启动管理器的信任,并在VeraCrypt预启动身份验证后破坏Windows启动过程。已应用该流程的系统应恢复制造商安全启动密钥,然后按照本页所述的正常步骤操作
较旧VeraCrypt版本记录自定义密钥流程(VeraCrypt-DCS <em>SecureBoot</em> 脚本 <code>sb_set_siglists.ps1</code>用自定义密钥2011版Microsoft证书及过时的2018 dbx替换PK、KEK、db和dbx。此流程<strong>已经弃用,在2023证书链系统上不得使用</strong>:它会移除对Windows启动管理器的信任、丢弃当前撤销并可能破坏Windows交接。应恢复制造商密钥和当前dbx
</div>
<div style="text-align:left; margin-top:19px; margin-bottom:19px; padding-top:0px; padding-bottom:0px">
+1 -1
View File
@@ -61,7 +61,7 @@ VeraCrypt可以对系统分区或整个系统驱动器进行即时加密,即
由于BIOS要求,预启动密码需使用 <strong>美国键盘布局</strong> 输入。在系统加密过程中,VeraCrypt会自动透明地将键盘切换到美国布局,以确保输入的密码值与预启动模式下输入的密码值匹配。然而,从剪贴板粘贴密码可能会覆盖此保护措施。为防止因这种差异而产生的任何问题,VeraCrypt在系统加密向导中禁用了从剪贴板粘贴密码的选项。因此,在设置或输入密码时,务必手动使用与创建系统加密时相同的按键进行输入,以确保能够一致地访问您的加密系统。
</div>
<p>注意:默认情况下,Windows 7及更高版本从一个特殊的小分区启动。该分区包含启动系统所需的文件。Windows只允许具有管理员权限的应用程序在系统运行时写入该分区。在EFI启动模式(现代PC的默认模式)下,VeraCrypt无法加密此分区,因为它必须保持未加密状态,以便BIOS可以从中加载EFI引导加载程序。这反过来意味着在EFI启动模式下,VeraCrypt仅提供对安装Windows的系统分区进行加密(用户以后可以使用VeraCrypt手动加密其他数据分区)。在MBR传统启动模式下,只有当您选择加密整个系统驱动器(而不是仅选择加密安装Windows的分区)时,VeraCrypt才会对该分区进行加密。</p>
<p>在启用安全启动的EFI启动模式下,VeraCrypt会在安装、修复/重新安装、升级或Windows PostOOBE修复期间,选择受当前固件安全启动db信任且由Microsoft UEFI CA签名的引导加载程序套件。VeraCrypt 2023引导加载程序套件需要Microsoft UEFI CA 2023和Microsoft Option ROM UEFI CA 20232011引导加载程序套件需要Microsoft Corporation UEFI CA 2011。如果当前db不信任任何受支持的套件,VeraCrypt会中止操作,而不会安装会在下一次重启时被固件拒绝的加载程序。如果您手动更改固件安全启动db条目,请运行VeraCrypt修复/重新安装以刷新已安装的引导加载程序套件。有关详细信息,包括Microsoft 2023证书过渡和恢复步骤,请参阅 <a href="EFISecureBoot.html" style="text-align:left; color:#0080c0; text-decoration:none">EFI安全启动</a></p>
<p>在启用安全启动的EFI启动模式下,VeraCrypt会在安装、修复/重新安装、升级或Windows PostOOBE修复期间,选择由Microsoft UEFI CA签名且当前固件安全启动策略允许的引导加载程序套件:每个所需CA都必须存在于允许签名数据库(db)中,并且不在禁止签名数据库(dbx)中。VeraCrypt 2023引导加载程序套件需要Microsoft UEFI CA 2023和Microsoft Option ROM UEFI CA 20232011引导加载程序套件需要Microsoft Corporation UEFI CA 2011。如果当前db/dbx策略不允许任何受支持的套件,VeraCrypt会中止操作,而不会安装会在下一次重启时被固件拒绝的加载程序。如果您手动更改固件安全启动db或dbx条目,请运行VeraCrypt修复/重新安装以刷新已安装的引导加载程序套件。有关详细信息,包括Microsoft 2023证书过渡和恢复步骤,请参阅 <a href="EFISecureBoot.html" style="text-align:left; color:#0080c0; text-decoration:none">EFI安全启动</a></p>
<p>&nbsp;</p>
<p><a href="Hidden%20Operating%20System.html" style="text-align:left; color:#0080c0; text-decoration:none; font-weight:bold">下一部分 &gt;&gt;</a></p>
</div>
+696 -81
View File
@@ -39,6 +39,12 @@
#include <algorithm>
#include <Strsafe.h>
#include <wincrypt.h>
#include <wintrust.h>
#include <Softpub.h>
#pragma comment(lib, "Crypt32.lib")
#pragma comment(lib, "Wintrust.lib")
static unsigned char g_pbEFIDcsPK[1385] = {
0xA1, 0x59, 0xC0, 0xA5, 0xE4, 0x94, 0xA7, 0x4A, 0x87, 0xB5, 0xAB, 0x15,
@@ -2614,6 +2620,7 @@ namespace VeraCrypt
DWORD ResourceSet;
const wchar_t *SelectionReason;
DWORD FirmwareDbError;
DWORD FirmwareDbxError;
};
struct EfiBootLoaderResourceSelection
@@ -2622,6 +2629,7 @@ namespace VeraCrypt
DWORD ResourceSet;
const wchar_t *Reason;
DWORD FirmwareDbError;
DWORD FirmwareDbxError;
};
struct FirmwareDbMicrosoftUefiCaSupport
@@ -2741,9 +2749,9 @@ namespace VeraCrypt
return bRet;
}
static EfiBootLoaderResourceSelection MakeEfiBootLoaderResourceSelection (const EfiBootLoaderResourceSet& resources, DWORD resourceSet, const wchar_t *reason, DWORD firmwareDbError)
static EfiBootLoaderResourceSelection MakeEfiBootLoaderResourceSelection (const EfiBootLoaderResourceSet& resources, DWORD resourceSet, const wchar_t *reason, DWORD firmwareDbError, DWORD firmwareDbxError = ERROR_SUCCESS)
{
EfiBootLoaderResourceSelection selection = { &resources, resourceSet, reason, firmwareDbError };
EfiBootLoaderResourceSelection selection = { &resources, resourceSet, reason, firmwareDbError, firmwareDbxError };
return selection;
}
@@ -2816,7 +2824,7 @@ namespace VeraCrypt
SetLastError (previousLastError);
}
static void RecordEfiBootLoaderResourceSetSelectionDiagnostics (DWORD resourceSet, const wchar_t *selectionReason, DWORD firmwareDbError)
static void RecordEfiBootLoaderResourceSetSelectionDiagnostics (DWORD resourceSet, const wchar_t *selectionReason, DWORD firmwareDbError, DWORD firmwareDbxError = ERROR_SUCCESS)
{
if (!selectionReason)
return;
@@ -2835,6 +2843,7 @@ namespace VeraCrypt
WriteLocalMachineRegistryDword ((wchar_t *) EfiBootLoaderDiagnosticsRegistryKey, (wchar_t *) VC_EFI_BOOT_LOADER_RESCUE_DISK_PROMPT_RESOURCE_SET_VALUE_NAME, 0);
}
WriteLocalMachineRegistryDword ((wchar_t *) EfiBootLoaderDiagnosticsRegistryKey, L"EfiBootLoaderFirmwareDbLastError", firmwareDbError);
WriteLocalMachineRegistryDword ((wchar_t *) EfiBootLoaderDiagnosticsRegistryKey, L"EfiBootLoaderFirmwareDbxLastError", firmwareDbxError);
WriteLocalMachineRegistryString (EfiBootLoaderDiagnosticsRegistryKey, L"EfiBootLoaderSelectionReason", selectionReason, FALSE);
WriteLocalMachineRegistryString (EfiBootLoaderDiagnosticsRegistryKey, L"EfiBootLoaderSelectionTimeUtc", selectionTimeUtc, FALSE);
SetLastError (previousLastError);
@@ -2845,7 +2854,7 @@ namespace VeraCrypt
if (!images.ResourceSet || !images.SelectionReason)
return;
RecordEfiBootLoaderResourceSetSelectionDiagnostics (images.ResourceSet, images.SelectionReason, images.FirmwareDbError);
RecordEfiBootLoaderResourceSetSelectionDiagnostics (images.ResourceSet, images.SelectionReason, images.FirmwareDbError, images.FirmwareDbxError);
}
static uint32 ReadUint32LittleEndian (const uint8* buffer)
@@ -2889,12 +2898,13 @@ namespace VeraCrypt
return FirmwareDbMicrosoftUefiCaSupportContainsSupportedSet (support);
}
// Returns true when the db is structurally valid, or when malformed data appears only
// Parses either the allowed database (db) or forbidden database (dbx). Returns true
// when the signature database is structurally valid, or when malformed data appears only
// after a complete VeraCrypt-supported Microsoft CA set has already been found. In the
// latter case support.DbMalformed remains set so selection diagnostics can report it.
static bool FirmwareDbBufferGetMicrosoftUefiCaSupport (const std::vector<uint8>& db, FirmwareDbMicrosoftUefiCaSupport& support)
static bool FirmwareSignatureDatabaseBufferGetMicrosoftUefiCaSupport (const std::vector<uint8>& database, FirmwareDbMicrosoftUefiCaSupport& support)
{
// Microsoft documents these CAs as valid db entries in EFI_CERT_X509_GUID or EFI_CERT_RSA2048_GUID form:
// Microsoft documents these CAs as valid signature-database entries in EFI_CERT_X509_GUID or EFI_CERT_RSA2048_GUID form:
// https://learn.microsoft.com/windows-hardware/manufacture/desktop/windows-secure-boot-key-creation-and-management-guidance
// EFI_CERT_X509_GUID {a5c059a1-94e4-4aa7-87b5-ab155c2bf072}
static const uint8 efiCertX509Guid[16] = { 0xA1, 0x59, 0xC0, 0xA5, 0xE4, 0x94, 0xA7, 0x4A, 0x87, 0xB5, 0xAB, 0x15, 0x5C, 0x2B, 0xF0, 0x72 };
@@ -3020,7 +3030,7 @@ namespace VeraCrypt
// The two Windows boot manager signing CAs below are not used for loader-set selection.
// They are tracked so that the trust of the chainloaded Windows boot manager copy
// (bootmgfw_ms.vc) can be verified against the active Secure Boot db before a reboot.
// (bootmgfw_ms.vc) can be checked against the active Secure Boot db and dbx before a reboot.
// Microsoft Windows Production PCA 2011, SHA-1 thumbprint 580A6F4CC4E4B669B9EBDC1B2B3E087B80D0678D.
// DER source: https://go.microsoft.com/fwlink/p/?linkid=321192, SHA-256 E8E95F0733A55E8BAD7BE0A1413EE23C51FCEA64B3C8FA6A786935FDDCC71961.
static const uint8 microsoftWindowsProductionPca2011Rsa2048Modulus[256] =
@@ -3102,18 +3112,18 @@ namespace VeraCrypt
size_t offset = 0;
memset (&support, 0, sizeof (support));
while (offset < db.size ())
while (offset < database.size ())
{
if (db.size () - offset < efiSignatureListHeaderSize)
if (database.size () - offset < efiSignatureListHeaderSize)
return FirmwareDbMicrosoftUefiCaSupportSetMalformed (support, ERROR_INVALID_DATA);
const uint8* signatureList = &db[offset];
const uint8* signatureList = &database[offset];
uint32 signatureListSize = ReadUint32LittleEndian (signatureList + efiGuidSize);
uint32 signatureHeaderSize = ReadUint32LittleEndian (signatureList + efiGuidSize + sizeof (uint32));
uint32 signatureSize = ReadUint32LittleEndian (signatureList + efiGuidSize + sizeof (uint32) * 2);
if ((signatureListSize < efiSignatureListHeaderSize)
|| (signatureListSize > db.size () - offset)
|| (signatureListSize > database.size () - offset)
|| (signatureHeaderSize > signatureListSize - efiSignatureListHeaderSize))
return FirmwareDbMicrosoftUefiCaSupportSetMalformed (support, ERROR_INVALID_DATA);
@@ -3129,7 +3139,7 @@ namespace VeraCrypt
for (size_t signatureOffset = signaturesOffset; signatureOffset < offset + signatureListSize; signatureOffset += signatureSize)
{
const uint8* certificate = &db[signatureOffset + efiSignatureOwnerSize];
const uint8* certificate = &database[signatureOffset + efiSignatureOwnerSize];
size_t certificateSize = signatureSize - efiSignatureOwnerSize;
if (!support.ContainsMicrosoftCorporationUefiCa2011
@@ -3170,7 +3180,7 @@ namespace VeraCrypt
for (size_t signatureOffset = signaturesOffset; signatureOffset < offset + signatureListSize; signatureOffset += signatureSize)
{
const uint8* publicKey = &db[signatureOffset + efiSignatureOwnerSize];
const uint8* publicKey = &database[signatureOffset + efiSignatureOwnerSize];
if (!support.ContainsMicrosoftCorporationUefiCa2011
&& BufferEquals (publicKey, efiRsa2048KeySize, microsoftCorporationUefiCa2011Rsa2048Modulus, sizeof (microsoftCorporationUefiCa2011Rsa2048Modulus)))
@@ -3206,17 +3216,18 @@ namespace VeraCrypt
return true;
}
static bool TryFirmwareDbGetMicrosoftUefiCaSupport (FirmwareDbMicrosoftUefiCaSupport& support)
static bool TryFirmwareSignatureDatabaseGetMicrosoftUefiCaSupport (const wchar_t *variableName, FirmwareDbMicrosoftUefiCaSupport& support)
{
std::vector<uint8> db;
memset (&support, 0, sizeof (support));
std::vector<uint8> database;
DWORD dwError = ERROR_SUCCESS;
if (!ReadFirmwareEnvironmentVariableBuffer (L"db", EfiImageSecurityDatabaseGuid, db, &dwError))
if (!ReadFirmwareEnvironmentVariableBuffer (variableName, EfiImageSecurityDatabaseGuid, database, &dwError))
{
SetLastError (dwError);
return false;
}
if (!FirmwareDbBufferGetMicrosoftUefiCaSupport (db, support))
if (!FirmwareSignatureDatabaseBufferGetMicrosoftUefiCaSupport (database, support))
{
SetLastError (support.ParseError ? support.ParseError : ERROR_INVALID_DATA);
return false;
@@ -3225,6 +3236,36 @@ namespace VeraCrypt
return true;
}
static bool TryFirmwareDbGetMicrosoftUefiCaSupport (FirmwareDbMicrosoftUefiCaSupport& support)
{
return TryFirmwareSignatureDatabaseGetMicrosoftUefiCaSupport (L"db", support);
}
static bool TryFirmwareDbxGetMicrosoftUefiCaSupport (FirmwareDbMicrosoftUefiCaSupport& support, bool *pPresent = NULL)
{
if (pPresent)
*pPresent = false;
if (TryFirmwareSignatureDatabaseGetMicrosoftUefiCaSupport (L"dbx", support))
{
if (pPresent)
*pPresent = true;
return true;
}
// dbx is optional in UEFI. Custom-key deployments in particular may have no
// dbx variable at all; that is a valid empty forbidden database, not a read
// failure. Preserve fail-closed handling for every other error.
if (GetLastError () == ERROR_ENVVAR_NOT_FOUND)
{
memset (&support, 0, sizeof (support));
SetLastError (ERROR_SUCCESS);
return true;
}
return false;
}
static bool IsFirmwareDbUnavailableError (DWORD dwError)
{
return (dwError == ERROR_ENVVAR_NOT_FOUND) || (dwError == ERROR_INVALID_FUNCTION);
@@ -3254,9 +3295,9 @@ namespace VeraCrypt
return true;
}
static __declspec(noreturn) void ThrowUnsupportedEfiSecureBootDb (const wchar_t *reason, DWORD firmwareDbError)
static __declspec(noreturn) void ThrowUnsupportedEfiSecureBootDb (const wchar_t *reason, DWORD firmwareDbError, DWORD firmwareDbxError = ERROR_SUCCESS)
{
RecordEfiBootLoaderResourceSetSelectionDiagnostics (0, reason, firmwareDbError);
RecordEfiBootLoaderResourceSetSelectionDiagnostics (0, reason, firmwareDbError, firmwareDbxError);
throw ErrorException ("SYSENC_EFI_UNSUPPORTED_SECUREBOOT_CA", SRC_POS);
}
@@ -3264,47 +3305,93 @@ namespace VeraCrypt
{
// The current 2023 DCS set uses both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023:
// DcsInt.dcs and LegacySpeaker.dcs are signed through the Option ROM UEFI CA 2023 chain.
// If Secure Boot is enabled, only select a loader set whose signing CA is trusted by the active db.
// If Secure Boot is enabled (or its state cannot be established), only select a loader set whose
// signing CA is allowed by the active db and is not forbidden by the active dbx.
FirmwareDbMicrosoftUefiCaSupport support;
if (TryFirmwareDbGetMicrosoftUefiCaSupport (support))
{
DWORD firmwareDbError = FirmwareDbMicrosoftUefiCaSupportGetDiagnosticError (support);
if (FirmwareDbMicrosoftUefiCaSupportContains2023Set (support))
{
return MakeEfiBootLoaderResourceSelection (
EfiBootLoaderResources2023,
VC_EFI_BOOT_LOADER_RESOURCE_SET_2023,
support.DbMalformed
? L"firmware db contains Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 before malformed data"
: L"firmware db contains Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023",
firmwareDbError);
}
if (support.ContainsMicrosoftCorporationUefiCa2011)
{
return MakeEfiBootLoaderResourceSelection (
EfiBootLoaderResources2011,
VC_EFI_BOOT_LOADER_RESOURCE_SET_2011,
support.DbMalformed
? L"firmware db contains Microsoft Corporation UEFI CA 2011 before malformed data"
: L"firmware db contains Microsoft Corporation UEFI CA 2011",
firmwareDbError);
}
bool bSecureBootEnabled = false;
bool bSecureBootStateKnown = TryFirmwareSecureBootEnabled (bSecureBootEnabled);
DWORD secureBootLastError = bSecureBootStateKnown ? ERROR_SUCCESS : GetLastError ();
if (support.DbMalformed && (!bSecureBootStateKnown || bSecureBootEnabled))
{
ThrowUnsupportedEfiSecureBootDb (
L"Secure Boot is enabled or unavailable, but firmware db could not be parsed completely; refusing to select an EFI bootloader from partial policy data",
firmwareDbError);
}
FirmwareDbMicrosoftUefiCaSupport forbiddenSupport;
bool bFirmwareDbxChecked = false;
bool bFirmwareDbxPresent = false;
DWORD firmwareDbxError = ERROR_SUCCESS;
if (!TryFirmwareDbxGetMicrosoftUefiCaSupport (forbiddenSupport, &bFirmwareDbxPresent) || forbiddenSupport.DbMalformed)
{
firmwareDbxError = forbiddenSupport.ParseError ? forbiddenSupport.ParseError : GetLastError ();
if (firmwareDbxError == ERROR_SUCCESS)
firmwareDbxError = ERROR_INVALID_DATA;
if (!bSecureBootStateKnown || bSecureBootEnabled)
{
ThrowUnsupportedEfiSecureBootDb (
L"Secure Boot is enabled or unavailable, but firmware dbx could not be read and parsed completely; refusing to select an EFI bootloader without checking revocations",
firmwareDbError,
firmwareDbxError);
}
}
else
bFirmwareDbxChecked = true;
bool b2023SetPresent = FirmwareDbMicrosoftUefiCaSupportContains2023Set (support);
bool b2023SetRevoked = b2023SetPresent && bFirmwareDbxChecked
&& (forbiddenSupport.ContainsMicrosoftUefiCa2023 || forbiddenSupport.ContainsMicrosoftOptionRomUefiCa2023);
bool b2011SetPresent = support.ContainsMicrosoftCorporationUefiCa2011;
bool b2011SetRevoked = b2011SetPresent && bFirmwareDbxChecked && forbiddenSupport.ContainsMicrosoftCorporationUefiCa2011;
if (b2023SetPresent && !b2023SetRevoked)
{
const wchar_t *reason = bFirmwareDbxChecked
? (bFirmwareDbxPresent
? L"firmware db contains the Microsoft 2023 UEFI CA pair and dbx contains no known revocation of either CA"
: L"firmware db contains the Microsoft 2023 UEFI CA pair and the optional dbx variable is absent")
: L"Secure Boot is disabled; firmware db contains the Microsoft 2023 UEFI CA pair, but dbx could not be checked";
return MakeEfiBootLoaderResourceSelection (
EfiBootLoaderResources2023,
VC_EFI_BOOT_LOADER_RESOURCE_SET_2023,
reason,
firmwareDbError,
firmwareDbxError);
}
if (b2011SetPresent && !b2011SetRevoked)
{
const wchar_t *reason = bFirmwareDbxChecked
? (bFirmwareDbxPresent
? L"firmware db contains Microsoft Corporation UEFI CA 2011 and dbx contains no known revocation of that CA"
: L"firmware db contains Microsoft Corporation UEFI CA 2011 and the optional dbx variable is absent")
: L"Secure Boot is disabled; firmware db contains Microsoft Corporation UEFI CA 2011, but dbx could not be checked";
return MakeEfiBootLoaderResourceSelection (
EfiBootLoaderResources2011,
VC_EFI_BOOT_LOADER_RESOURCE_SET_2011,
reason,
firmwareDbError,
firmwareDbxError);
}
if (bSecureBootStateKnown && !bSecureBootEnabled)
return MakeEfiBootLoaderResourceSelection (EfiBootLoaderResources2011, VC_EFI_BOOT_LOADER_RESOURCE_SET_2011, L"Secure Boot is disabled and firmware db does not contain a supported Microsoft UEFI CA; using 2011 compatibility fallback", ERROR_SUCCESS);
if (!bSecureBootStateKnown && IsFirmwareDbUnavailableError (secureBootLastError))
return MakeEfiBootLoaderResourceSelection (EfiBootLoaderResources2011, VC_EFI_BOOT_LOADER_RESOURCE_SET_2011, L"Secure Boot is unavailable and firmware db does not contain a supported Microsoft UEFI CA; using 2011 compatibility fallback", ERROR_SUCCESS);
if (bSecureBootStateKnown)
ThrowUnsupportedEfiSecureBootDb (L"Secure Boot is enabled but firmware db does not contain Microsoft Corporation UEFI CA 2011 or the Microsoft 2023 UEFI CA pair required by VeraCrypt", ERROR_SUCCESS);
if (b2023SetRevoked || b2011SetRevoked)
ThrowUnsupportedEfiSecureBootDb (L"Secure Boot is enabled, but every VeraCrypt EFI bootloader signing CA set present in firmware db is forbidden by firmware dbx", firmwareDbError, firmwareDbxError);
ThrowUnsupportedEfiSecureBootDb (L"firmware db does not contain a supported Microsoft UEFI CA and Secure Boot state could not be read; refusing to select an unsupported EFI bootloader signing CA", secureBootLastError);
if (bSecureBootStateKnown)
ThrowUnsupportedEfiSecureBootDb (L"Secure Boot is enabled but firmware db does not contain Microsoft Corporation UEFI CA 2011 or the Microsoft 2023 UEFI CA pair required by VeraCrypt", firmwareDbError, firmwareDbxError);
ThrowUnsupportedEfiSecureBootDb (L"firmware db does not contain a supported Microsoft UEFI CA and Secure Boot state could not be read; refusing to select an unsupported EFI bootloader signing CA", secureBootLastError, firmwareDbxError);
}
DWORD dwError = GetLastError ();
@@ -3357,9 +3444,8 @@ namespace VeraCrypt
return resource;
}
static EfiBootLoaderImages MapEfiBootLoaderImages (bool rescueDisk)
static EfiBootLoaderImages MapEfiBootLoaderImages (const EfiBootLoaderResourceSelection& selection, bool rescueDisk)
{
EfiBootLoaderResourceSelection selection = GetPreferredEfiBootLoaderResourceSet ();
const EfiBootLoaderResourceSet& resources = *selection.Resources;
EfiBootLoaderImages images = {0};
@@ -3372,10 +3458,29 @@ namespace VeraCrypt
images.ResourceSet = selection.ResourceSet;
images.SelectionReason = selection.Reason;
images.FirmwareDbError = selection.FirmwareDbError;
images.FirmwareDbxError = selection.FirmwareDbxError;
return images;
}
static EfiBootLoaderImages MapEfiBootLoaderImages (bool rescueDisk)
{
return MapEfiBootLoaderImages (GetPreferredEfiBootLoaderResourceSet (), rescueDisk);
}
static EfiBootLoaderImages MapEfiBootLoaderImages (DWORD resourceSet, bool rescueDisk)
{
if (resourceSet == VC_EFI_BOOT_LOADER_RESOURCE_SET_2011)
return MapEfiBootLoaderImages (MakeEfiBootLoaderResourceSelection (
EfiBootLoaderResources2011, resourceSet, L"explicit 2011 resource-set inspection", ERROR_SUCCESS), rescueDisk);
if (resourceSet == VC_EFI_BOOT_LOADER_RESOURCE_SET_2023)
return MapEfiBootLoaderImages (MakeEfiBootLoaderResourceSelection (
EfiBootLoaderResources2023, resourceSet, L"explicit 2023 resource-set inspection", ERROR_SUCCESS), rescueDisk);
throw ParameterIncorrect (SRC_POS);
}
static void BackupEfiBootLoaderImageIfDifferent (EfiBoot& efiBoot, const wchar_t* imageName, const wchar_t* backupName, uint8* replacementData, DWORD replacementSize)
{
std::vector<uint8> currentImage;
@@ -3404,7 +3509,7 @@ namespace VeraCrypt
{
std::vector<uint8> currentImage;
if (!efiBoot.ReadFileToBuffer (imageName, currentImage))
return false;
return true;
return (currentImage.size () != replacementSize)
|| ((replacementSize != 0) && (memcmp (currentImage.data (), replacementData, replacementSize) != 0));
@@ -3419,6 +3524,11 @@ namespace VeraCrypt
|| EfiBootLoaderImageDiffers (efiBoot, L"\\EFI\\VeraCrypt\\DcsInfo.dcs", images.DcsInfo, images.SizeDcsInfo);
}
static bool EfiBootLoaderImagesMatch (EfiBoot& efiBoot, const EfiBootLoaderImages& images)
{
return !EfiBootLoaderImagesDiffer (efiBoot, images);
}
static bool EfiBootLoaderRefreshRequiresRescueDiskPrompt (EfiBoot& efiBoot, const EfiBootLoaderImages& images)
{
DWORD recordedResourceSet = 0;
@@ -4015,6 +4125,395 @@ namespace VeraCrypt
&& BufferHasPattern (fileContent.data (), fileContent.size (), g_szMsBootString, strlen (g_szMsBootString));
}
template <typename T>
static bool ReadStructureFromBuffer (const std::vector<uint8>& buffer, size_t offset, T& value)
{
if (offset > buffer.size () || sizeof (T) > buffer.size () - offset)
return false;
memcpy (&value, buffer.data () + offset, sizeof (T));
return true;
}
static bool GetPeSecurityDirectory (const std::vector<uint8>& image, IMAGE_DATA_DIRECTORY& securityDirectory)
{
memset (&securityDirectory, 0, sizeof (securityDirectory));
IMAGE_DOS_HEADER dosHeader;
if (!ReadStructureFromBuffer (image, 0, dosHeader)
|| dosHeader.e_magic != IMAGE_DOS_SIGNATURE
|| dosHeader.e_lfanew < 0)
return false;
size_t ntOffset = (size_t) dosHeader.e_lfanew;
DWORD ntSignature = 0;
IMAGE_FILE_HEADER fileHeader;
if (!ReadStructureFromBuffer (image, ntOffset, ntSignature)
|| ntSignature != IMAGE_NT_SIGNATURE
|| !ReadStructureFromBuffer (image, ntOffset + sizeof (ntSignature), fileHeader))
return false;
size_t optionalOffset = ntOffset + sizeof (ntSignature) + sizeof (fileHeader);
WORD optionalMagic = 0;
if (!ReadStructureFromBuffer (image, optionalOffset, optionalMagic))
return false;
size_t dataDirectoryOffset = 0;
size_t numberOfRvaAndSizesOffset = 0;
if (optionalMagic == IMAGE_NT_OPTIONAL_HDR32_MAGIC)
{
dataDirectoryOffset = offsetof (IMAGE_OPTIONAL_HEADER32, DataDirectory);
numberOfRvaAndSizesOffset = offsetof (IMAGE_OPTIONAL_HEADER32, NumberOfRvaAndSizes);
}
else if (optionalMagic == IMAGE_NT_OPTIONAL_HDR64_MAGIC)
{
dataDirectoryOffset = offsetof (IMAGE_OPTIONAL_HEADER64, DataDirectory);
numberOfRvaAndSizesOffset = offsetof (IMAGE_OPTIONAL_HEADER64, NumberOfRvaAndSizes);
}
else
return false;
DWORD numberOfRvaAndSizes = 0;
if (!ReadStructureFromBuffer (image, optionalOffset + numberOfRvaAndSizesOffset, numberOfRvaAndSizes)
|| numberOfRvaAndSizes <= IMAGE_DIRECTORY_ENTRY_SECURITY)
return false;
size_t securityEntryOffset = dataDirectoryOffset + IMAGE_DIRECTORY_ENTRY_SECURITY * sizeof (IMAGE_DATA_DIRECTORY);
if (securityEntryOffset > fileHeader.SizeOfOptionalHeader
|| sizeof (IMAGE_DATA_DIRECTORY) > fileHeader.SizeOfOptionalHeader - securityEntryOffset
|| !ReadStructureFromBuffer (image, optionalOffset + securityEntryOffset, securityDirectory)
|| securityDirectory.VirtualAddress == 0
|| securityDirectory.Size < sizeof (WIN_CERTIFICATE))
return false;
size_t certificateTableOffset = (size_t) securityDirectory.VirtualAddress;
return certificateTableOffset <= image.size ()
&& (size_t) securityDirectory.Size <= image.size () - certificateTableOffset;
}
static DWORD GetCertificateIssuerFamily (PCCERT_CONTEXT certificate)
{
wchar_t issuerName[256] = {0};
if (CertGetNameStringW (certificate, CERT_NAME_SIMPLE_DISPLAY_TYPE, CERT_NAME_ISSUER_FLAG,
NULL, issuerName, ARRAYSIZE (issuerName)) <= 1)
return VC_EFI_WINDOWS_LOADER_SIGNER_UNKNOWN;
if (_wcsicmp (issuerName, L"Microsoft Windows Production PCA 2011") == 0)
return VC_EFI_WINDOWS_LOADER_SIGNER_PCA_2011;
if (_wcsicmp (issuerName, L"Windows UEFI CA 2023") == 0)
return VC_EFI_WINDOWS_LOADER_SIGNER_CA_2023;
return VC_EFI_WINDOWS_LOADER_SIGNER_UNKNOWN;
}
static bool GetPkcs7SignerFamily (const uint8 *pkcs7Data, DWORD pkcs7Size, DWORD& signerFamily)
{
signerFamily = VC_EFI_WINDOWS_LOADER_SIGNER_UNKNOWN;
CRYPT_DATA_BLOB blob = { pkcs7Size, const_cast<BYTE *> (pkcs7Data) };
HCERTSTORE certificateStore = NULL;
HCRYPTMSG cryptMsg = NULL;
bool bParsed = false;
if (!CryptQueryObject (CERT_QUERY_OBJECT_BLOB, &blob,
CERT_QUERY_CONTENT_FLAG_PKCS7_SIGNED | CERT_QUERY_CONTENT_FLAG_PKCS7_SIGNED_EMBED,
CERT_QUERY_FORMAT_FLAG_BINARY, 0, NULL, NULL, NULL, &certificateStore, &cryptMsg, NULL))
return false;
DWORD signerCount = 0;
DWORD signerCountSize = sizeof (signerCount);
if (CryptMsgGetParam (cryptMsg, CMSG_SIGNER_COUNT_PARAM, 0, &signerCount, &signerCountSize))
{
bParsed = signerCount != 0;
for (DWORD signerIndex = 0; signerIndex < signerCount; ++signerIndex)
{
DWORD signerInfoSize = 0;
if (!CryptMsgGetParam (cryptMsg, CMSG_SIGNER_INFO_PARAM, signerIndex, NULL, &signerInfoSize)
|| signerInfoSize < sizeof (CMSG_SIGNER_INFO))
{
bParsed = false;
break;
}
std::vector<uint8> signerInfoBuffer (signerInfoSize);
if (!CryptMsgGetParam (cryptMsg, CMSG_SIGNER_INFO_PARAM, signerIndex, signerInfoBuffer.data (), &signerInfoSize))
{
bParsed = false;
break;
}
PCMSG_SIGNER_INFO signerInfo = reinterpret_cast<PCMSG_SIGNER_INFO> (signerInfoBuffer.data ());
CERT_INFO certificateInfo;
memset (&certificateInfo, 0, sizeof (certificateInfo));
certificateInfo.Issuer = signerInfo->Issuer;
certificateInfo.SerialNumber = signerInfo->SerialNumber;
PCCERT_CONTEXT signerCertificate = CertFindCertificateInStore (certificateStore,
X509_ASN_ENCODING | PKCS_7_ASN_ENCODING, 0, CERT_FIND_SUBJECT_CERT, &certificateInfo, NULL);
if (!signerCertificate)
{
bParsed = false;
break;
}
DWORD currentFamily = GetCertificateIssuerFamily (signerCertificate);
CertFreeCertificateContext (signerCertificate);
if (currentFamily != VC_EFI_WINDOWS_LOADER_SIGNER_UNKNOWN)
{
if (signerFamily != VC_EFI_WINDOWS_LOADER_SIGNER_UNKNOWN && signerFamily != currentFamily)
{
signerFamily = VC_EFI_WINDOWS_LOADER_SIGNER_UNKNOWN;
bParsed = false;
break;
}
signerFamily = currentFamily;
}
}
}
if (cryptMsg)
CryptMsgClose (cryptMsg);
if (certificateStore)
CertCloseStore (certificateStore, 0);
return bParsed;
}
// Extracts the signer from the PE image's embedded WIN_CERTIFICATE table. This
// deliberately ignores catalog signatures: the firmware evaluates the image's
// embedded Authenticode signature, and Get-AuthenticodeSignature may otherwise
// report an unrelated catalog signer for a Windows boot file.
static bool GetEmbeddedPeSignerFamily (const std::vector<uint8>& image, DWORD& signerFamily)
{
signerFamily = VC_EFI_WINDOWS_LOADER_SIGNER_UNKNOWN;
IMAGE_DATA_DIRECTORY securityDirectory;
if (!GetPeSecurityDirectory (image, securityDirectory))
return false;
size_t tableOffset = (size_t) securityDirectory.VirtualAddress;
size_t tableEnd = tableOffset + (size_t) securityDirectory.Size;
bool bParsedSignature = false;
DWORD detectedFamily = VC_EFI_WINDOWS_LOADER_SIGNER_UNKNOWN;
while (tableOffset + sizeof (WIN_CERTIFICATE) <= tableEnd)
{
WIN_CERTIFICATE certificateHeader;
if (!ReadStructureFromBuffer (image, tableOffset, certificateHeader)
|| certificateHeader.dwLength < offsetof (WIN_CERTIFICATE, bCertificate)
|| certificateHeader.dwLength > tableEnd - tableOffset)
return false;
if (certificateHeader.wCertificateType == WIN_CERT_TYPE_PKCS_SIGNED_DATA)
{
DWORD currentFamily = VC_EFI_WINDOWS_LOADER_SIGNER_UNKNOWN;
const size_t certificateDataOffset = offsetof (WIN_CERTIFICATE, bCertificate);
DWORD certificateDataSize = certificateHeader.dwLength - (DWORD) certificateDataOffset;
if (!GetPkcs7SignerFamily (image.data () + tableOffset + certificateDataOffset,
certificateDataSize, currentFamily))
return false;
bParsedSignature = true;
if (currentFamily != VC_EFI_WINDOWS_LOADER_SIGNER_UNKNOWN)
{
if (detectedFamily != VC_EFI_WINDOWS_LOADER_SIGNER_UNKNOWN && detectedFamily != currentFamily)
return false;
detectedFamily = currentFamily;
}
}
size_t alignedLength = ((size_t) certificateHeader.dwLength + 7) & ~(size_t) 7;
if (alignedLength == 0 || alignedLength > tableEnd - tableOffset)
break;
tableOffset += alignedLength;
}
signerFamily = detectedFamily;
return bParsedSignature;
}
static bool ReadLocalFileToBuffer (const wchar_t *path, std::vector<uint8>& fileContent)
{
fileContent.clear ();
File file (path, true);
if (!file.IsOpened ())
return false;
unsigned __int64 fileSize = 0;
file.GetFileSize (fileSize);
if (fileSize == 0 || fileSize > TC_MAX_EFI_BOOT_LOADER_FILE_SIZE || fileSize > UINT_MAX)
{
file.Close ();
return false;
}
fileContent.resize ((size_t) fileSize);
bool bRead = file.Read (fileContent.data (), (DWORD) fileSize) == (DWORD) fileSize;
file.Close ();
if (!bRead)
fileContent.clear ();
return bRead;
}
static bool IsWindowsLoaderSignerAllowedByKnownCaPolicy (DWORD signerFamily,
const FirmwareDbMicrosoftUefiCaSupport& allowedSupport,
const FirmwareDbMicrosoftUefiCaSupport& forbiddenSupport)
{
if (signerFamily == VC_EFI_WINDOWS_LOADER_SIGNER_CA_2023)
return allowedSupport.ContainsWindowsUefiCa2023 && !forbiddenSupport.ContainsWindowsUefiCa2023;
if (signerFamily == VC_EFI_WINDOWS_LOADER_SIGNER_PCA_2011)
return allowedSupport.ContainsMicrosoftWindowsProductionPca2011
&& !forbiddenSupport.ContainsMicrosoftWindowsProductionPca2011;
return false;
}
static bool EfiBootLoaderStandardCopiesMatch (EfiBoot& efiBoot, const EfiBootLoaderImages& images)
{
const wchar_t *standardPaths[] =
{
L"\\EFI\\Microsoft\\Boot\\bootmgfw.efi",
L"\\EFI\\Boot\\bootx64.efi"
};
for (size_t pathIndex = 0; pathIndex < ARRAYSIZE (standardPaths); ++pathIndex)
{
std::vector<uint8> standardImage;
if (!efiBoot.ReadFileToBuffer (standardPaths[pathIndex], standardImage))
{
if (efiBoot.FileExists (standardPaths[pathIndex]))
return false;
continue;
}
if (BufferHasVeraCryptBootLoaderPattern (standardImage)
&& !BufferEquals (standardImage.data (), standardImage.size (), images.DcsBoot, images.SizeDcsBoot))
return false;
}
return true;
}
static int GetWindowsLoaderSignerPreference (DWORD signerFamily)
{
return signerFamily == VC_EFI_WINDOWS_LOADER_SIGNER_CA_2023 ? 2
: (signerFamily == VC_EFI_WINDOWS_LOADER_SIGNER_PCA_2011 ? 1 : 0);
}
static bool VerifyFileAuthenticodeSignature (const wchar_t *path)
{
WINTRUST_FILE_INFO fileInfo;
memset (&fileInfo, 0, sizeof (fileInfo));
fileInfo.cbStruct = sizeof (fileInfo);
fileInfo.pcwszFilePath = path;
WINTRUST_DATA trustData;
memset (&trustData, 0, sizeof (trustData));
trustData.cbStruct = sizeof (trustData);
trustData.dwUIChoice = WTD_UI_NONE;
trustData.fdwRevocationChecks = WTD_REVOKE_NONE;
trustData.dwUnionChoice = WTD_CHOICE_FILE;
trustData.pFile = &fileInfo;
trustData.dwStateAction = WTD_STATEACTION_VERIFY;
trustData.dwProvFlags = WTD_CACHE_ONLY_URL_RETRIEVAL;
GUID action = WINTRUST_ACTION_GENERIC_VERIFY_V2;
LONG trustResult = WinVerifyTrust (NULL, &action, &trustData);
trustData.dwStateAction = WTD_STATEACTION_CLOSE;
WinVerifyTrust (NULL, &action, &trustData);
return trustResult == ERROR_SUCCESS;
}
static bool RefreshWindowsBootManagerFromWindows (EfiBoot& efiBoot, const wchar_t *destinationName)
{
FirmwareDbMicrosoftUefiCaSupport allowedSupport;
FirmwareDbMicrosoftUefiCaSupport forbiddenSupport;
if (!TryFirmwareDbGetMicrosoftUefiCaSupport (allowedSupport) || allowedSupport.DbMalformed
|| !TryFirmwareDbxGetMicrosoftUefiCaSupport (forbiddenSupport) || forbiddenSupport.DbMalformed)
return false;
wchar_t windowsDirectory[MAX_PATH] = {0};
UINT windowsDirectoryLength = ::GetWindowsDirectoryW (windowsDirectory, ARRAYSIZE (windowsDirectory));
if (windowsDirectoryLength == 0 || windowsDirectoryLength >= ARRAYSIZE (windowsDirectory))
return false;
const wchar_t *relativeCandidatePaths[] =
{
L"\\Boot\\EFI_EX\\bootmgfw_EX.efi",
L"\\Boot\\EFI\\bootmgfw.efi"
};
std::vector<uint8> preferredCandidate;
wstring preferredCandidatePath;
DWORD preferredSigner = VC_EFI_WINDOWS_LOADER_SIGNER_UNKNOWN;
for (size_t candidateIndex = 0; candidateIndex < ARRAYSIZE (relativeCandidatePaths); ++candidateIndex)
{
wstring candidatePath = windowsDirectory;
candidatePath += relativeCandidatePaths[candidateIndex];
std::vector<uint8> candidate;
DWORD candidateSigner = VC_EFI_WINDOWS_LOADER_SIGNER_UNKNOWN;
static const char windowsBootManagerMarker[] = "bootmgfw.pdb";
if (!ReadLocalFileToBuffer (candidatePath.c_str (), candidate)
|| !BufferHasPattern (candidate.data (), candidate.size (), windowsBootManagerMarker, strlen (windowsBootManagerMarker))
|| !VerifyFileAuthenticodeSignature (candidatePath.c_str ())
|| !GetEmbeddedPeSignerFamily (candidate, candidateSigner)
|| !IsWindowsLoaderSignerAllowedByKnownCaPolicy (candidateSigner, allowedSupport, forbiddenSupport))
continue;
if (GetWindowsLoaderSignerPreference (candidateSigner) > GetWindowsLoaderSignerPreference (preferredSigner))
{
preferredCandidate.swap (candidate);
preferredCandidatePath = candidatePath;
preferredSigner = candidateSigner;
}
}
if (preferredCandidate.empty ())
return false;
std::vector<uint8> installedLoader;
DWORD installedSigner = VC_EFI_WINDOWS_LOADER_SIGNER_UNKNOWN;
bool bInstalledLoaderRead = false;
try
{
bInstalledLoaderRead = efiBoot.ReadFileToBuffer (destinationName, installedLoader);
}
catch (...)
{
installedLoader.clear ();
}
if (bInstalledLoaderRead
&& GetEmbeddedPeSignerFamily (installedLoader, installedSigner)
&& IsWindowsLoaderSignerAllowedByKnownCaPolicy (installedSigner, allowedSupport, forbiddenSupport)
&& GetWindowsLoaderSignerPreference (installedSigner) > GetWindowsLoaderSignerPreference (preferredSigner))
return true;
if (!installedLoader.empty ()
&& BufferEquals (installedLoader.data (), installedLoader.size (), preferredCandidate.data (), preferredCandidate.size ()))
return true;
// Keep the currently bootable manager intact until a complete replacement has
// been written and read back on the ESP.
wstring temporaryName = destinationName;
temporaryName += L".vc_new";
try
{
efiBoot.SaveFile (temporaryName.c_str (), preferredCandidate.data (), (DWORD) preferredCandidate.size ());
std::vector<uint8> verifiedCandidate;
if (!efiBoot.ReadFileToBuffer (temporaryName.c_str (), verifiedCandidate)
|| !BufferEquals (verifiedCandidate.data (), verifiedCandidate.size (), preferredCandidate.data (), preferredCandidate.size ()))
throw ErrorException ("EFI_BOOT_LOADER_FILE_READ_FAILED", SRC_POS);
throw_sys_if (!efiBoot.RenameFile (temporaryName.c_str (), destinationName, TRUE));
}
catch (...)
{
efiBoot.DelFile (temporaryName.c_str ());
throw;
}
WriteEfiBootLoaderDiagnosticsRegistryDword (L"WindowsLoaderRefreshSigner", preferredSigner);
WriteLocalMachineRegistryString (EfiBootLoaderDiagnosticsRegistryKey, L"WindowsLoaderRefreshSource",
(wchar_t *) preferredCandidatePath.c_str (), FALSE);
return true;
}
void EfiBoot::SaveFile(const wchar_t* name, uint8* data, DWORD size) {
wstring path = EfiBootPartPath;
path += name;
@@ -4404,10 +4903,12 @@ namespace VeraCrypt
const wchar_t * szBackupMsBootloader = L"\\EFI\\Microsoft\\Boot\\bootmgfw_ms.vc";
const wchar_t * szStdEfiBootloader = L"\\EFI\\Boot\\bootx64.efi";
const wchar_t * szBackupEfiBootloader = L"\\EFI\\Boot\\original_bootx64.vc_backup";
const bool bCanRefreshWindowsLoaderFromOs = !hiddenOSCreation && !IsHiddenOSRunning ();
if (preserveUserConfig)
{
bool bModifiedMsBoot = true, bMissingMsBoot = false, bMsBootloaderMovedToBackup = false;
bool bWindowsLoaderRefreshedFromOs = false;
if (EfiBootInst.FileExists (szStdMsBootloader))
EfiBootInst.GetFileSize(szStdMsBootloader, loaderSize);
else
@@ -4485,10 +4986,21 @@ namespace VeraCrypt
}
if (!bFound && !PostOOBEMode)
throw ErrorException ("WINDOWS_EFI_BOOT_LOADER_MISSING", SRC_POS);
{
// Windows keeps servicing copies outside the ESP. They are especially
// important after the 2023 CA migration, because the standard ESP path
// intentionally contains DcsBoot and Windows may therefore not replace it.
bWindowsLoaderRefreshedFromOs = bCanRefreshWindowsLoaderFromOs
&& RefreshWindowsBootManagerFromWindows (EfiBootInst, szBackupMsBootloader);
if (!bWindowsLoaderRefreshedFromOs)
throw ErrorException ("WINDOWS_EFI_BOOT_LOADER_MISSING", SRC_POS);
}
}
}
if (bCanRefreshWindowsLoaderFromOs && !bWindowsLoaderRefreshedFromOs)
RefreshWindowsBootManagerFromWindows (EfiBootInst, szBackupMsBootloader);
if (PostOOBEMode && EfiBootInst.FileExists (L"\\EFI\\VeraCrypt\\DcsBoot.efi"))
{
const bool bRefreshMsBootloader = !bModifiedMsBoot
@@ -6212,6 +6724,44 @@ namespace VeraCrypt
*pMicrosoft2023UefiCAsSupported = GetPreferredEfiBootLoaderResourceSet ().ResourceSet == VC_EFI_BOOT_LOADER_RESOURCE_SET_2023;
}
static void RecordEfiBootChainTrustStatusDiagnostics (
const EfiBootChainTrustStatus& status,
DWORD chainError = ERROR_SUCCESS,
DWORD firmwareDbError = ERROR_SUCCESS,
DWORD firmwareDbxError = ERROR_SUCCESS)
{
DWORD previousLastError = GetLastError ();
WCHAR checkTimeUtc[32] = {0};
SYSTEMTIME systemTime;
GetSystemTime (&systemTime);
StringCchPrintfW (checkTimeUtc, ARRAYSIZE (checkTimeUtc), L"%04u-%02u-%02uT%02u:%02u:%02uZ",
systemTime.wYear, systemTime.wMonth, systemTime.wDay, systemTime.wHour, systemTime.wMinute, systemTime.wSecond);
WriteEfiBootLoaderDiagnosticsRegistryDword (L"EfiBootChainStatusKnown", status.StatusKnown ? 1 : 0);
WriteEfiBootLoaderDiagnosticsRegistryDword (L"EfiBootChainLastError", chainError);
WriteEfiBootLoaderDiagnosticsRegistryDword (L"EfiBootLoaderFirmwareDbLastError", firmwareDbError);
WriteEfiBootLoaderDiagnosticsRegistryDword (L"EfiBootLoaderFirmwareDbxLastError", firmwareDbxError);
WriteEfiBootLoaderDiagnosticsRegistryDword (L"SecureBootEnabled", status.SecureBootEnabled ? 1 : 0);
WriteEfiBootLoaderDiagnosticsRegistryDword (L"FirmwareDbxPresent", status.FirmwareDbxPresent ? 1 : 0);
WriteEfiBootLoaderDiagnosticsRegistryDword (L"VeraCryptLoaderFilesValid", status.VeraCryptLoaderFilesValid ? 1 : 0);
WriteEfiBootLoaderDiagnosticsRegistryDword (L"VeraCryptLoaderKnownCaAllowed", status.VeraCryptLoaderKnownCaAllowed ? 1 : 0);
WriteEfiBootLoaderDiagnosticsRegistryDword (L"VeraCryptLoaderKnownCaRevoked", status.VeraCryptLoaderKnownCaRevoked ? 1 : 0);
WriteEfiBootLoaderDiagnosticsRegistryDword (L"WindowsLoaderInspectionSucceeded", status.WindowsLoaderInspectionSucceeded ? 1 : 0);
WriteEfiBootLoaderDiagnosticsRegistryDword (L"WindowsLoaderPresent", status.WindowsLoaderPresent ? 1 : 0);
WriteEfiBootLoaderDiagnosticsRegistryDword (L"WindowsLoaderSigner", status.WindowsLoaderSigner);
WriteEfiBootLoaderDiagnosticsRegistryDword (L"WindowsLoaderKnownCaAllowed", status.WindowsLoaderKnownCaAllowed ? 1 : 0);
WriteEfiBootLoaderDiagnosticsRegistryDword (L"WindowsLoaderKnownCaRevoked", status.WindowsLoaderKnownCaRevoked ? 1 : 0);
WriteEfiBootLoaderDiagnosticsRegistryDword (L"WindowsLoaderMigrationRecommended", status.WindowsLoaderMigrationRecommended ? 1 : 0);
WriteEfiBootLoaderDiagnosticsRegistryDword (L"EfiBootLoaderInstalledResourceSet", status.InstalledResourceSet);
WriteEfiBootLoaderDiagnosticsRegistryDword (L"EfiBootLoaderRecordedResourceSet", status.RecordedResourceSet);
RegDeleteKeyValueW (HKEY_LOCAL_MACHINE, EfiBootLoaderDiagnosticsRegistryKey, L"VeraCryptLoaderTrusted");
RegDeleteKeyValueW (HKEY_LOCAL_MACHINE, EfiBootLoaderDiagnosticsRegistryKey, L"VeraCryptLoaderRevoked");
RegDeleteKeyValueW (HKEY_LOCAL_MACHINE, EfiBootLoaderDiagnosticsRegistryKey, L"WindowsLoaderTrusted");
RegDeleteKeyValueW (HKEY_LOCAL_MACHINE, EfiBootLoaderDiagnosticsRegistryKey, L"WindowsLoaderRevoked");
WriteLocalMachineRegistryString (EfiBootLoaderDiagnosticsRegistryKey, L"EfiBootChainCheckTimeUtc", checkTimeUtc, FALSE);
SetLastError (previousLastError);
}
bool BootEncryption::GetEfiBootChainTrustStatus (EfiBootChainTrustStatus& status)
{
memset (&status, 0, sizeof (status));
@@ -6222,57 +6772,122 @@ namespace VeraCrypt
bool bSecureBootEnabled = false;
if (!TryFirmwareSecureBootEnabled (bSecureBootEnabled))
return false;
{
DWORD dwError = GetLastError ();
RecordEfiBootChainTrustStatusDiagnostics (status, dwError);
return true;
}
status.SecureBootEnabled = bSecureBootEnabled;
// Trust facts are only asserted from a fully parsed firmware db: acting on
// partial data could produce false "untrusted" reports.
// Known-CA policy facts are asserted only from fully parsed db and dbx
// variables. This does not model the other UEFI revocation forms (image
// hashes, certificate TBS hashes, and security-version revocations).
FirmwareDbMicrosoftUefiCaSupport support;
if (!TryFirmwareDbGetMicrosoftUefiCaSupport (support) || support.DbMalformed)
return false;
if (!TryFirmwareDbGetMicrosoftUefiCaSupport (support))
{
DWORD dwError = GetLastError ();
RecordEfiBootChainTrustStatusDiagnostics (status, dwError, dwError);
return true;
}
if (support.DbMalformed)
{
DWORD dwError = support.ParseError ? support.ParseError : ERROR_INVALID_DATA;
RecordEfiBootChainTrustStatusDiagnostics (status, dwError, dwError);
return true;
}
FirmwareDbMicrosoftUefiCaSupport forbiddenSupport;
bool bFirmwareDbxPresent = false;
if (!TryFirmwareDbxGetMicrosoftUefiCaSupport (forbiddenSupport, &bFirmwareDbxPresent))
{
DWORD dwError = GetLastError ();
RecordEfiBootChainTrustStatusDiagnostics (status, dwError, ERROR_SUCCESS, dwError);
return true;
}
if (forbiddenSupport.DbMalformed)
{
DWORD dwError = forbiddenSupport.ParseError ? forbiddenSupport.ParseError : ERROR_INVALID_DATA;
RecordEfiBootChainTrustStatusDiagnostics (status, dwError, ERROR_SUCCESS, dwError);
return true;
}
status.FirmwareDbxPresent = bFirmwareDbxPresent;
DWORD recordedResourceSet = 0;
if (!ReadRecordedEfiBootLoaderResourceSet (recordedResourceSet))
return false;
status.InstalledResourceSet = recordedResourceSet;
if (recordedResourceSet == VC_EFI_BOOT_LOADER_RESOURCE_SET_2023)
status.VeraCryptLoaderTrusted = FirmwareDbMicrosoftUefiCaSupportContains2023Set (support);
else if (recordedResourceSet == VC_EFI_BOOT_LOADER_RESOURCE_SET_2011)
status.VeraCryptLoaderTrusted = support.ContainsMicrosoftCorporationUefiCa2011;
else
return false;
if (ReadRecordedEfiBootLoaderResourceSet (recordedResourceSet))
status.RecordedResourceSet = recordedResourceSet;
try
{
EfiBootInst.PrepareBootPartition (true);
// The signer family of the chainloaded Windows boot manager copy is identified by the
// issuer name embedded in its Authenticode certificate table. Like loader-set selection,
// this is a byte-presence heuristic, not a signature verification.
std::vector<uint8> loader;
if (EfiBootInst.ReadFileToBuffer (L"\\EFI\\Microsoft\\Boot\\bootmgfw_ms.vc", loader) && !loader.empty ())
EfiBootLoaderImages images2011 = MapEfiBootLoaderImages (VC_EFI_BOOT_LOADER_RESOURCE_SET_2011, false);
EfiBootLoaderImages images2023 = MapEfiBootLoaderImages (VC_EFI_BOOT_LOADER_RESOURCE_SET_2023, false);
bool bMatches2011 = EfiBootLoaderImagesMatch (EfiBootInst, images2011);
bool bMatches2023 = EfiBootLoaderImagesMatch (EfiBootInst, images2023);
const EfiBootLoaderImages *installedImages = NULL;
if (bMatches2011 != bMatches2023)
{
static const char szWindowsProductionPca2011Name[] = "Microsoft Windows Production PCA 2011";
static const char szWindowsUefiCa2023Name[] = "Windows UEFI CA 2023";
bool bSignedThroughPca2011 = BufferHasPattern (loader.data (), loader.size (), szWindowsProductionPca2011Name, strlen (szWindowsProductionPca2011Name));
bool bSignedThroughWindowsCa2023 = BufferHasPattern (loader.data (), loader.size (), szWindowsUefiCa2023Name, strlen (szWindowsUefiCa2023Name));
installedImages = bMatches2023 ? &images2023 : &images2011;
status.InstalledResourceSet = installedImages->ResourceSet;
status.VeraCryptLoaderFilesValid = EfiBootLoaderStandardCopiesMatch (EfiBootInst, *installedImages);
}
if (bSignedThroughPca2011 || bSignedThroughWindowsCa2023)
if (status.VeraCryptLoaderFilesValid && status.InstalledResourceSet == VC_EFI_BOOT_LOADER_RESOURCE_SET_2023)
{
status.VeraCryptLoaderKnownCaRevoked = forbiddenSupport.ContainsMicrosoftUefiCa2023
|| forbiddenSupport.ContainsMicrosoftOptionRomUefiCa2023;
status.VeraCryptLoaderKnownCaAllowed = FirmwareDbMicrosoftUefiCaSupportContains2023Set (support)
&& !status.VeraCryptLoaderKnownCaRevoked;
}
else if (status.VeraCryptLoaderFilesValid && status.InstalledResourceSet == VC_EFI_BOOT_LOADER_RESOURCE_SET_2011)
{
status.VeraCryptLoaderKnownCaRevoked = forbiddenSupport.ContainsMicrosoftCorporationUefiCa2011;
status.VeraCryptLoaderKnownCaAllowed = support.ContainsMicrosoftCorporationUefiCa2011
&& !status.VeraCryptLoaderKnownCaRevoked;
}
status.WindowsLoaderPresent = EfiBootInst.FileExists (L"\\EFI\\Microsoft\\Boot\\bootmgfw_ms.vc");
if (status.WindowsLoaderPresent)
{
std::vector<uint8> loader;
if (EfiBootInst.ReadFileToBuffer (L"\\EFI\\Microsoft\\Boot\\bootmgfw_ms.vc", loader) && !loader.empty ())
{
status.WindowsLoaderSignerKnown = true;
status.WindowsLoaderTrusted =
(bSignedThroughPca2011 && support.ContainsMicrosoftWindowsProductionPca2011)
|| (bSignedThroughWindowsCa2023 && support.ContainsWindowsUefiCa2023);
static const char windowsBootManagerMarker[] = "bootmgfw.pdb";
status.WindowsLoaderInspectionSucceeded = !BufferHasVeraCryptBootLoaderPattern (loader)
&& BufferHasPattern (loader.data (), loader.size (), windowsBootManagerMarker, strlen (windowsBootManagerMarker))
&& GetEmbeddedPeSignerFamily (loader, status.WindowsLoaderSigner);
if (status.WindowsLoaderInspectionSucceeded)
{
status.WindowsLoaderSignerKnown = status.WindowsLoaderSigner == VC_EFI_WINDOWS_LOADER_SIGNER_PCA_2011
|| status.WindowsLoaderSigner == VC_EFI_WINDOWS_LOADER_SIGNER_CA_2023;
if (status.WindowsLoaderSigner == VC_EFI_WINDOWS_LOADER_SIGNER_PCA_2011)
{
status.WindowsLoaderKnownCaRevoked = forbiddenSupport.ContainsMicrosoftWindowsProductionPca2011;
status.WindowsLoaderKnownCaAllowed = support.ContainsMicrosoftWindowsProductionPca2011
&& !status.WindowsLoaderKnownCaRevoked;
status.WindowsLoaderMigrationRecommended = status.WindowsLoaderKnownCaAllowed
&& support.ContainsWindowsUefiCa2023;
}
else if (status.WindowsLoaderSigner == VC_EFI_WINDOWS_LOADER_SIGNER_CA_2023)
{
status.WindowsLoaderKnownCaRevoked = forbiddenSupport.ContainsWindowsUefiCa2023;
status.WindowsLoaderKnownCaAllowed = support.ContainsWindowsUefiCa2023
&& !status.WindowsLoaderKnownCaRevoked;
}
}
}
}
}
catch (...)
{
// The EFI system partition could not be inspected; the VeraCrypt loader facts above remain valid.
// The EFI system partition could not be inspected; the known CA facts above remain valid.
status.VeraCryptLoaderFilesValid = false;
status.WindowsLoaderInspectionSucceeded = false;
}
status.StatusKnown = true;
RecordEfiBootChainTrustStatusDiagnostics (status);
return true;
}
+17 -7
View File
@@ -232,16 +232,26 @@ namespace VeraCrypt
std::wstring BootVolumePath;
};
// Trust facts about the installed EFI boot chain, derived from the active Secure Boot db.
// Only valid when StatusKnown is true: partial or malformed firmware data never asserts facts.
// Known-CA compatibility facts for the installed EFI boot chain. UEFI dbx can
// also revoke individual image hashes, certificate TBS hashes, or security
// versions, so these fields deliberately do not claim complete firmware trust.
struct EfiBootChainTrustStatus
{
bool StatusKnown; // Secure Boot state read and firmware db parsed completely
bool StatusKnown; // Secure Boot state read and firmware db/dbx CA entries parsed completely
bool SecureBootEnabled;
bool VeraCryptLoaderTrusted; // signing CA(s) of the installed VeraCrypt EFI loader set found in db
bool WindowsLoaderSignerKnown; // signer family of EFI\Microsoft\Boot\bootmgfw_ms.vc identified
bool WindowsLoaderTrusted; // signing CA of bootmgfw_ms.vc found in db
DWORD InstalledResourceSet; // VC_EFI_BOOT_LOADER_RESOURCE_SET_2011 or VC_EFI_BOOT_LOADER_RESOURCE_SET_2023
bool FirmwareDbxPresent; // false is valid and means the optional dbx variable is absent
bool VeraCryptLoaderFilesValid; // installed DCS files and any VeraCrypt standard-path copies match one embedded set
bool VeraCryptLoaderKnownCaAllowed; // required signing CA(s) found in db and no matching CA found in dbx
bool VeraCryptLoaderKnownCaRevoked; // at least one required signing CA found in dbx
bool WindowsLoaderInspectionSucceeded; // file read and embedded Authenticode signature parsed
bool WindowsLoaderPresent; // EFI\Microsoft\Boot\bootmgfw_ms.vc exists
bool WindowsLoaderSignerKnown; // embedded signer family of bootmgfw_ms.vc identified
bool WindowsLoaderKnownCaAllowed; // signing CA found in db and no matching CA found in dbx
bool WindowsLoaderKnownCaRevoked; // signing CA of bootmgfw_ms.vc found in dbx
bool WindowsLoaderMigrationRecommended; // PCA 2011 copy remains while Windows UEFI CA 2023 is available
DWORD WindowsLoaderSigner; // VC_EFI_WINDOWS_LOADER_SIGNER_* value
DWORD InstalledResourceSet; // resource set identified from the actual installed DCS files
DWORD RecordedResourceSet; // last resource set recorded at installation/refresh time
};
class BootEncryption
+3
View File
@@ -89,6 +89,9 @@ enum
#define VC_EFI_BOOT_LOADER_RESCUE_DISK_PROMPT_ID_VALUE_NAME L"EfiBootLoaderRescueDiskPromptId"
#define VC_EFI_BOOT_LOADER_RESCUE_DISK_PROMPT_RESOURCE_SET_VALUE_NAME L"EfiBootLoaderRescueDiskPromptResourceSet"
#define VC_EFI_BOOT_LOADER_RESCUE_DISK_RESOURCE_SET_VALUE_NAME L"EfiBootLoaderRescueDiskResourceSet"
#define VC_EFI_WINDOWS_LOADER_SIGNER_UNKNOWN 0
#define VC_EFI_WINDOWS_LOADER_SIGNER_PCA_2011 2011
#define VC_EFI_WINDOWS_LOADER_SIGNER_CA_2023 2023
#define VC_ERROR_EFI_UNSUPPORTED_SECURE_BOOT_DB ((DWORD) 0xE0000201)
#define VC_FILENAME_RENAMED_SUFFIX L"_old"
+4 -3
View File
@@ -1685,11 +1685,12 @@
<entry lang="en" key="MACOSX_APFS_EROFS_HINT">macOS reported the selected device as read-only. If this is an APFS disk, make sure you selected the physical APFS store partition, not an APFS synthesized volume. Use Disk Utility or 'diskutil list' to identify the physical partition, then retry.</entry>
<entry lang="en" key="FAVORITE_PIM_OR_KDF_CHANGED">This volume is registered as a System Favorite and its PIM and/or KDF settings were changed.\nDo you want VeraCrypt to automatically update the System Favorite configuration (administrator privileges required)?\n\nPlease note that if you answer no, you'll have to update the System Favorite manually.</entry>
<entry lang="en" key="PIM_RESET_ON_KDF_CHANGE_CONFIRM">The selected KDF uses different PIM parameters, so VeraCrypt will not reuse the current custom PIM. The new volume header will use the default PIM for the selected KDF unless you select "Use PIM" in the New section and enter a custom value.\n\nDo you want to continue?</entry>
<entry lang="en" key="SYSENC_EFI_UNSUPPORTED_SECUREBOOT_CA">Secure Boot is enabled, but the firmware Secure Boot database does not trust any Microsoft UEFI CA set supported by VeraCrypt's EFI bootloader. Enable either Microsoft Corporation UEFI CA 2011, or both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023, then run VeraCrypt Repair/Reinstall. Alternatively, disable Secure Boot.</entry>
<entry lang="en" key="SYSENC_EFI_UNSUPPORTED_SECUREBOOT_CA">VeraCrypt could not confirm that an EFI bootloader set is compatible with the current Secure Boot configuration. A required Microsoft CA may be missing from db or listed by dbx, or a firmware variable may be unreadable or malformed. An absent dbx variable is valid; a nonzero dbx diagnostic error is not.\n\nEnable either Microsoft Corporation UEFI CA 2011, or both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023, and run VeraCrypt Repair/Reinstall. Keep Secure Boot disabled until the diagnostics show a complete compatible assessment.</entry>
<entry lang="en" key="MACOSX_CHECK_FILESYS">A Terminal window will open after you press 'OK' and check the file system on the selected VeraCrypt volume using 'diskutil'. The result will be shown in that window.\n\nIf the check cannot be started, Disk Utility will be launched instead.</entry>
<entry lang="en" key="MACOSX_REPAIR_FILESYS">A Terminal window will open after you press 'OK' and attempt to repair the file system on the selected VeraCrypt volume using 'diskutil'. The result will be shown in that window.\n\nIf the repair cannot be started, Disk Utility will be launched instead.</entry>
<entry lang="en" key="SYSENC_EFI_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: Secure Boot is enabled, but the Microsoft UEFI CA that signs the installed VeraCrypt EFI bootloader was not found in the firmware Secure Boot database (db). The firmware may refuse to start VeraCrypt at the next reboot, so Windows will not start until Secure Boot is disabled or the trusted certificates/loader set are repaired.\n\nBefore restarting this computer, do not disable or remove Microsoft Corporation UEFI CA 2011 unless the firmware db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and VeraCrypt has been repaired/reinstalled so the 2023-signed loader set is installed. Enable the required Microsoft certificates in the BIOS/UEFI settings if needed, then run VeraCrypt Repair/Reinstall. Make sure you have an up-to-date VeraCrypt Rescue Disk before restarting.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: Secure Boot is enabled, but the Microsoft CA that signs the Windows Boot Manager copy used by VeraCrypt (bootmgfw_ms.vc) was not found in the firmware Secure Boot database (db). After successful pre-boot authentication, the handoff to Windows may fail and the computer may return to the VeraCrypt password prompt.\n\nBefore restarting this computer, do not disable or revoke Microsoft Windows Production PCA 2011 unless Windows Boot Manager has migrated to a Windows UEFI CA 2023-signed version and the firmware db contains Windows UEFI CA 2023. Apply the Windows Secure Boot certificate updates, then run VeraCrypt Repair/Reinstall if needed. Make sure you have an up-to-date VeraCrypt Rescue Disk before restarting.</entry>
<entry lang="en" key="SYSENC_EFI_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: VeraCrypt could not validate the installed EFI bootloader files against one complete embedded resource set and confirm that all known required signing CAs are present in db and not listed by dbx. Firmware may reject VeraCrypt when Secure Boot is enabled.\n\nBefore booting with Secure Boot enabled, restore the required Microsoft certificates and current dbx as needed, then run VeraCrypt Repair/Reinstall. Do not remove Microsoft Corporation UEFI CA 2011 until db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and the actual installed files match VeraCrypt's 2023 set. This check cannot model every image-hash or security-version revocation. Make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_NOT_TRUSTED_BY_SECUREBOOT">Warning: VeraCrypt could not validate the embedded signature and known-CA compatibility of the Windows Boot Manager it chainloads (bootmgfw_ms.vc). The file may be missing, unreadable, not a Windows Boot Manager, have an unrecognized embedded signer, or use a known signing CA that is absent from db or listed by dbx. The handoff to Windows may fail when Secure Boot is enabled.\n\nComplete or repair the Windows Secure Boot certificate and boot-manager update, keep the VeraCrypt System Favorites service enabled, and run VeraCrypt Repair/Reinstall. Repair also checks Windows' serviced EFI_EX/EFI copies for a compatible current Boot Manager. If Windows cannot start, temporarily disable Secure Boot to recover. Make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
<entry lang="en" key="SYSENC_EFI_WINDOWS_LOADER_PCA2011_MIGRATION_NEEDED">Warning: The embedded signature of the Windows Boot Manager used by VeraCrypt (bootmgfw_ms.vc) is still issued by Microsoft Windows Production PCA 2011, although firmware db already contains Windows UEFI CA 2023. Its known CA is currently allowed, but it will no longer start after the PCA 2011 certificate is added to dbx.\n\nDo not apply the PCA 2011 revocation (AvailableUpdates bit 0x80, including combined value 0x280) yet. First complete the Windows 2023 boot-manager update while the VeraCrypt System Favorites service is enabled, then run VeraCrypt Repair/Reinstall so VeraCrypt can import a compatible serviced EFI_EX/EFI copy. Verify the embedded issuer of bootmgfw_ms.vc is Windows UEFI CA 2023 and make sure you have an up-to-date VeraCrypt Rescue Disk.</entry>
</localization>
<xs:schema attributeFormDefault="unqualified" elementFormDefault="qualified" xmlns:xs="http://www.w3.org/2001/XMLSchema">
<xs:element name="VeraCrypt">
+39 -9
View File
@@ -10836,7 +10836,7 @@ static void SystemFavoritesServiceLogBootLoaderUpdateError (const wchar_t *opera
{
if (IsUnsupportedEfiSecureBootDbException (e))
{
SystemFavoritesServiceLogError (wstring (operation) + L" failed: Secure Boot is enabled, but the firmware Secure Boot db does not trust any Microsoft UEFI CA set supported by VeraCrypt. See HKLM\\SOFTWARE\\VeraCrypt\\Diagnostics\\EfiBootLoader for the recorded selection reason.");
SystemFavoritesServiceLogError (wstring (operation) + L" failed: Secure Boot is enabled, but the firmware Secure Boot db/dbx policy does not permit a Microsoft UEFI CA set supported by VeraCrypt, or the policy could not be read completely. See HKLM\\SOFTWARE\\VeraCrypt\\Diagnostics\\EfiBootLoader for the recorded selection reason.");
return;
}
@@ -10881,6 +10881,15 @@ static BOOL GetSystemFavoritesServiceBootLoaderUpdateOptions (uint32 serviceFlag
return TRUE;
}
enum
{
VC_EFI_BOOT_CHAIN_WARNING_VERACRYPT_LOADER = 0x01,
VC_EFI_BOOT_CHAIN_WARNING_WINDOWS_LOADER = 0x02,
VC_EFI_BOOT_CHAIN_WARNING_WINDOWS_MIGRATION = 0x04
};
static DWORD SystemFavoritesServiceLastEfiBootChainWarningMask = MAXDWORD;
static void SystemFavoritesServiceUpdateLoaderProcessing (BOOL bForce)
{
SystemFavoritesServiceLogInfo (L"SystemFavoritesServiceUpdateLoaderProcessing called");
@@ -10901,18 +10910,39 @@ static void SystemFavoritesServiceUpdateLoaderProcessing (BOOL bForce)
bootEnc.InstallBootLoader (true);
SystemFavoritesServiceLogInfo (L"SystemFavoritesServiceUpdateLoaderProcessing: InstallBootLoader called");
// Record in the event log when the active Secure Boot db no longer trusts a
// component of the boot chain (e.g. after a Secure Boot certificate update),
// so that a subsequent pre-boot failure can be diagnosed from Windows.
// Record actual-file and known-CA compatibility failures so a subsequent
// firmware-enforced pre-boot failure can be diagnosed from Windows.
try
{
EfiBootChainTrustStatus trustStatus;
if (bootEnc.GetEfiBootChainTrustStatus (trustStatus) && trustStatus.StatusKnown && trustStatus.SecureBootEnabled)
if (bootEnc.GetEfiBootChainTrustStatus (trustStatus))
{
if (!trustStatus.VeraCryptLoaderTrusted)
SystemFavoritesServiceLogWarning (L"Secure Boot chain check: the firmware Secure Boot db does not trust the Microsoft UEFI CA that signs the installed VeraCrypt EFI bootloader. Pre-boot authentication may fail at the next reboot.");
else if (trustStatus.WindowsLoaderSignerKnown && !trustStatus.WindowsLoaderTrusted)
SystemFavoritesServiceLogWarning (L"Secure Boot chain check: the firmware Secure Boot db does not trust the Microsoft CA that signs the Windows boot manager copy used by VeraCrypt (bootmgfw_ms.vc). The handoff to Windows after pre-boot authentication may fail at the next reboot.");
DWORD warningMask = 0;
if (!trustStatus.StatusKnown
|| !trustStatus.VeraCryptLoaderFilesValid
|| !trustStatus.VeraCryptLoaderKnownCaAllowed)
warningMask |= VC_EFI_BOOT_CHAIN_WARNING_VERACRYPT_LOADER;
if (trustStatus.StatusKnown && (!trustStatus.WindowsLoaderInspectionSucceeded
|| !trustStatus.WindowsLoaderPresent
|| !trustStatus.WindowsLoaderSignerKnown
|| !trustStatus.WindowsLoaderKnownCaAllowed))
warningMask |= VC_EFI_BOOT_CHAIN_WARNING_WINDOWS_LOADER;
else if (trustStatus.StatusKnown && trustStatus.WindowsLoaderMigrationRecommended)
warningMask |= VC_EFI_BOOT_CHAIN_WARNING_WINDOWS_MIGRATION;
// The service refreshes the loader at several lifecycle events. Emit each
// unchanged warning state only once per service process to avoid log spam.
if (warningMask != SystemFavoritesServiceLastEfiBootChainWarningMask)
{
if (warningMask & VC_EFI_BOOT_CHAIN_WARNING_VERACRYPT_LOADER)
SystemFavoritesServiceLogWarning (L"Secure Boot compatibility check: VeraCrypt could not validate the installed DCS files against an embedded loader set and confirm that its known signing CAs are allowed by db and not listed by dbx. Do not boot with Secure Boot enabled until the policy and loader set have been repaired.");
if (warningMask & VC_EFI_BOOT_CHAIN_WARNING_WINDOWS_LOADER)
SystemFavoritesServiceLogWarning (L"Secure Boot compatibility check: the Windows boot manager used by VeraCrypt (bootmgfw_ms.vc) is missing or unreadable, its embedded signer is unrecognized, or its known signing CA is not allowed by db or is listed by dbx. The handoff to Windows may fail when Secure Boot is enabled.");
else if (warningMask & VC_EFI_BOOT_CHAIN_WARNING_WINDOWS_MIGRATION)
SystemFavoritesServiceLogWarning (L"Secure Boot transition check: bootmgfw_ms.vc is still signed by Microsoft Windows Production PCA 2011 although firmware db already contains Windows UEFI CA 2023. Complete the Windows 2023 boot manager update before applying the PCA 2011 dbx revocation.");
SystemFavoritesServiceLastEfiBootChainWarningMask = warningMask;
}
}
}
catch (...) { }
+13 -6
View File
@@ -1799,18 +1799,25 @@ BOOL UpgradeBootLoader (HWND hwndDlg)
bootEnc.InstallBootLoader (true);
// Verify the whole boot chain against the active Secure Boot db before the user
// reboots: a component that the firmware no longer trusts (e.g. after a Secure Boot
// certificate update) would otherwise only surface as a pre-boot failure.
// Validate the actual boot files and their known-CA compatibility with the active
// Secure Boot db/dbx before the user reboots. Other dbx revocation forms remain
// firmware-enforced and cannot be completely predicted here.
try
{
EfiBootChainTrustStatus trustStatus;
if (bootEnc.GetEfiBootChainTrustStatus (trustStatus) && trustStatus.StatusKnown && trustStatus.SecureBootEnabled)
if (bootEnc.GetEfiBootChainTrustStatus (trustStatus))
{
if (!trustStatus.VeraCryptLoaderTrusted)
if (!trustStatus.StatusKnown)
Warning ("SYSENC_EFI_UNSUPPORTED_SECUREBOOT_CA", hwndDlg);
else if (!trustStatus.VeraCryptLoaderFilesValid || !trustStatus.VeraCryptLoaderKnownCaAllowed)
Warning ("SYSENC_EFI_LOADER_NOT_TRUSTED_BY_SECUREBOOT", hwndDlg);
else if (trustStatus.WindowsLoaderSignerKnown && !trustStatus.WindowsLoaderTrusted)
if (trustStatus.StatusKnown && (!trustStatus.WindowsLoaderInspectionSucceeded
|| !trustStatus.WindowsLoaderPresent
|| !trustStatus.WindowsLoaderSignerKnown
|| !trustStatus.WindowsLoaderKnownCaAllowed))
Warning ("SYSENC_EFI_WINDOWS_LOADER_NOT_TRUSTED_BY_SECUREBOOT", hwndDlg);
else if (trustStatus.StatusKnown && trustStatus.WindowsLoaderMigrationRecommended)
Warning ("SYSENC_EFI_WINDOWS_LOADER_PCA2011_MIGRATION_NEEDED", hwndDlg);
}
}
catch (...) { }
+12 -6
View File
@@ -1826,9 +1826,8 @@ BOOL UpgradeBootLoader_Dll (MSIHANDLE hInstaller, HWND hwndDlg)
// this is done by the service now
//bootEnc.InstallBootLoader (true);
// Verify the installed boot chain against the active Secure Boot db before the user
// reboots: a component that the firmware no longer trusts (e.g. after a Secure Boot
// certificate update) would otherwise only surface as a pre-boot failure. In the MSI
// Validate the installed boot files and their known-CA compatibility with the active
// Secure Boot db/dbx before the user reboots. In the MSI
// upgrade path, the System Favorites service has already attempted the loader refresh.
try
{
@@ -1839,12 +1838,19 @@ BOOL UpgradeBootLoader_Dll (MSIHANDLE hInstaller, HWND hwndDlg)
else
{
EfiBootChainTrustStatus trustStatus;
if (bootEnc.GetEfiBootChainTrustStatus (trustStatus) && trustStatus.StatusKnown && trustStatus.SecureBootEnabled)
if (bootEnc.GetEfiBootChainTrustStatus (trustStatus))
{
if (!trustStatus.VeraCryptLoaderTrusted)
if (!trustStatus.StatusKnown)
MSILogAndShow (hInstaller, MSI_WARNING_LEVEL, GetString("SYSENC_EFI_UNSUPPORTED_SECUREBOOT_CA"));
else if (!trustStatus.VeraCryptLoaderFilesValid || !trustStatus.VeraCryptLoaderKnownCaAllowed)
MSILogAndShow (hInstaller, MSI_WARNING_LEVEL, GetString("SYSENC_EFI_LOADER_NOT_TRUSTED_BY_SECUREBOOT"));
else if (trustStatus.WindowsLoaderSignerKnown && !trustStatus.WindowsLoaderTrusted)
if (trustStatus.StatusKnown && (!trustStatus.WindowsLoaderInspectionSucceeded
|| !trustStatus.WindowsLoaderPresent
|| !trustStatus.WindowsLoaderSignerKnown
|| !trustStatus.WindowsLoaderKnownCaAllowed))
MSILogAndShow (hInstaller, MSI_WARNING_LEVEL, GetString("SYSENC_EFI_WINDOWS_LOADER_NOT_TRUSTED_BY_SECUREBOOT"));
else if (trustStatus.StatusKnown && trustStatus.WindowsLoaderMigrationRecommended)
MSILogAndShow (hInstaller, MSI_WARNING_LEVEL, GetString("SYSENC_EFI_WINDOWS_LOADER_PCA2011_MIGRATION_NEEDED"));
}
}
}