News: 1592207652

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Windows Server to require TPM2.0 and Secure boot by default in future release

(2020/06/15)


Microsoft has [1]announced that the next “major release” of Windows Server will require TPM 2.0 and Secure Boot installed and enabled by default.

“These requirements apply to servers where Windows Server will run, including bare metal, virtual machines (guests) running on Hyper-V or on third party hypervisors approved through the Server Virtualization Validation Program (SVVP),” writes Microsoft’s Windows Server Team.

“Looking ahead, Secure boot and TPM2.0 will serve as the core building blocks for Windows Server security and provide customers with strengthened baseline security for systems available from the ecosystem,” Microsoft’s post adds. “The enforcement of these requirements will be applied to new server platforms introduced to market after January 1, 2021.”

It's hard to argue against the change because Secure boot is a more-than-useful way of ensuring that servers boot into know and trusted environments. TPM2.0 has been all-but-standard since 2016 for PCs. Making it a requirement for the sensitive jobs Windows Server is asked to undertake ought not to be controversial.

There is, of course, some pain in this announcement because it will limit upgrade paths for some users.

But Microsoft appears to know this as its post says: “Existing server platforms will include Additional Qualification certification to help customers identify systems that meet these requirements, similar to the current Assurance AQ for Windows Server 2019 today.”

However the post doesn’t offer any detail about whether the “major release” of Windows Server 2019 it mentions is the H2 update that users of the semi-annual channel expect in a few months, or something else. ®

Sponsored: [2]Google Security Whitepaper



[1] https://cloudblogs.microsoft.com/windowsserver/2020/06/11/microsoft-raises-the-security-standard-for-next-major-windows-server-release/

[2] https://go.theregister.com/tl/1956/-8471/google-security-whitepaper?td=wptl1956

Well now....

Maelstorm

Well now, this may push administrators to alternate operating systems such as Linux. Not every IT department can afford new server hardware every year. Many IT departments are cash strapped as it is. Now to mandate new hardware when upgrading an operating system is a joke.

Re: Well now....

Steve Davies 3

Or... they will stick with the old version(s) of server until the budgets allow the purchase of new hardware. To enforce this in VM's is a bit rich. Companies will want to test their back end systems and doing it in a VM makes perfect sense until... Sorry MS this is another fail. IT departments need at least 3 years notice of this sort of change.

Oh wait!

They'll be pressurising bare metal customers to go all cloudy starting tomorrow. "we have all the required hardware ready to go. Sign here (says the Devil)

I wish MS would get it through their thick heads that some systems really don't work if the server is in the cloud. Would you trust an Oil refinery control system to run inside some Azure Cloud somewhere on the planet?

No, you would not. The control system will hopefully be air-gapped at least once from the internet.

Re: Well now....

big_D

Same in many production environments. I used to work for a software company that used software to control PLCs. From the time of receiving an RFID tag on a meat hook, the software had around 20 milliseconds to tell the PLC which lane to push the tag to, before it reached the switch.

Re: Well now....

Dave Pickles

But how do you install Linux if new servers come with compulsory Secure Boot?

Re: Well now....

karlkarl

It is not "Compulsory", it is "Default". Proper hardware will allow you to turn it off.

Microsoft is a niche product in the server market, no sane hardware manufacturer would arrive at the conclusion that a compulsory secure boot is a good idea. The money that Microsoft (possibly illegally) pays them to do so would still not justify it unlike the desktop space.

Re: Well now....

DCdave

It's hardly "every year", just next year and as the article says, TPM 2.0 has been around for a few years in hardware.

On top of that, Server 2016 LTS will still be around for a while yet, 2019 LTS even longer.

And if that weren't enough, a hypervisor can almost certainly emulate it for you.

Re: Well now....

Steve K

I don't know whether that is correct.

TPM 2.0 has been around for a while now so most recent (x64) server hardware will have it built-in (or a TPM slot for an add-in card) even if it may not be enabled.

Stuart Castle

Although it you are supporting a reasonably large system, it may well cost more to switch to an alternate (once you include things like re-training, the cost of migration, support and even potentially redesigning aspects of the system). Don't get me wrong. I know that Linux is perfectly capable of doing anything in the Data Centre that Windows Server can. I also know it is the primary OS in hundreds of thousands of Data Centres (including Google), but I am making that point that in any reasonably large system upgrade, the cost of the hardware and software is a small percentage of the total cost.

[email protected]

Microsoft have already cooked their goose in the SaaS/Data centre market by charging so much for SQL Server. Enterprise SQL Server can cost you £1000s/month when PostgreSQL costs zero for the license and zero for the OS (Centos) - so requiring Secure Boot is just a marketing statement. If bad actor is in the position to be physically present at your server in your data centre then the least of your worries will be booting Windows.

Anonymous Coward

"so requiring Secure Boot is just a marketing statement. If bad actor is in the position to be physically present at your server in your data centre then the least of your worries will be booting Windows."

What does being physically present have to do with what secure boot does?

[email protected]

Because if they can remotely access your boot sector and change boot device then you're already well and truly compromised and will have had your pants pulled down.

I hope you're not pretending to be evil while secretly being good.
That would be dishonest.