diff --git a/Translations/Language.ar.xml b/Translations/Language.ar.xml index ecd60594af..32e93f62e4 100644 --- a/Translations/Language.ar.xml +++ b/Translations/Language.ar.xml @@ -1691,6 +1691,9 @@ Warning: VeraCrypt could not validate the installed EFI bootloader files against one complete embedded resource set and confirm that all known required signing CAs are present in db and not listed by dbx. Firmware may reject VeraCrypt when Secure Boot is enabled.\n\nBefore booting with Secure Boot enabled, restore the required Microsoft certificates and current dbx as needed, then run VeraCrypt Repair/Reinstall. Do not remove Microsoft Corporation UEFI CA 2011 until db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and the actual installed files match VeraCrypt's 2023 set. This check cannot model every image-hash or security-version revocation. Make sure you have an up-to-date VeraCrypt Rescue Disk. Warning: VeraCrypt could not validate the embedded signature and known-CA compatibility of the Windows Boot Manager it chainloads (bootmgfw_ms.vc). The file may be missing, unreadable, not a Windows Boot Manager, have an unrecognized embedded signer, or use a known signing CA that is absent from db or listed by dbx. The handoff to Windows may fail when Secure Boot is enabled.\n\nComplete or repair the Windows Secure Boot certificate and boot-manager update, keep the VeraCrypt System Favorites service enabled, and run VeraCrypt Repair/Reinstall. Repair also checks Windows' serviced EFI_EX/EFI copies for a compatible current Boot Manager. If Windows cannot start, temporarily disable Secure Boot to recover. Make sure you have an up-to-date VeraCrypt Rescue Disk. Warning: The embedded signature of the Windows Boot Manager used by VeraCrypt (bootmgfw_ms.vc) is still issued by Microsoft Windows Production PCA 2011, although firmware db already contains Windows UEFI CA 2023. Its known CA is currently allowed, but it will no longer start after the PCA 2011 certificate is added to dbx.\n\nDo not apply the PCA 2011 revocation (AvailableUpdates bit 0x80, including combined value 0x280) yet. First complete the Windows 2023 boot-manager update while the VeraCrypt System Favorites service is enabled, then run VeraCrypt Repair/Reinstall so VeraCrypt can import a compatible serviced EFI_EX/EFI copy. Verify the embedded issuer of bootmgfw_ms.vc is Windows UEFI CA 2023 and make sure you have an up-to-date VeraCrypt Rescue Disk. + Outer p&assword: + Operation failed while hidden volume protection was enabled.\n\nUse the OUTER volume password, PIM, KDF, and keyfile(s), if any, in the main password dialog. Use the HIDDEN volume password, PIM, KDF, and keyfile(s), if any, in Mount Options > Hidden Volume Protection.\n\nOne or more credentials may be incorrect, or the volume may be invalid or unsupported. + OUTER volume (this dialog): password, PIM, KDF, and keyfile(s).\nHIDDEN volume (Mount Options): password, PIM, KDF, and keyfile(s). diff --git a/Translations/Language.be.xml b/Translations/Language.be.xml index 873dcd105d..da91d013ff 100644 --- a/Translations/Language.be.xml +++ b/Translations/Language.be.xml @@ -1691,6 +1691,9 @@ Warning: VeraCrypt could not validate the installed EFI bootloader files against one complete embedded resource set and confirm that all known required signing CAs are present in db and not listed by dbx. Firmware may reject VeraCrypt when Secure Boot is enabled.\n\nBefore booting with Secure Boot enabled, restore the required Microsoft certificates and current dbx as needed, then run VeraCrypt Repair/Reinstall. Do not remove Microsoft Corporation UEFI CA 2011 until db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and the actual installed files match VeraCrypt's 2023 set. This check cannot model every image-hash or security-version revocation. Make sure you have an up-to-date VeraCrypt Rescue Disk. Warning: VeraCrypt could not validate the embedded signature and known-CA compatibility of the Windows Boot Manager it chainloads (bootmgfw_ms.vc). The file may be missing, unreadable, not a Windows Boot Manager, have an unrecognized embedded signer, or use a known signing CA that is absent from db or listed by dbx. The handoff to Windows may fail when Secure Boot is enabled.\n\nComplete or repair the Windows Secure Boot certificate and boot-manager update, keep the VeraCrypt System Favorites service enabled, and run VeraCrypt Repair/Reinstall. Repair also checks Windows' serviced EFI_EX/EFI copies for a compatible current Boot Manager. If Windows cannot start, temporarily disable Secure Boot to recover. Make sure you have an up-to-date VeraCrypt Rescue Disk. Warning: The embedded signature of the Windows Boot Manager used by VeraCrypt (bootmgfw_ms.vc) is still issued by Microsoft Windows Production PCA 2011, although firmware db already contains Windows UEFI CA 2023. Its known CA is currently allowed, but it will no longer start after the PCA 2011 certificate is added to dbx.\n\nDo not apply the PCA 2011 revocation (AvailableUpdates bit 0x80, including combined value 0x280) yet. First complete the Windows 2023 boot-manager update while the VeraCrypt System Favorites service is enabled, then run VeraCrypt Repair/Reinstall so VeraCrypt can import a compatible serviced EFI_EX/EFI copy. Verify the embedded issuer of bootmgfw_ms.vc is Windows UEFI CA 2023 and make sure you have an up-to-date VeraCrypt Rescue Disk. + Outer p&assword: + Operation failed while hidden volume protection was enabled.\n\nUse the OUTER volume password, PIM, KDF, and keyfile(s), if any, in the main password dialog. Use the HIDDEN volume password, PIM, KDF, and keyfile(s), if any, in Mount Options > Hidden Volume Protection.\n\nOne or more credentials may be incorrect, or the volume may be invalid or unsupported. + OUTER volume (this dialog): password, PIM, KDF, and keyfile(s).\nHIDDEN volume (Mount Options): password, PIM, KDF, and keyfile(s). diff --git a/Translations/Language.bg.xml b/Translations/Language.bg.xml index a8ae4f764f..9919118b5b 100644 --- a/Translations/Language.bg.xml +++ b/Translations/Language.bg.xml @@ -1691,6 +1691,9 @@ Warning: VeraCrypt could not validate the installed EFI bootloader files against one complete embedded resource set and confirm that all known required signing CAs are present in db and not listed by dbx. Firmware may reject VeraCrypt when Secure Boot is enabled.\n\nBefore booting with Secure Boot enabled, restore the required Microsoft certificates and current dbx as needed, then run VeraCrypt Repair/Reinstall. Do not remove Microsoft Corporation UEFI CA 2011 until db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and the actual installed files match VeraCrypt's 2023 set. This check cannot model every image-hash or security-version revocation. Make sure you have an up-to-date VeraCrypt Rescue Disk. Warning: VeraCrypt could not validate the embedded signature and known-CA compatibility of the Windows Boot Manager it chainloads (bootmgfw_ms.vc). The file may be missing, unreadable, not a Windows Boot Manager, have an unrecognized embedded signer, or use a known signing CA that is absent from db or listed by dbx. The handoff to Windows may fail when Secure Boot is enabled.\n\nComplete or repair the Windows Secure Boot certificate and boot-manager update, keep the VeraCrypt System Favorites service enabled, and run VeraCrypt Repair/Reinstall. Repair also checks Windows' serviced EFI_EX/EFI copies for a compatible current Boot Manager. If Windows cannot start, temporarily disable Secure Boot to recover. Make sure you have an up-to-date VeraCrypt Rescue Disk. Warning: The embedded signature of the Windows Boot Manager used by VeraCrypt (bootmgfw_ms.vc) is still issued by Microsoft Windows Production PCA 2011, although firmware db already contains Windows UEFI CA 2023. Its known CA is currently allowed, but it will no longer start after the PCA 2011 certificate is added to dbx.\n\nDo not apply the PCA 2011 revocation (AvailableUpdates bit 0x80, including combined value 0x280) yet. First complete the Windows 2023 boot-manager update while the VeraCrypt System Favorites service is enabled, then run VeraCrypt Repair/Reinstall so VeraCrypt can import a compatible serviced EFI_EX/EFI copy. Verify the embedded issuer of bootmgfw_ms.vc is Windows UEFI CA 2023 and make sure you have an up-to-date VeraCrypt Rescue Disk. + Outer p&assword: + Operation failed while hidden volume protection was enabled.\n\nUse the OUTER volume password, PIM, KDF, and keyfile(s), if any, in the main password dialog. Use the HIDDEN volume password, PIM, KDF, and keyfile(s), if any, in Mount Options > Hidden Volume Protection.\n\nOne or more credentials may be incorrect, or the volume may be invalid or unsupported. + OUTER volume (this dialog): password, PIM, KDF, and keyfile(s).\nHIDDEN volume (Mount Options): password, PIM, KDF, and keyfile(s). diff --git a/Translations/Language.ca.xml b/Translations/Language.ca.xml index 7cda0b4214..1811a3f15a 100644 --- a/Translations/Language.ca.xml +++ b/Translations/Language.ca.xml @@ -1691,6 +1691,9 @@ Warning: VeraCrypt could not validate the installed EFI bootloader files against one complete embedded resource set and confirm that all known required signing CAs are present in db and not listed by dbx. Firmware may reject VeraCrypt when Secure Boot is enabled.\n\nBefore booting with Secure Boot enabled, restore the required Microsoft certificates and current dbx as needed, then run VeraCrypt Repair/Reinstall. Do not remove Microsoft Corporation UEFI CA 2011 until db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and the actual installed files match VeraCrypt's 2023 set. This check cannot model every image-hash or security-version revocation. Make sure you have an up-to-date VeraCrypt Rescue Disk. Warning: VeraCrypt could not validate the embedded signature and known-CA compatibility of the Windows Boot Manager it chainloads (bootmgfw_ms.vc). The file may be missing, unreadable, not a Windows Boot Manager, have an unrecognized embedded signer, or use a known signing CA that is absent from db or listed by dbx. The handoff to Windows may fail when Secure Boot is enabled.\n\nComplete or repair the Windows Secure Boot certificate and boot-manager update, keep the VeraCrypt System Favorites service enabled, and run VeraCrypt Repair/Reinstall. Repair also checks Windows' serviced EFI_EX/EFI copies for a compatible current Boot Manager. If Windows cannot start, temporarily disable Secure Boot to recover. Make sure you have an up-to-date VeraCrypt Rescue Disk. Warning: The embedded signature of the Windows Boot Manager used by VeraCrypt (bootmgfw_ms.vc) is still issued by Microsoft Windows Production PCA 2011, although firmware db already contains Windows UEFI CA 2023. Its known CA is currently allowed, but it will no longer start after the PCA 2011 certificate is added to dbx.\n\nDo not apply the PCA 2011 revocation (AvailableUpdates bit 0x80, including combined value 0x280) yet. First complete the Windows 2023 boot-manager update while the VeraCrypt System Favorites service is enabled, then run VeraCrypt Repair/Reinstall so VeraCrypt can import a compatible serviced EFI_EX/EFI copy. Verify the embedded issuer of bootmgfw_ms.vc is Windows UEFI CA 2023 and make sure you have an up-to-date VeraCrypt Rescue Disk. + Outer p&assword: + Operation failed while hidden volume protection was enabled.\n\nUse the OUTER volume password, PIM, KDF, and keyfile(s), if any, in the main password dialog. Use the HIDDEN volume password, PIM, KDF, and keyfile(s), if any, in Mount Options > Hidden Volume Protection.\n\nOne or more credentials may be incorrect, or the volume may be invalid or unsupported. + OUTER volume (this dialog): password, PIM, KDF, and keyfile(s).\nHIDDEN volume (Mount Options): password, PIM, KDF, and keyfile(s). diff --git a/Translations/Language.co.xml b/Translations/Language.co.xml index 4603547b8c..9aaa665ff1 100644 --- a/Translations/Language.co.xml +++ b/Translations/Language.co.xml @@ -1713,6 +1713,9 @@ Information about Corsican localization: Warning: VeraCrypt could not validate the installed EFI bootloader files against one complete embedded resource set and confirm that all known required signing CAs are present in db and not listed by dbx. Firmware may reject VeraCrypt when Secure Boot is enabled.\n\nBefore booting with Secure Boot enabled, restore the required Microsoft certificates and current dbx as needed, then run VeraCrypt Repair/Reinstall. Do not remove Microsoft Corporation UEFI CA 2011 until db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and the actual installed files match VeraCrypt's 2023 set. This check cannot model every image-hash or security-version revocation. Make sure you have an up-to-date VeraCrypt Rescue Disk. Warning: VeraCrypt could not validate the embedded signature and known-CA compatibility of the Windows Boot Manager it chainloads (bootmgfw_ms.vc). The file may be missing, unreadable, not a Windows Boot Manager, have an unrecognized embedded signer, or use a known signing CA that is absent from db or listed by dbx. The handoff to Windows may fail when Secure Boot is enabled.\n\nComplete or repair the Windows Secure Boot certificate and boot-manager update, keep the VeraCrypt System Favorites service enabled, and run VeraCrypt Repair/Reinstall. Repair also checks Windows' serviced EFI_EX/EFI copies for a compatible current Boot Manager. If Windows cannot start, temporarily disable Secure Boot to recover. Make sure you have an up-to-date VeraCrypt Rescue Disk. Warning: The embedded signature of the Windows Boot Manager used by VeraCrypt (bootmgfw_ms.vc) is still issued by Microsoft Windows Production PCA 2011, although firmware db already contains Windows UEFI CA 2023. Its known CA is currently allowed, but it will no longer start after the PCA 2011 certificate is added to dbx.\n\nDo not apply the PCA 2011 revocation (AvailableUpdates bit 0x80, including combined value 0x280) yet. First complete the Windows 2023 boot-manager update while the VeraCrypt System Favorites service is enabled, then run VeraCrypt Repair/Reinstall so VeraCrypt can import a compatible serviced EFI_EX/EFI copy. Verify the embedded issuer of bootmgfw_ms.vc is Windows UEFI CA 2023 and make sure you have an up-to-date VeraCrypt Rescue Disk. + Outer p&assword: + Operation failed while hidden volume protection was enabled.\n\nUse the OUTER volume password, PIM, KDF, and keyfile(s), if any, in the main password dialog. Use the HIDDEN volume password, PIM, KDF, and keyfile(s), if any, in Mount Options > Hidden Volume Protection.\n\nOne or more credentials may be incorrect, or the volume may be invalid or unsupported. + OUTER volume (this dialog): password, PIM, KDF, and keyfile(s).\nHIDDEN volume (Mount Options): password, PIM, KDF, and keyfile(s). diff --git a/Translations/Language.cs.xml b/Translations/Language.cs.xml index 4dd0442d89..f388aceca6 100644 --- a/Translations/Language.cs.xml +++ b/Translations/Language.cs.xml @@ -1691,6 +1691,9 @@ Warning: VeraCrypt could not validate the installed EFI bootloader files against one complete embedded resource set and confirm that all known required signing CAs are present in db and not listed by dbx. Firmware may reject VeraCrypt when Secure Boot is enabled.\n\nBefore booting with Secure Boot enabled, restore the required Microsoft certificates and current dbx as needed, then run VeraCrypt Repair/Reinstall. Do not remove Microsoft Corporation UEFI CA 2011 until db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and the actual installed files match VeraCrypt's 2023 set. This check cannot model every image-hash or security-version revocation. Make sure you have an up-to-date VeraCrypt Rescue Disk. Warning: VeraCrypt could not validate the embedded signature and known-CA compatibility of the Windows Boot Manager it chainloads (bootmgfw_ms.vc). The file may be missing, unreadable, not a Windows Boot Manager, have an unrecognized embedded signer, or use a known signing CA that is absent from db or listed by dbx. The handoff to Windows may fail when Secure Boot is enabled.\n\nComplete or repair the Windows Secure Boot certificate and boot-manager update, keep the VeraCrypt System Favorites service enabled, and run VeraCrypt Repair/Reinstall. Repair also checks Windows' serviced EFI_EX/EFI copies for a compatible current Boot Manager. If Windows cannot start, temporarily disable Secure Boot to recover. Make sure you have an up-to-date VeraCrypt Rescue Disk. Warning: The embedded signature of the Windows Boot Manager used by VeraCrypt (bootmgfw_ms.vc) is still issued by Microsoft Windows Production PCA 2011, although firmware db already contains Windows UEFI CA 2023. Its known CA is currently allowed, but it will no longer start after the PCA 2011 certificate is added to dbx.\n\nDo not apply the PCA 2011 revocation (AvailableUpdates bit 0x80, including combined value 0x280) yet. First complete the Windows 2023 boot-manager update while the VeraCrypt System Favorites service is enabled, then run VeraCrypt Repair/Reinstall so VeraCrypt can import a compatible serviced EFI_EX/EFI copy. Verify the embedded issuer of bootmgfw_ms.vc is Windows UEFI CA 2023 and make sure you have an up-to-date VeraCrypt Rescue Disk. + Outer p&assword: + Operation failed while hidden volume protection was enabled.\n\nUse the OUTER volume password, PIM, KDF, and keyfile(s), if any, in the main password dialog. Use the HIDDEN volume password, PIM, KDF, and keyfile(s), if any, in Mount Options > Hidden Volume Protection.\n\nOne or more credentials may be incorrect, or the volume may be invalid or unsupported. + OUTER volume (this dialog): password, PIM, KDF, and keyfile(s).\nHIDDEN volume (Mount Options): password, PIM, KDF, and keyfile(s). diff --git a/Translations/Language.da.xml b/Translations/Language.da.xml index 728fc96980..7ff3d8c831 100644 --- a/Translations/Language.da.xml +++ b/Translations/Language.da.xml @@ -1691,6 +1691,9 @@ Warning: VeraCrypt could not validate the installed EFI bootloader files against one complete embedded resource set and confirm that all known required signing CAs are present in db and not listed by dbx. Firmware may reject VeraCrypt when Secure Boot is enabled.\n\nBefore booting with Secure Boot enabled, restore the required Microsoft certificates and current dbx as needed, then run VeraCrypt Repair/Reinstall. Do not remove Microsoft Corporation UEFI CA 2011 until db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and the actual installed files match VeraCrypt's 2023 set. This check cannot model every image-hash or security-version revocation. Make sure you have an up-to-date VeraCrypt Rescue Disk. Warning: VeraCrypt could not validate the embedded signature and known-CA compatibility of the Windows Boot Manager it chainloads (bootmgfw_ms.vc). The file may be missing, unreadable, not a Windows Boot Manager, have an unrecognized embedded signer, or use a known signing CA that is absent from db or listed by dbx. The handoff to Windows may fail when Secure Boot is enabled.\n\nComplete or repair the Windows Secure Boot certificate and boot-manager update, keep the VeraCrypt System Favorites service enabled, and run VeraCrypt Repair/Reinstall. Repair also checks Windows' serviced EFI_EX/EFI copies for a compatible current Boot Manager. If Windows cannot start, temporarily disable Secure Boot to recover. Make sure you have an up-to-date VeraCrypt Rescue Disk. Warning: The embedded signature of the Windows Boot Manager used by VeraCrypt (bootmgfw_ms.vc) is still issued by Microsoft Windows Production PCA 2011, although firmware db already contains Windows UEFI CA 2023. Its known CA is currently allowed, but it will no longer start after the PCA 2011 certificate is added to dbx.\n\nDo not apply the PCA 2011 revocation (AvailableUpdates bit 0x80, including combined value 0x280) yet. First complete the Windows 2023 boot-manager update while the VeraCrypt System Favorites service is enabled, then run VeraCrypt Repair/Reinstall so VeraCrypt can import a compatible serviced EFI_EX/EFI copy. Verify the embedded issuer of bootmgfw_ms.vc is Windows UEFI CA 2023 and make sure you have an up-to-date VeraCrypt Rescue Disk. + Outer p&assword: + Operation failed while hidden volume protection was enabled.\n\nUse the OUTER volume password, PIM, KDF, and keyfile(s), if any, in the main password dialog. Use the HIDDEN volume password, PIM, KDF, and keyfile(s), if any, in Mount Options > Hidden Volume Protection.\n\nOne or more credentials may be incorrect, or the volume may be invalid or unsupported. + OUTER volume (this dialog): password, PIM, KDF, and keyfile(s).\nHIDDEN volume (Mount Options): password, PIM, KDF, and keyfile(s). diff --git a/Translations/Language.de.xml b/Translations/Language.de.xml index db5852ca99..a42de26a22 100644 --- a/Translations/Language.de.xml +++ b/Translations/Language.de.xml @@ -1694,6 +1694,9 @@ Warning: VeraCrypt could not validate the installed EFI bootloader files against one complete embedded resource set and confirm that all known required signing CAs are present in db and not listed by dbx. Firmware may reject VeraCrypt when Secure Boot is enabled.\n\nBefore booting with Secure Boot enabled, restore the required Microsoft certificates and current dbx as needed, then run VeraCrypt Repair/Reinstall. Do not remove Microsoft Corporation UEFI CA 2011 until db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and the actual installed files match VeraCrypt's 2023 set. This check cannot model every image-hash or security-version revocation. Make sure you have an up-to-date VeraCrypt Rescue Disk. Warning: VeraCrypt could not validate the embedded signature and known-CA compatibility of the Windows Boot Manager it chainloads (bootmgfw_ms.vc). The file may be missing, unreadable, not a Windows Boot Manager, have an unrecognized embedded signer, or use a known signing CA that is absent from db or listed by dbx. The handoff to Windows may fail when Secure Boot is enabled.\n\nComplete or repair the Windows Secure Boot certificate and boot-manager update, keep the VeraCrypt System Favorites service enabled, and run VeraCrypt Repair/Reinstall. Repair also checks Windows' serviced EFI_EX/EFI copies for a compatible current Boot Manager. If Windows cannot start, temporarily disable Secure Boot to recover. Make sure you have an up-to-date VeraCrypt Rescue Disk. Warning: The embedded signature of the Windows Boot Manager used by VeraCrypt (bootmgfw_ms.vc) is still issued by Microsoft Windows Production PCA 2011, although firmware db already contains Windows UEFI CA 2023. Its known CA is currently allowed, but it will no longer start after the PCA 2011 certificate is added to dbx.\n\nDo not apply the PCA 2011 revocation (AvailableUpdates bit 0x80, including combined value 0x280) yet. First complete the Windows 2023 boot-manager update while the VeraCrypt System Favorites service is enabled, then run VeraCrypt Repair/Reinstall so VeraCrypt can import a compatible serviced EFI_EX/EFI copy. Verify the embedded issuer of bootmgfw_ms.vc is Windows UEFI CA 2023 and make sure you have an up-to-date VeraCrypt Rescue Disk. + Outer p&assword: + Operation failed while hidden volume protection was enabled.\n\nUse the OUTER volume password, PIM, KDF, and keyfile(s), if any, in the main password dialog. Use the HIDDEN volume password, PIM, KDF, and keyfile(s), if any, in Mount Options > Hidden Volume Protection.\n\nOne or more credentials may be incorrect, or the volume may be invalid or unsupported. + OUTER volume (this dialog): password, PIM, KDF, and keyfile(s).\nHIDDEN volume (Mount Options): password, PIM, KDF, and keyfile(s). diff --git a/Translations/Language.el.xml b/Translations/Language.el.xml index 1ef70e621c..7af10044da 100644 --- a/Translations/Language.el.xml +++ b/Translations/Language.el.xml @@ -1691,6 +1691,9 @@ Warning: VeraCrypt could not validate the installed EFI bootloader files against one complete embedded resource set and confirm that all known required signing CAs are present in db and not listed by dbx. Firmware may reject VeraCrypt when Secure Boot is enabled.\n\nBefore booting with Secure Boot enabled, restore the required Microsoft certificates and current dbx as needed, then run VeraCrypt Repair/Reinstall. Do not remove Microsoft Corporation UEFI CA 2011 until db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and the actual installed files match VeraCrypt's 2023 set. This check cannot model every image-hash or security-version revocation. Make sure you have an up-to-date VeraCrypt Rescue Disk. Warning: VeraCrypt could not validate the embedded signature and known-CA compatibility of the Windows Boot Manager it chainloads (bootmgfw_ms.vc). The file may be missing, unreadable, not a Windows Boot Manager, have an unrecognized embedded signer, or use a known signing CA that is absent from db or listed by dbx. The handoff to Windows may fail when Secure Boot is enabled.\n\nComplete or repair the Windows Secure Boot certificate and boot-manager update, keep the VeraCrypt System Favorites service enabled, and run VeraCrypt Repair/Reinstall. Repair also checks Windows' serviced EFI_EX/EFI copies for a compatible current Boot Manager. If Windows cannot start, temporarily disable Secure Boot to recover. Make sure you have an up-to-date VeraCrypt Rescue Disk. Warning: The embedded signature of the Windows Boot Manager used by VeraCrypt (bootmgfw_ms.vc) is still issued by Microsoft Windows Production PCA 2011, although firmware db already contains Windows UEFI CA 2023. Its known CA is currently allowed, but it will no longer start after the PCA 2011 certificate is added to dbx.\n\nDo not apply the PCA 2011 revocation (AvailableUpdates bit 0x80, including combined value 0x280) yet. First complete the Windows 2023 boot-manager update while the VeraCrypt System Favorites service is enabled, then run VeraCrypt Repair/Reinstall so VeraCrypt can import a compatible serviced EFI_EX/EFI copy. Verify the embedded issuer of bootmgfw_ms.vc is Windows UEFI CA 2023 and make sure you have an up-to-date VeraCrypt Rescue Disk. + Outer p&assword: + Operation failed while hidden volume protection was enabled.\n\nUse the OUTER volume password, PIM, KDF, and keyfile(s), if any, in the main password dialog. Use the HIDDEN volume password, PIM, KDF, and keyfile(s), if any, in Mount Options > Hidden Volume Protection.\n\nOne or more credentials may be incorrect, or the volume may be invalid or unsupported. + OUTER volume (this dialog): password, PIM, KDF, and keyfile(s).\nHIDDEN volume (Mount Options): password, PIM, KDF, and keyfile(s). diff --git a/Translations/Language.es.xml b/Translations/Language.es.xml index 35387cffd1..863326374e 100644 --- a/Translations/Language.es.xml +++ b/Translations/Language.es.xml @@ -1691,6 +1691,9 @@ Warning: VeraCrypt could not validate the installed EFI bootloader files against one complete embedded resource set and confirm that all known required signing CAs are present in db and not listed by dbx. Firmware may reject VeraCrypt when Secure Boot is enabled.\n\nBefore booting with Secure Boot enabled, restore the required Microsoft certificates and current dbx as needed, then run VeraCrypt Repair/Reinstall. Do not remove Microsoft Corporation UEFI CA 2011 until db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and the actual installed files match VeraCrypt's 2023 set. This check cannot model every image-hash or security-version revocation. Make sure you have an up-to-date VeraCrypt Rescue Disk. Warning: VeraCrypt could not validate the embedded signature and known-CA compatibility of the Windows Boot Manager it chainloads (bootmgfw_ms.vc). The file may be missing, unreadable, not a Windows Boot Manager, have an unrecognized embedded signer, or use a known signing CA that is absent from db or listed by dbx. The handoff to Windows may fail when Secure Boot is enabled.\n\nComplete or repair the Windows Secure Boot certificate and boot-manager update, keep the VeraCrypt System Favorites service enabled, and run VeraCrypt Repair/Reinstall. Repair also checks Windows' serviced EFI_EX/EFI copies for a compatible current Boot Manager. If Windows cannot start, temporarily disable Secure Boot to recover. Make sure you have an up-to-date VeraCrypt Rescue Disk. Warning: The embedded signature of the Windows Boot Manager used by VeraCrypt (bootmgfw_ms.vc) is still issued by Microsoft Windows Production PCA 2011, although firmware db already contains Windows UEFI CA 2023. Its known CA is currently allowed, but it will no longer start after the PCA 2011 certificate is added to dbx.\n\nDo not apply the PCA 2011 revocation (AvailableUpdates bit 0x80, including combined value 0x280) yet. First complete the Windows 2023 boot-manager update while the VeraCrypt System Favorites service is enabled, then run VeraCrypt Repair/Reinstall so VeraCrypt can import a compatible serviced EFI_EX/EFI copy. Verify the embedded issuer of bootmgfw_ms.vc is Windows UEFI CA 2023 and make sure you have an up-to-date VeraCrypt Rescue Disk. + Outer p&assword: + Operation failed while hidden volume protection was enabled.\n\nUse the OUTER volume password, PIM, KDF, and keyfile(s), if any, in the main password dialog. Use the HIDDEN volume password, PIM, KDF, and keyfile(s), if any, in Mount Options > Hidden Volume Protection.\n\nOne or more credentials may be incorrect, or the volume may be invalid or unsupported. + OUTER volume (this dialog): password, PIM, KDF, and keyfile(s).\nHIDDEN volume (Mount Options): password, PIM, KDF, and keyfile(s). diff --git a/Translations/Language.et.xml b/Translations/Language.et.xml index 4308e615be..4b4a53165f 100644 --- a/Translations/Language.et.xml +++ b/Translations/Language.et.xml @@ -1691,6 +1691,9 @@ Warning: VeraCrypt could not validate the installed EFI bootloader files against one complete embedded resource set and confirm that all known required signing CAs are present in db and not listed by dbx. Firmware may reject VeraCrypt when Secure Boot is enabled.\n\nBefore booting with Secure Boot enabled, restore the required Microsoft certificates and current dbx as needed, then run VeraCrypt Repair/Reinstall. Do not remove Microsoft Corporation UEFI CA 2011 until db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and the actual installed files match VeraCrypt's 2023 set. This check cannot model every image-hash or security-version revocation. Make sure you have an up-to-date VeraCrypt Rescue Disk. Warning: VeraCrypt could not validate the embedded signature and known-CA compatibility of the Windows Boot Manager it chainloads (bootmgfw_ms.vc). The file may be missing, unreadable, not a Windows Boot Manager, have an unrecognized embedded signer, or use a known signing CA that is absent from db or listed by dbx. The handoff to Windows may fail when Secure Boot is enabled.\n\nComplete or repair the Windows Secure Boot certificate and boot-manager update, keep the VeraCrypt System Favorites service enabled, and run VeraCrypt Repair/Reinstall. Repair also checks Windows' serviced EFI_EX/EFI copies for a compatible current Boot Manager. If Windows cannot start, temporarily disable Secure Boot to recover. Make sure you have an up-to-date VeraCrypt Rescue Disk. Warning: The embedded signature of the Windows Boot Manager used by VeraCrypt (bootmgfw_ms.vc) is still issued by Microsoft Windows Production PCA 2011, although firmware db already contains Windows UEFI CA 2023. Its known CA is currently allowed, but it will no longer start after the PCA 2011 certificate is added to dbx.\n\nDo not apply the PCA 2011 revocation (AvailableUpdates bit 0x80, including combined value 0x280) yet. First complete the Windows 2023 boot-manager update while the VeraCrypt System Favorites service is enabled, then run VeraCrypt Repair/Reinstall so VeraCrypt can import a compatible serviced EFI_EX/EFI copy. Verify the embedded issuer of bootmgfw_ms.vc is Windows UEFI CA 2023 and make sure you have an up-to-date VeraCrypt Rescue Disk. + Outer p&assword: + Operation failed while hidden volume protection was enabled.\n\nUse the OUTER volume password, PIM, KDF, and keyfile(s), if any, in the main password dialog. Use the HIDDEN volume password, PIM, KDF, and keyfile(s), if any, in Mount Options > Hidden Volume Protection.\n\nOne or more credentials may be incorrect, or the volume may be invalid or unsupported. + OUTER volume (this dialog): password, PIM, KDF, and keyfile(s).\nHIDDEN volume (Mount Options): password, PIM, KDF, and keyfile(s). diff --git a/Translations/Language.eu.xml b/Translations/Language.eu.xml index cbd3eb265b..405bfd4ec0 100644 --- a/Translations/Language.eu.xml +++ b/Translations/Language.eu.xml @@ -1691,6 +1691,9 @@ Warning: VeraCrypt could not validate the installed EFI bootloader files against one complete embedded resource set and confirm that all known required signing CAs are present in db and not listed by dbx. Firmware may reject VeraCrypt when Secure Boot is enabled.\n\nBefore booting with Secure Boot enabled, restore the required Microsoft certificates and current dbx as needed, then run VeraCrypt Repair/Reinstall. Do not remove Microsoft Corporation UEFI CA 2011 until db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and the actual installed files match VeraCrypt's 2023 set. This check cannot model every image-hash or security-version revocation. Make sure you have an up-to-date VeraCrypt Rescue Disk. Warning: VeraCrypt could not validate the embedded signature and known-CA compatibility of the Windows Boot Manager it chainloads (bootmgfw_ms.vc). The file may be missing, unreadable, not a Windows Boot Manager, have an unrecognized embedded signer, or use a known signing CA that is absent from db or listed by dbx. The handoff to Windows may fail when Secure Boot is enabled.\n\nComplete or repair the Windows Secure Boot certificate and boot-manager update, keep the VeraCrypt System Favorites service enabled, and run VeraCrypt Repair/Reinstall. Repair also checks Windows' serviced EFI_EX/EFI copies for a compatible current Boot Manager. If Windows cannot start, temporarily disable Secure Boot to recover. Make sure you have an up-to-date VeraCrypt Rescue Disk. Warning: The embedded signature of the Windows Boot Manager used by VeraCrypt (bootmgfw_ms.vc) is still issued by Microsoft Windows Production PCA 2011, although firmware db already contains Windows UEFI CA 2023. Its known CA is currently allowed, but it will no longer start after the PCA 2011 certificate is added to dbx.\n\nDo not apply the PCA 2011 revocation (AvailableUpdates bit 0x80, including combined value 0x280) yet. First complete the Windows 2023 boot-manager update while the VeraCrypt System Favorites service is enabled, then run VeraCrypt Repair/Reinstall so VeraCrypt can import a compatible serviced EFI_EX/EFI copy. Verify the embedded issuer of bootmgfw_ms.vc is Windows UEFI CA 2023 and make sure you have an up-to-date VeraCrypt Rescue Disk. + Outer p&assword: + Operation failed while hidden volume protection was enabled.\n\nUse the OUTER volume password, PIM, KDF, and keyfile(s), if any, in the main password dialog. Use the HIDDEN volume password, PIM, KDF, and keyfile(s), if any, in Mount Options > Hidden Volume Protection.\n\nOne or more credentials may be incorrect, or the volume may be invalid or unsupported. + OUTER volume (this dialog): password, PIM, KDF, and keyfile(s).\nHIDDEN volume (Mount Options): password, PIM, KDF, and keyfile(s). diff --git a/Translations/Language.fa.xml b/Translations/Language.fa.xml index e6f1eaca06..f0e13a0b27 100644 --- a/Translations/Language.fa.xml +++ b/Translations/Language.fa.xml @@ -1691,6 +1691,9 @@ Warning: VeraCrypt could not validate the installed EFI bootloader files against one complete embedded resource set and confirm that all known required signing CAs are present in db and not listed by dbx. Firmware may reject VeraCrypt when Secure Boot is enabled.\n\nBefore booting with Secure Boot enabled, restore the required Microsoft certificates and current dbx as needed, then run VeraCrypt Repair/Reinstall. Do not remove Microsoft Corporation UEFI CA 2011 until db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and the actual installed files match VeraCrypt's 2023 set. This check cannot model every image-hash or security-version revocation. Make sure you have an up-to-date VeraCrypt Rescue Disk. Warning: VeraCrypt could not validate the embedded signature and known-CA compatibility of the Windows Boot Manager it chainloads (bootmgfw_ms.vc). The file may be missing, unreadable, not a Windows Boot Manager, have an unrecognized embedded signer, or use a known signing CA that is absent from db or listed by dbx. The handoff to Windows may fail when Secure Boot is enabled.\n\nComplete or repair the Windows Secure Boot certificate and boot-manager update, keep the VeraCrypt System Favorites service enabled, and run VeraCrypt Repair/Reinstall. Repair also checks Windows' serviced EFI_EX/EFI copies for a compatible current Boot Manager. If Windows cannot start, temporarily disable Secure Boot to recover. Make sure you have an up-to-date VeraCrypt Rescue Disk. Warning: The embedded signature of the Windows Boot Manager used by VeraCrypt (bootmgfw_ms.vc) is still issued by Microsoft Windows Production PCA 2011, although firmware db already contains Windows UEFI CA 2023. Its known CA is currently allowed, but it will no longer start after the PCA 2011 certificate is added to dbx.\n\nDo not apply the PCA 2011 revocation (AvailableUpdates bit 0x80, including combined value 0x280) yet. First complete the Windows 2023 boot-manager update while the VeraCrypt System Favorites service is enabled, then run VeraCrypt Repair/Reinstall so VeraCrypt can import a compatible serviced EFI_EX/EFI copy. Verify the embedded issuer of bootmgfw_ms.vc is Windows UEFI CA 2023 and make sure you have an up-to-date VeraCrypt Rescue Disk. + Outer p&assword: + Operation failed while hidden volume protection was enabled.\n\nUse the OUTER volume password, PIM, KDF, and keyfile(s), if any, in the main password dialog. Use the HIDDEN volume password, PIM, KDF, and keyfile(s), if any, in Mount Options > Hidden Volume Protection.\n\nOne or more credentials may be incorrect, or the volume may be invalid or unsupported. + OUTER volume (this dialog): password, PIM, KDF, and keyfile(s).\nHIDDEN volume (Mount Options): password, PIM, KDF, and keyfile(s). diff --git a/Translations/Language.fi.xml b/Translations/Language.fi.xml index 06d5897c21..19ad2887e5 100644 --- a/Translations/Language.fi.xml +++ b/Translations/Language.fi.xml @@ -1691,6 +1691,9 @@ Warning: VeraCrypt could not validate the installed EFI bootloader files against one complete embedded resource set and confirm that all known required signing CAs are present in db and not listed by dbx. Firmware may reject VeraCrypt when Secure Boot is enabled.\n\nBefore booting with Secure Boot enabled, restore the required Microsoft certificates and current dbx as needed, then run VeraCrypt Repair/Reinstall. Do not remove Microsoft Corporation UEFI CA 2011 until db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and the actual installed files match VeraCrypt's 2023 set. This check cannot model every image-hash or security-version revocation. Make sure you have an up-to-date VeraCrypt Rescue Disk. Warning: VeraCrypt could not validate the embedded signature and known-CA compatibility of the Windows Boot Manager it chainloads (bootmgfw_ms.vc). The file may be missing, unreadable, not a Windows Boot Manager, have an unrecognized embedded signer, or use a known signing CA that is absent from db or listed by dbx. The handoff to Windows may fail when Secure Boot is enabled.\n\nComplete or repair the Windows Secure Boot certificate and boot-manager update, keep the VeraCrypt System Favorites service enabled, and run VeraCrypt Repair/Reinstall. Repair also checks Windows' serviced EFI_EX/EFI copies for a compatible current Boot Manager. If Windows cannot start, temporarily disable Secure Boot to recover. Make sure you have an up-to-date VeraCrypt Rescue Disk. Warning: The embedded signature of the Windows Boot Manager used by VeraCrypt (bootmgfw_ms.vc) is still issued by Microsoft Windows Production PCA 2011, although firmware db already contains Windows UEFI CA 2023. Its known CA is currently allowed, but it will no longer start after the PCA 2011 certificate is added to dbx.\n\nDo not apply the PCA 2011 revocation (AvailableUpdates bit 0x80, including combined value 0x280) yet. First complete the Windows 2023 boot-manager update while the VeraCrypt System Favorites service is enabled, then run VeraCrypt Repair/Reinstall so VeraCrypt can import a compatible serviced EFI_EX/EFI copy. Verify the embedded issuer of bootmgfw_ms.vc is Windows UEFI CA 2023 and make sure you have an up-to-date VeraCrypt Rescue Disk. + Outer p&assword: + Operation failed while hidden volume protection was enabled.\n\nUse the OUTER volume password, PIM, KDF, and keyfile(s), if any, in the main password dialog. Use the HIDDEN volume password, PIM, KDF, and keyfile(s), if any, in Mount Options > Hidden Volume Protection.\n\nOne or more credentials may be incorrect, or the volume may be invalid or unsupported. + OUTER volume (this dialog): password, PIM, KDF, and keyfile(s).\nHIDDEN volume (Mount Options): password, PIM, KDF, and keyfile(s). diff --git a/Translations/Language.fr.xml b/Translations/Language.fr.xml index 4bc6943797..b9690586aa 100644 --- a/Translations/Language.fr.xml +++ b/Translations/Language.fr.xml @@ -1691,6 +1691,9 @@ Warning: VeraCrypt could not validate the installed EFI bootloader files against one complete embedded resource set and confirm that all known required signing CAs are present in db and not listed by dbx. Firmware may reject VeraCrypt when Secure Boot is enabled.\n\nBefore booting with Secure Boot enabled, restore the required Microsoft certificates and current dbx as needed, then run VeraCrypt Repair/Reinstall. Do not remove Microsoft Corporation UEFI CA 2011 until db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and the actual installed files match VeraCrypt's 2023 set. This check cannot model every image-hash or security-version revocation. Make sure you have an up-to-date VeraCrypt Rescue Disk. Warning: VeraCrypt could not validate the embedded signature and known-CA compatibility of the Windows Boot Manager it chainloads (bootmgfw_ms.vc). The file may be missing, unreadable, not a Windows Boot Manager, have an unrecognized embedded signer, or use a known signing CA that is absent from db or listed by dbx. The handoff to Windows may fail when Secure Boot is enabled.\n\nComplete or repair the Windows Secure Boot certificate and boot-manager update, keep the VeraCrypt System Favorites service enabled, and run VeraCrypt Repair/Reinstall. Repair also checks Windows' serviced EFI_EX/EFI copies for a compatible current Boot Manager. If Windows cannot start, temporarily disable Secure Boot to recover. Make sure you have an up-to-date VeraCrypt Rescue Disk. Warning: The embedded signature of the Windows Boot Manager used by VeraCrypt (bootmgfw_ms.vc) is still issued by Microsoft Windows Production PCA 2011, although firmware db already contains Windows UEFI CA 2023. Its known CA is currently allowed, but it will no longer start after the PCA 2011 certificate is added to dbx.\n\nDo not apply the PCA 2011 revocation (AvailableUpdates bit 0x80, including combined value 0x280) yet. First complete the Windows 2023 boot-manager update while the VeraCrypt System Favorites service is enabled, then run VeraCrypt Repair/Reinstall so VeraCrypt can import a compatible serviced EFI_EX/EFI copy. Verify the embedded issuer of bootmgfw_ms.vc is Windows UEFI CA 2023 and make sure you have an up-to-date VeraCrypt Rescue Disk. + Outer p&assword: + Operation failed while hidden volume protection was enabled.\n\nUse the OUTER volume password, PIM, KDF, and keyfile(s), if any, in the main password dialog. Use the HIDDEN volume password, PIM, KDF, and keyfile(s), if any, in Mount Options > Hidden Volume Protection.\n\nOne or more credentials may be incorrect, or the volume may be invalid or unsupported. + OUTER volume (this dialog): password, PIM, KDF, and keyfile(s).\nHIDDEN volume (Mount Options): password, PIM, KDF, and keyfile(s). diff --git a/Translations/Language.he.xml b/Translations/Language.he.xml index b0fa198040..3d283400b4 100644 --- a/Translations/Language.he.xml +++ b/Translations/Language.he.xml @@ -1691,6 +1691,9 @@ Warning: VeraCrypt could not validate the installed EFI bootloader files against one complete embedded resource set and confirm that all known required signing CAs are present in db and not listed by dbx. Firmware may reject VeraCrypt when Secure Boot is enabled.\n\nBefore booting with Secure Boot enabled, restore the required Microsoft certificates and current dbx as needed, then run VeraCrypt Repair/Reinstall. Do not remove Microsoft Corporation UEFI CA 2011 until db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and the actual installed files match VeraCrypt's 2023 set. This check cannot model every image-hash or security-version revocation. Make sure you have an up-to-date VeraCrypt Rescue Disk. Warning: VeraCrypt could not validate the embedded signature and known-CA compatibility of the Windows Boot Manager it chainloads (bootmgfw_ms.vc). The file may be missing, unreadable, not a Windows Boot Manager, have an unrecognized embedded signer, or use a known signing CA that is absent from db or listed by dbx. The handoff to Windows may fail when Secure Boot is enabled.\n\nComplete or repair the Windows Secure Boot certificate and boot-manager update, keep the VeraCrypt System Favorites service enabled, and run VeraCrypt Repair/Reinstall. Repair also checks Windows' serviced EFI_EX/EFI copies for a compatible current Boot Manager. If Windows cannot start, temporarily disable Secure Boot to recover. Make sure you have an up-to-date VeraCrypt Rescue Disk. Warning: The embedded signature of the Windows Boot Manager used by VeraCrypt (bootmgfw_ms.vc) is still issued by Microsoft Windows Production PCA 2011, although firmware db already contains Windows UEFI CA 2023. Its known CA is currently allowed, but it will no longer start after the PCA 2011 certificate is added to dbx.\n\nDo not apply the PCA 2011 revocation (AvailableUpdates bit 0x80, including combined value 0x280) yet. First complete the Windows 2023 boot-manager update while the VeraCrypt System Favorites service is enabled, then run VeraCrypt Repair/Reinstall so VeraCrypt can import a compatible serviced EFI_EX/EFI copy. Verify the embedded issuer of bootmgfw_ms.vc is Windows UEFI CA 2023 and make sure you have an up-to-date VeraCrypt Rescue Disk. + Outer p&assword: + Operation failed while hidden volume protection was enabled.\n\nUse the OUTER volume password, PIM, KDF, and keyfile(s), if any, in the main password dialog. Use the HIDDEN volume password, PIM, KDF, and keyfile(s), if any, in Mount Options > Hidden Volume Protection.\n\nOne or more credentials may be incorrect, or the volume may be invalid or unsupported. + OUTER volume (this dialog): password, PIM, KDF, and keyfile(s).\nHIDDEN volume (Mount Options): password, PIM, KDF, and keyfile(s). diff --git a/Translations/Language.hu.xml b/Translations/Language.hu.xml index ca3397fb05..0d579be295 100644 --- a/Translations/Language.hu.xml +++ b/Translations/Language.hu.xml @@ -1691,6 +1691,9 @@ Warning: VeraCrypt could not validate the installed EFI bootloader files against one complete embedded resource set and confirm that all known required signing CAs are present in db and not listed by dbx. Firmware may reject VeraCrypt when Secure Boot is enabled.\n\nBefore booting with Secure Boot enabled, restore the required Microsoft certificates and current dbx as needed, then run VeraCrypt Repair/Reinstall. Do not remove Microsoft Corporation UEFI CA 2011 until db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and the actual installed files match VeraCrypt's 2023 set. This check cannot model every image-hash or security-version revocation. Make sure you have an up-to-date VeraCrypt Rescue Disk. Warning: VeraCrypt could not validate the embedded signature and known-CA compatibility of the Windows Boot Manager it chainloads (bootmgfw_ms.vc). The file may be missing, unreadable, not a Windows Boot Manager, have an unrecognized embedded signer, or use a known signing CA that is absent from db or listed by dbx. The handoff to Windows may fail when Secure Boot is enabled.\n\nComplete or repair the Windows Secure Boot certificate and boot-manager update, keep the VeraCrypt System Favorites service enabled, and run VeraCrypt Repair/Reinstall. Repair also checks Windows' serviced EFI_EX/EFI copies for a compatible current Boot Manager. If Windows cannot start, temporarily disable Secure Boot to recover. Make sure you have an up-to-date VeraCrypt Rescue Disk. Warning: The embedded signature of the Windows Boot Manager used by VeraCrypt (bootmgfw_ms.vc) is still issued by Microsoft Windows Production PCA 2011, although firmware db already contains Windows UEFI CA 2023. Its known CA is currently allowed, but it will no longer start after the PCA 2011 certificate is added to dbx.\n\nDo not apply the PCA 2011 revocation (AvailableUpdates bit 0x80, including combined value 0x280) yet. First complete the Windows 2023 boot-manager update while the VeraCrypt System Favorites service is enabled, then run VeraCrypt Repair/Reinstall so VeraCrypt can import a compatible serviced EFI_EX/EFI copy. Verify the embedded issuer of bootmgfw_ms.vc is Windows UEFI CA 2023 and make sure you have an up-to-date VeraCrypt Rescue Disk. + Outer p&assword: + Operation failed while hidden volume protection was enabled.\n\nUse the OUTER volume password, PIM, KDF, and keyfile(s), if any, in the main password dialog. Use the HIDDEN volume password, PIM, KDF, and keyfile(s), if any, in Mount Options > Hidden Volume Protection.\n\nOne or more credentials may be incorrect, or the volume may be invalid or unsupported. + OUTER volume (this dialog): password, PIM, KDF, and keyfile(s).\nHIDDEN volume (Mount Options): password, PIM, KDF, and keyfile(s). diff --git a/Translations/Language.id.xml b/Translations/Language.id.xml index 500061e1af..df5cea9c22 100644 --- a/Translations/Language.id.xml +++ b/Translations/Language.id.xml @@ -1691,6 +1691,9 @@ Warning: VeraCrypt could not validate the installed EFI bootloader files against one complete embedded resource set and confirm that all known required signing CAs are present in db and not listed by dbx. Firmware may reject VeraCrypt when Secure Boot is enabled.\n\nBefore booting with Secure Boot enabled, restore the required Microsoft certificates and current dbx as needed, then run VeraCrypt Repair/Reinstall. Do not remove Microsoft Corporation UEFI CA 2011 until db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and the actual installed files match VeraCrypt's 2023 set. This check cannot model every image-hash or security-version revocation. Make sure you have an up-to-date VeraCrypt Rescue Disk. Warning: VeraCrypt could not validate the embedded signature and known-CA compatibility of the Windows Boot Manager it chainloads (bootmgfw_ms.vc). The file may be missing, unreadable, not a Windows Boot Manager, have an unrecognized embedded signer, or use a known signing CA that is absent from db or listed by dbx. The handoff to Windows may fail when Secure Boot is enabled.\n\nComplete or repair the Windows Secure Boot certificate and boot-manager update, keep the VeraCrypt System Favorites service enabled, and run VeraCrypt Repair/Reinstall. Repair also checks Windows' serviced EFI_EX/EFI copies for a compatible current Boot Manager. If Windows cannot start, temporarily disable Secure Boot to recover. Make sure you have an up-to-date VeraCrypt Rescue Disk. Warning: The embedded signature of the Windows Boot Manager used by VeraCrypt (bootmgfw_ms.vc) is still issued by Microsoft Windows Production PCA 2011, although firmware db already contains Windows UEFI CA 2023. Its known CA is currently allowed, but it will no longer start after the PCA 2011 certificate is added to dbx.\n\nDo not apply the PCA 2011 revocation (AvailableUpdates bit 0x80, including combined value 0x280) yet. First complete the Windows 2023 boot-manager update while the VeraCrypt System Favorites service is enabled, then run VeraCrypt Repair/Reinstall so VeraCrypt can import a compatible serviced EFI_EX/EFI copy. Verify the embedded issuer of bootmgfw_ms.vc is Windows UEFI CA 2023 and make sure you have an up-to-date VeraCrypt Rescue Disk. + Outer p&assword: + Operation failed while hidden volume protection was enabled.\n\nUse the OUTER volume password, PIM, KDF, and keyfile(s), if any, in the main password dialog. Use the HIDDEN volume password, PIM, KDF, and keyfile(s), if any, in Mount Options > Hidden Volume Protection.\n\nOne or more credentials may be incorrect, or the volume may be invalid or unsupported. + OUTER volume (this dialog): password, PIM, KDF, and keyfile(s).\nHIDDEN volume (Mount Options): password, PIM, KDF, and keyfile(s). diff --git a/Translations/Language.it.xml b/Translations/Language.it.xml index 3f849a0723..ec02f1f60c 100644 --- a/Translations/Language.it.xml +++ b/Translations/Language.it.xml @@ -1691,6 +1691,9 @@ Warning: VeraCrypt could not validate the installed EFI bootloader files against one complete embedded resource set and confirm that all known required signing CAs are present in db and not listed by dbx. Firmware may reject VeraCrypt when Secure Boot is enabled.\n\nBefore booting with Secure Boot enabled, restore the required Microsoft certificates and current dbx as needed, then run VeraCrypt Repair/Reinstall. Do not remove Microsoft Corporation UEFI CA 2011 until db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and the actual installed files match VeraCrypt's 2023 set. This check cannot model every image-hash or security-version revocation. Make sure you have an up-to-date VeraCrypt Rescue Disk. Warning: VeraCrypt could not validate the embedded signature and known-CA compatibility of the Windows Boot Manager it chainloads (bootmgfw_ms.vc). The file may be missing, unreadable, not a Windows Boot Manager, have an unrecognized embedded signer, or use a known signing CA that is absent from db or listed by dbx. The handoff to Windows may fail when Secure Boot is enabled.\n\nComplete or repair the Windows Secure Boot certificate and boot-manager update, keep the VeraCrypt System Favorites service enabled, and run VeraCrypt Repair/Reinstall. Repair also checks Windows' serviced EFI_EX/EFI copies for a compatible current Boot Manager. If Windows cannot start, temporarily disable Secure Boot to recover. Make sure you have an up-to-date VeraCrypt Rescue Disk. Warning: The embedded signature of the Windows Boot Manager used by VeraCrypt (bootmgfw_ms.vc) is still issued by Microsoft Windows Production PCA 2011, although firmware db already contains Windows UEFI CA 2023. Its known CA is currently allowed, but it will no longer start after the PCA 2011 certificate is added to dbx.\n\nDo not apply the PCA 2011 revocation (AvailableUpdates bit 0x80, including combined value 0x280) yet. First complete the Windows 2023 boot-manager update while the VeraCrypt System Favorites service is enabled, then run VeraCrypt Repair/Reinstall so VeraCrypt can import a compatible serviced EFI_EX/EFI copy. Verify the embedded issuer of bootmgfw_ms.vc is Windows UEFI CA 2023 and make sure you have an up-to-date VeraCrypt Rescue Disk. + Outer p&assword: + Operation failed while hidden volume protection was enabled.\n\nUse the OUTER volume password, PIM, KDF, and keyfile(s), if any, in the main password dialog. Use the HIDDEN volume password, PIM, KDF, and keyfile(s), if any, in Mount Options > Hidden Volume Protection.\n\nOne or more credentials may be incorrect, or the volume may be invalid or unsupported. + OUTER volume (this dialog): password, PIM, KDF, and keyfile(s).\nHIDDEN volume (Mount Options): password, PIM, KDF, and keyfile(s). diff --git a/Translations/Language.ja.xml b/Translations/Language.ja.xml index 5b4089f3fe..a6c4a96e61 100644 --- a/Translations/Language.ja.xml +++ b/Translations/Language.ja.xml @@ -1691,6 +1691,9 @@ Warning: VeraCrypt could not validate the installed EFI bootloader files against one complete embedded resource set and confirm that all known required signing CAs are present in db and not listed by dbx. Firmware may reject VeraCrypt when Secure Boot is enabled.\n\nBefore booting with Secure Boot enabled, restore the required Microsoft certificates and current dbx as needed, then run VeraCrypt Repair/Reinstall. Do not remove Microsoft Corporation UEFI CA 2011 until db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and the actual installed files match VeraCrypt's 2023 set. This check cannot model every image-hash or security-version revocation. Make sure you have an up-to-date VeraCrypt Rescue Disk. Warning: VeraCrypt could not validate the embedded signature and known-CA compatibility of the Windows Boot Manager it chainloads (bootmgfw_ms.vc). The file may be missing, unreadable, not a Windows Boot Manager, have an unrecognized embedded signer, or use a known signing CA that is absent from db or listed by dbx. The handoff to Windows may fail when Secure Boot is enabled.\n\nComplete or repair the Windows Secure Boot certificate and boot-manager update, keep the VeraCrypt System Favorites service enabled, and run VeraCrypt Repair/Reinstall. Repair also checks Windows' serviced EFI_EX/EFI copies for a compatible current Boot Manager. If Windows cannot start, temporarily disable Secure Boot to recover. Make sure you have an up-to-date VeraCrypt Rescue Disk. Warning: The embedded signature of the Windows Boot Manager used by VeraCrypt (bootmgfw_ms.vc) is still issued by Microsoft Windows Production PCA 2011, although firmware db already contains Windows UEFI CA 2023. Its known CA is currently allowed, but it will no longer start after the PCA 2011 certificate is added to dbx.\n\nDo not apply the PCA 2011 revocation (AvailableUpdates bit 0x80, including combined value 0x280) yet. First complete the Windows 2023 boot-manager update while the VeraCrypt System Favorites service is enabled, then run VeraCrypt Repair/Reinstall so VeraCrypt can import a compatible serviced EFI_EX/EFI copy. Verify the embedded issuer of bootmgfw_ms.vc is Windows UEFI CA 2023 and make sure you have an up-to-date VeraCrypt Rescue Disk. + Outer p&assword: + Operation failed while hidden volume protection was enabled.\n\nUse the OUTER volume password, PIM, KDF, and keyfile(s), if any, in the main password dialog. Use the HIDDEN volume password, PIM, KDF, and keyfile(s), if any, in Mount Options > Hidden Volume Protection.\n\nOne or more credentials may be incorrect, or the volume may be invalid or unsupported. + OUTER volume (this dialog): password, PIM, KDF, and keyfile(s).\nHIDDEN volume (Mount Options): password, PIM, KDF, and keyfile(s). diff --git a/Translations/Language.ka.xml b/Translations/Language.ka.xml index 226c8a95b8..b6e6d8d349 100644 --- a/Translations/Language.ka.xml +++ b/Translations/Language.ka.xml @@ -1691,6 +1691,9 @@ Warning: VeraCrypt could not validate the installed EFI bootloader files against one complete embedded resource set and confirm that all known required signing CAs are present in db and not listed by dbx. Firmware may reject VeraCrypt when Secure Boot is enabled.\n\nBefore booting with Secure Boot enabled, restore the required Microsoft certificates and current dbx as needed, then run VeraCrypt Repair/Reinstall. Do not remove Microsoft Corporation UEFI CA 2011 until db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and the actual installed files match VeraCrypt's 2023 set. This check cannot model every image-hash or security-version revocation. Make sure you have an up-to-date VeraCrypt Rescue Disk. Warning: VeraCrypt could not validate the embedded signature and known-CA compatibility of the Windows Boot Manager it chainloads (bootmgfw_ms.vc). The file may be missing, unreadable, not a Windows Boot Manager, have an unrecognized embedded signer, or use a known signing CA that is absent from db or listed by dbx. The handoff to Windows may fail when Secure Boot is enabled.\n\nComplete or repair the Windows Secure Boot certificate and boot-manager update, keep the VeraCrypt System Favorites service enabled, and run VeraCrypt Repair/Reinstall. Repair also checks Windows' serviced EFI_EX/EFI copies for a compatible current Boot Manager. If Windows cannot start, temporarily disable Secure Boot to recover. Make sure you have an up-to-date VeraCrypt Rescue Disk. Warning: The embedded signature of the Windows Boot Manager used by VeraCrypt (bootmgfw_ms.vc) is still issued by Microsoft Windows Production PCA 2011, although firmware db already contains Windows UEFI CA 2023. Its known CA is currently allowed, but it will no longer start after the PCA 2011 certificate is added to dbx.\n\nDo not apply the PCA 2011 revocation (AvailableUpdates bit 0x80, including combined value 0x280) yet. First complete the Windows 2023 boot-manager update while the VeraCrypt System Favorites service is enabled, then run VeraCrypt Repair/Reinstall so VeraCrypt can import a compatible serviced EFI_EX/EFI copy. Verify the embedded issuer of bootmgfw_ms.vc is Windows UEFI CA 2023 and make sure you have an up-to-date VeraCrypt Rescue Disk. + Outer p&assword: + Operation failed while hidden volume protection was enabled.\n\nUse the OUTER volume password, PIM, KDF, and keyfile(s), if any, in the main password dialog. Use the HIDDEN volume password, PIM, KDF, and keyfile(s), if any, in Mount Options > Hidden Volume Protection.\n\nOne or more credentials may be incorrect, or the volume may be invalid or unsupported. + OUTER volume (this dialog): password, PIM, KDF, and keyfile(s).\nHIDDEN volume (Mount Options): password, PIM, KDF, and keyfile(s). diff --git a/Translations/Language.ko.xml b/Translations/Language.ko.xml index 22de0d18a3..5cb7f63ca2 100644 --- a/Translations/Language.ko.xml +++ b/Translations/Language.ko.xml @@ -1691,6 +1691,9 @@ Warning: VeraCrypt could not validate the installed EFI bootloader files against one complete embedded resource set and confirm that all known required signing CAs are present in db and not listed by dbx. Firmware may reject VeraCrypt when Secure Boot is enabled.\n\nBefore booting with Secure Boot enabled, restore the required Microsoft certificates and current dbx as needed, then run VeraCrypt Repair/Reinstall. Do not remove Microsoft Corporation UEFI CA 2011 until db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and the actual installed files match VeraCrypt's 2023 set. This check cannot model every image-hash or security-version revocation. Make sure you have an up-to-date VeraCrypt Rescue Disk. Warning: VeraCrypt could not validate the embedded signature and known-CA compatibility of the Windows Boot Manager it chainloads (bootmgfw_ms.vc). The file may be missing, unreadable, not a Windows Boot Manager, have an unrecognized embedded signer, or use a known signing CA that is absent from db or listed by dbx. The handoff to Windows may fail when Secure Boot is enabled.\n\nComplete or repair the Windows Secure Boot certificate and boot-manager update, keep the VeraCrypt System Favorites service enabled, and run VeraCrypt Repair/Reinstall. Repair also checks Windows' serviced EFI_EX/EFI copies for a compatible current Boot Manager. If Windows cannot start, temporarily disable Secure Boot to recover. Make sure you have an up-to-date VeraCrypt Rescue Disk. Warning: The embedded signature of the Windows Boot Manager used by VeraCrypt (bootmgfw_ms.vc) is still issued by Microsoft Windows Production PCA 2011, although firmware db already contains Windows UEFI CA 2023. Its known CA is currently allowed, but it will no longer start after the PCA 2011 certificate is added to dbx.\n\nDo not apply the PCA 2011 revocation (AvailableUpdates bit 0x80, including combined value 0x280) yet. First complete the Windows 2023 boot-manager update while the VeraCrypt System Favorites service is enabled, then run VeraCrypt Repair/Reinstall so VeraCrypt can import a compatible serviced EFI_EX/EFI copy. Verify the embedded issuer of bootmgfw_ms.vc is Windows UEFI CA 2023 and make sure you have an up-to-date VeraCrypt Rescue Disk. + Outer p&assword: + Operation failed while hidden volume protection was enabled.\n\nUse the OUTER volume password, PIM, KDF, and keyfile(s), if any, in the main password dialog. Use the HIDDEN volume password, PIM, KDF, and keyfile(s), if any, in Mount Options > Hidden Volume Protection.\n\nOne or more credentials may be incorrect, or the volume may be invalid or unsupported. + OUTER volume (this dialog): password, PIM, KDF, and keyfile(s).\nHIDDEN volume (Mount Options): password, PIM, KDF, and keyfile(s). diff --git a/Translations/Language.lv.xml b/Translations/Language.lv.xml index d4b67a7154..ddff237af2 100644 --- a/Translations/Language.lv.xml +++ b/Translations/Language.lv.xml @@ -1691,6 +1691,9 @@ Warning: VeraCrypt could not validate the installed EFI bootloader files against one complete embedded resource set and confirm that all known required signing CAs are present in db and not listed by dbx. Firmware may reject VeraCrypt when Secure Boot is enabled.\n\nBefore booting with Secure Boot enabled, restore the required Microsoft certificates and current dbx as needed, then run VeraCrypt Repair/Reinstall. Do not remove Microsoft Corporation UEFI CA 2011 until db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and the actual installed files match VeraCrypt's 2023 set. This check cannot model every image-hash or security-version revocation. Make sure you have an up-to-date VeraCrypt Rescue Disk. Warning: VeraCrypt could not validate the embedded signature and known-CA compatibility of the Windows Boot Manager it chainloads (bootmgfw_ms.vc). The file may be missing, unreadable, not a Windows Boot Manager, have an unrecognized embedded signer, or use a known signing CA that is absent from db or listed by dbx. The handoff to Windows may fail when Secure Boot is enabled.\n\nComplete or repair the Windows Secure Boot certificate and boot-manager update, keep the VeraCrypt System Favorites service enabled, and run VeraCrypt Repair/Reinstall. Repair also checks Windows' serviced EFI_EX/EFI copies for a compatible current Boot Manager. If Windows cannot start, temporarily disable Secure Boot to recover. Make sure you have an up-to-date VeraCrypt Rescue Disk. Warning: The embedded signature of the Windows Boot Manager used by VeraCrypt (bootmgfw_ms.vc) is still issued by Microsoft Windows Production PCA 2011, although firmware db already contains Windows UEFI CA 2023. Its known CA is currently allowed, but it will no longer start after the PCA 2011 certificate is added to dbx.\n\nDo not apply the PCA 2011 revocation (AvailableUpdates bit 0x80, including combined value 0x280) yet. First complete the Windows 2023 boot-manager update while the VeraCrypt System Favorites service is enabled, then run VeraCrypt Repair/Reinstall so VeraCrypt can import a compatible serviced EFI_EX/EFI copy. Verify the embedded issuer of bootmgfw_ms.vc is Windows UEFI CA 2023 and make sure you have an up-to-date VeraCrypt Rescue Disk. + Outer p&assword: + Operation failed while hidden volume protection was enabled.\n\nUse the OUTER volume password, PIM, KDF, and keyfile(s), if any, in the main password dialog. Use the HIDDEN volume password, PIM, KDF, and keyfile(s), if any, in Mount Options > Hidden Volume Protection.\n\nOne or more credentials may be incorrect, or the volume may be invalid or unsupported. + OUTER volume (this dialog): password, PIM, KDF, and keyfile(s).\nHIDDEN volume (Mount Options): password, PIM, KDF, and keyfile(s). diff --git a/Translations/Language.my.xml b/Translations/Language.my.xml index 323e9fd10e..a0d9aad935 100644 --- a/Translations/Language.my.xml +++ b/Translations/Language.my.xml @@ -1693,6 +1693,9 @@ Warning: VeraCrypt could not validate the installed EFI bootloader files against one complete embedded resource set and confirm that all known required signing CAs are present in db and not listed by dbx. Firmware may reject VeraCrypt when Secure Boot is enabled.\n\nBefore booting with Secure Boot enabled, restore the required Microsoft certificates and current dbx as needed, then run VeraCrypt Repair/Reinstall. Do not remove Microsoft Corporation UEFI CA 2011 until db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and the actual installed files match VeraCrypt's 2023 set. This check cannot model every image-hash or security-version revocation. Make sure you have an up-to-date VeraCrypt Rescue Disk. Warning: VeraCrypt could not validate the embedded signature and known-CA compatibility of the Windows Boot Manager it chainloads (bootmgfw_ms.vc). The file may be missing, unreadable, not a Windows Boot Manager, have an unrecognized embedded signer, or use a known signing CA that is absent from db or listed by dbx. The handoff to Windows may fail when Secure Boot is enabled.\n\nComplete or repair the Windows Secure Boot certificate and boot-manager update, keep the VeraCrypt System Favorites service enabled, and run VeraCrypt Repair/Reinstall. Repair also checks Windows' serviced EFI_EX/EFI copies for a compatible current Boot Manager. If Windows cannot start, temporarily disable Secure Boot to recover. Make sure you have an up-to-date VeraCrypt Rescue Disk. Warning: The embedded signature of the Windows Boot Manager used by VeraCrypt (bootmgfw_ms.vc) is still issued by Microsoft Windows Production PCA 2011, although firmware db already contains Windows UEFI CA 2023. Its known CA is currently allowed, but it will no longer start after the PCA 2011 certificate is added to dbx.\n\nDo not apply the PCA 2011 revocation (AvailableUpdates bit 0x80, including combined value 0x280) yet. First complete the Windows 2023 boot-manager update while the VeraCrypt System Favorites service is enabled, then run VeraCrypt Repair/Reinstall so VeraCrypt can import a compatible serviced EFI_EX/EFI copy. Verify the embedded issuer of bootmgfw_ms.vc is Windows UEFI CA 2023 and make sure you have an up-to-date VeraCrypt Rescue Disk. + Outer p&assword: + Operation failed while hidden volume protection was enabled.\n\nUse the OUTER volume password, PIM, KDF, and keyfile(s), if any, in the main password dialog. Use the HIDDEN volume password, PIM, KDF, and keyfile(s), if any, in Mount Options > Hidden Volume Protection.\n\nOne or more credentials may be incorrect, or the volume may be invalid or unsupported. + OUTER volume (this dialog): password, PIM, KDF, and keyfile(s).\nHIDDEN volume (Mount Options): password, PIM, KDF, and keyfile(s). diff --git a/Translations/Language.nb.xml b/Translations/Language.nb.xml index 0b8fe0a3ec..6d4ea9546d 100644 --- a/Translations/Language.nb.xml +++ b/Translations/Language.nb.xml @@ -1691,6 +1691,9 @@ Warning: VeraCrypt could not validate the installed EFI bootloader files against one complete embedded resource set and confirm that all known required signing CAs are present in db and not listed by dbx. Firmware may reject VeraCrypt when Secure Boot is enabled.\n\nBefore booting with Secure Boot enabled, restore the required Microsoft certificates and current dbx as needed, then run VeraCrypt Repair/Reinstall. Do not remove Microsoft Corporation UEFI CA 2011 until db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and the actual installed files match VeraCrypt's 2023 set. This check cannot model every image-hash or security-version revocation. Make sure you have an up-to-date VeraCrypt Rescue Disk. Warning: VeraCrypt could not validate the embedded signature and known-CA compatibility of the Windows Boot Manager it chainloads (bootmgfw_ms.vc). The file may be missing, unreadable, not a Windows Boot Manager, have an unrecognized embedded signer, or use a known signing CA that is absent from db or listed by dbx. The handoff to Windows may fail when Secure Boot is enabled.\n\nComplete or repair the Windows Secure Boot certificate and boot-manager update, keep the VeraCrypt System Favorites service enabled, and run VeraCrypt Repair/Reinstall. Repair also checks Windows' serviced EFI_EX/EFI copies for a compatible current Boot Manager. If Windows cannot start, temporarily disable Secure Boot to recover. Make sure you have an up-to-date VeraCrypt Rescue Disk. Warning: The embedded signature of the Windows Boot Manager used by VeraCrypt (bootmgfw_ms.vc) is still issued by Microsoft Windows Production PCA 2011, although firmware db already contains Windows UEFI CA 2023. Its known CA is currently allowed, but it will no longer start after the PCA 2011 certificate is added to dbx.\n\nDo not apply the PCA 2011 revocation (AvailableUpdates bit 0x80, including combined value 0x280) yet. First complete the Windows 2023 boot-manager update while the VeraCrypt System Favorites service is enabled, then run VeraCrypt Repair/Reinstall so VeraCrypt can import a compatible serviced EFI_EX/EFI copy. Verify the embedded issuer of bootmgfw_ms.vc is Windows UEFI CA 2023 and make sure you have an up-to-date VeraCrypt Rescue Disk. + Outer p&assword: + Operation failed while hidden volume protection was enabled.\n\nUse the OUTER volume password, PIM, KDF, and keyfile(s), if any, in the main password dialog. Use the HIDDEN volume password, PIM, KDF, and keyfile(s), if any, in Mount Options > Hidden Volume Protection.\n\nOne or more credentials may be incorrect, or the volume may be invalid or unsupported. + OUTER volume (this dialog): password, PIM, KDF, and keyfile(s).\nHIDDEN volume (Mount Options): password, PIM, KDF, and keyfile(s). diff --git a/Translations/Language.nl.xml b/Translations/Language.nl.xml index 063a55442a..c48373b963 100644 --- a/Translations/Language.nl.xml +++ b/Translations/Language.nl.xml @@ -1691,6 +1691,9 @@ Warning: VeraCrypt could not validate the installed EFI bootloader files against one complete embedded resource set and confirm that all known required signing CAs are present in db and not listed by dbx. Firmware may reject VeraCrypt when Secure Boot is enabled.\n\nBefore booting with Secure Boot enabled, restore the required Microsoft certificates and current dbx as needed, then run VeraCrypt Repair/Reinstall. Do not remove Microsoft Corporation UEFI CA 2011 until db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and the actual installed files match VeraCrypt's 2023 set. This check cannot model every image-hash or security-version revocation. Make sure you have an up-to-date VeraCrypt Rescue Disk. Warning: VeraCrypt could not validate the embedded signature and known-CA compatibility of the Windows Boot Manager it chainloads (bootmgfw_ms.vc). The file may be missing, unreadable, not a Windows Boot Manager, have an unrecognized embedded signer, or use a known signing CA that is absent from db or listed by dbx. The handoff to Windows may fail when Secure Boot is enabled.\n\nComplete or repair the Windows Secure Boot certificate and boot-manager update, keep the VeraCrypt System Favorites service enabled, and run VeraCrypt Repair/Reinstall. Repair also checks Windows' serviced EFI_EX/EFI copies for a compatible current Boot Manager. If Windows cannot start, temporarily disable Secure Boot to recover. Make sure you have an up-to-date VeraCrypt Rescue Disk. Warning: The embedded signature of the Windows Boot Manager used by VeraCrypt (bootmgfw_ms.vc) is still issued by Microsoft Windows Production PCA 2011, although firmware db already contains Windows UEFI CA 2023. Its known CA is currently allowed, but it will no longer start after the PCA 2011 certificate is added to dbx.\n\nDo not apply the PCA 2011 revocation (AvailableUpdates bit 0x80, including combined value 0x280) yet. First complete the Windows 2023 boot-manager update while the VeraCrypt System Favorites service is enabled, then run VeraCrypt Repair/Reinstall so VeraCrypt can import a compatible serviced EFI_EX/EFI copy. Verify the embedded issuer of bootmgfw_ms.vc is Windows UEFI CA 2023 and make sure you have an up-to-date VeraCrypt Rescue Disk. + Outer p&assword: + Operation failed while hidden volume protection was enabled.\n\nUse the OUTER volume password, PIM, KDF, and keyfile(s), if any, in the main password dialog. Use the HIDDEN volume password, PIM, KDF, and keyfile(s), if any, in Mount Options > Hidden Volume Protection.\n\nOne or more credentials may be incorrect, or the volume may be invalid or unsupported. + OUTER volume (this dialog): password, PIM, KDF, and keyfile(s).\nHIDDEN volume (Mount Options): password, PIM, KDF, and keyfile(s). diff --git a/Translations/Language.nn.xml b/Translations/Language.nn.xml index d0386f5000..f187641248 100644 --- a/Translations/Language.nn.xml +++ b/Translations/Language.nn.xml @@ -1691,6 +1691,9 @@ Warning: VeraCrypt could not validate the installed EFI bootloader files against one complete embedded resource set and confirm that all known required signing CAs are present in db and not listed by dbx. Firmware may reject VeraCrypt when Secure Boot is enabled.\n\nBefore booting with Secure Boot enabled, restore the required Microsoft certificates and current dbx as needed, then run VeraCrypt Repair/Reinstall. Do not remove Microsoft Corporation UEFI CA 2011 until db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and the actual installed files match VeraCrypt's 2023 set. This check cannot model every image-hash or security-version revocation. Make sure you have an up-to-date VeraCrypt Rescue Disk. Warning: VeraCrypt could not validate the embedded signature and known-CA compatibility of the Windows Boot Manager it chainloads (bootmgfw_ms.vc). The file may be missing, unreadable, not a Windows Boot Manager, have an unrecognized embedded signer, or use a known signing CA that is absent from db or listed by dbx. The handoff to Windows may fail when Secure Boot is enabled.\n\nComplete or repair the Windows Secure Boot certificate and boot-manager update, keep the VeraCrypt System Favorites service enabled, and run VeraCrypt Repair/Reinstall. Repair also checks Windows' serviced EFI_EX/EFI copies for a compatible current Boot Manager. If Windows cannot start, temporarily disable Secure Boot to recover. Make sure you have an up-to-date VeraCrypt Rescue Disk. Warning: The embedded signature of the Windows Boot Manager used by VeraCrypt (bootmgfw_ms.vc) is still issued by Microsoft Windows Production PCA 2011, although firmware db already contains Windows UEFI CA 2023. Its known CA is currently allowed, but it will no longer start after the PCA 2011 certificate is added to dbx.\n\nDo not apply the PCA 2011 revocation (AvailableUpdates bit 0x80, including combined value 0x280) yet. First complete the Windows 2023 boot-manager update while the VeraCrypt System Favorites service is enabled, then run VeraCrypt Repair/Reinstall so VeraCrypt can import a compatible serviced EFI_EX/EFI copy. Verify the embedded issuer of bootmgfw_ms.vc is Windows UEFI CA 2023 and make sure you have an up-to-date VeraCrypt Rescue Disk. + Outer p&assword: + Operation failed while hidden volume protection was enabled.\n\nUse the OUTER volume password, PIM, KDF, and keyfile(s), if any, in the main password dialog. Use the HIDDEN volume password, PIM, KDF, and keyfile(s), if any, in Mount Options > Hidden Volume Protection.\n\nOne or more credentials may be incorrect, or the volume may be invalid or unsupported. + OUTER volume (this dialog): password, PIM, KDF, and keyfile(s).\nHIDDEN volume (Mount Options): password, PIM, KDF, and keyfile(s). diff --git a/Translations/Language.pl.xml b/Translations/Language.pl.xml index f1d5d43667..2acb26a400 100644 --- a/Translations/Language.pl.xml +++ b/Translations/Language.pl.xml @@ -1691,6 +1691,9 @@ Ostrzeżenie: VeraCrypt nie może zweryfikować zainstalowanych plików programu rozruchowego EFI względem jednego pełnego osadzonego zestawu zasobów ani potwierdzić, że wszystkie znane wymagane urzędy certyfikacji znajdują się w db i nie są wymienione w dbx. Oprogramowanie układowe może odrzucić VeraCrypt po włączeniu Secure Boot.\n\nPrzed uruchomieniem z włączonym Secure Boot przywróć wymagane certyfikaty Microsoft i aktualną dbx, a następnie uruchom naprawę/ponowną instalację VeraCrypt. Nie usuwaj Microsoft Corporation UEFI CA 2011, dopóki db nie zawiera obu certyfikatów Microsoft UEFI CA 2023 i Microsoft Option ROM UEFI CA 2023, a faktycznie zainstalowane pliki nie odpowiadają zestawowi VeraCrypt 2023. To sprawdzenie nie obejmuje wszystkich odwołań skrótów obrazów ani wersji zabezpieczeń. Upewnij się, że masz aktualny Dysk Ratunkowy VeraCrypt. Ostrzeżenie: VeraCrypt nie może zweryfikować osadzonego podpisu ani zgodności znanych CA Menedżera rozruchu Windows używanego do przekazania sterowania (bootmgfw_ms.vc). Plik może nie istnieć, być nieczytelny lub nie być Menedżerem rozruchu Windows; jego osadzony podpisujący może być nierozpoznany albo znany CA podpisujący może być nieobecny w db lub wymieniony w dbx. Przekazanie sterowania do Windows może się nie powieść po włączeniu Secure Boot.\n\nDokończ lub napraw aktualizację certyfikatów Secure Boot i Menedżera rozruchu Windows, pozostaw włączoną usługę VeraCrypt System Favorites i uruchom naprawę/ponowną instalację VeraCrypt. Naprawa sprawdza również obsługiwane przez Windows kopie EFI_EX/EFI w poszukiwaniu zgodnego aktualnego Menedżera rozruchu. Jeśli Windows nie uruchamia się, tymczasowo wyłącz Secure Boot. Upewnij się, że masz aktualny Dysk Ratunkowy VeraCrypt. Ostrzeżenie: Osadzony podpis Menedżera rozruchu Windows używanego przez VeraCrypt (bootmgfw_ms.vc) jest nadal wystawiony przez Microsoft Windows Production PCA 2011, mimo że db oprogramowania układowego zawiera już Windows UEFI CA 2023. Znany CA jest obecnie dozwolony, lecz plik przestanie się uruchamiać po dodaniu certyfikatu PCA 2011 do dbx.\n\nNie stosuj jeszcze odwołania PCA 2011 (bit 0x80 wartości AvailableUpdates, również w połączonej wartości 0x280). Najpierw dokończ aktualizację Menedżera rozruchu Windows 2023 przy włączonej usłudze VeraCrypt System Favorites, a następnie uruchom naprawę/ponowną instalację VeraCrypt, aby program mógł zaimportować zgodną obsługiwaną kopię EFI_EX/EFI. Sprawdź, czy osadzonym wystawcą bootmgfw_ms.vc jest Windows UEFI CA 2023, i upewnij się, że masz aktualny Dysk Ratunkowy VeraCrypt. + Outer p&assword: + Operation failed while hidden volume protection was enabled.\n\nUse the OUTER volume password, PIM, KDF, and keyfile(s), if any, in the main password dialog. Use the HIDDEN volume password, PIM, KDF, and keyfile(s), if any, in Mount Options > Hidden Volume Protection.\n\nOne or more credentials may be incorrect, or the volume may be invalid or unsupported. + OUTER volume (this dialog): password, PIM, KDF, and keyfile(s).\nHIDDEN volume (Mount Options): password, PIM, KDF, and keyfile(s). diff --git a/Translations/Language.pt-br.xml b/Translations/Language.pt-br.xml index 0062f6b239..fa2335d233 100644 --- a/Translations/Language.pt-br.xml +++ b/Translations/Language.pt-br.xml @@ -1691,6 +1691,9 @@ Warning: VeraCrypt could not validate the installed EFI bootloader files against one complete embedded resource set and confirm that all known required signing CAs are present in db and not listed by dbx. Firmware may reject VeraCrypt when Secure Boot is enabled.\n\nBefore booting with Secure Boot enabled, restore the required Microsoft certificates and current dbx as needed, then run VeraCrypt Repair/Reinstall. Do not remove Microsoft Corporation UEFI CA 2011 until db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and the actual installed files match VeraCrypt's 2023 set. This check cannot model every image-hash or security-version revocation. Make sure you have an up-to-date VeraCrypt Rescue Disk. Warning: VeraCrypt could not validate the embedded signature and known-CA compatibility of the Windows Boot Manager it chainloads (bootmgfw_ms.vc). The file may be missing, unreadable, not a Windows Boot Manager, have an unrecognized embedded signer, or use a known signing CA that is absent from db or listed by dbx. The handoff to Windows may fail when Secure Boot is enabled.\n\nComplete or repair the Windows Secure Boot certificate and boot-manager update, keep the VeraCrypt System Favorites service enabled, and run VeraCrypt Repair/Reinstall. Repair also checks Windows' serviced EFI_EX/EFI copies for a compatible current Boot Manager. If Windows cannot start, temporarily disable Secure Boot to recover. Make sure you have an up-to-date VeraCrypt Rescue Disk. Warning: The embedded signature of the Windows Boot Manager used by VeraCrypt (bootmgfw_ms.vc) is still issued by Microsoft Windows Production PCA 2011, although firmware db already contains Windows UEFI CA 2023. Its known CA is currently allowed, but it will no longer start after the PCA 2011 certificate is added to dbx.\n\nDo not apply the PCA 2011 revocation (AvailableUpdates bit 0x80, including combined value 0x280) yet. First complete the Windows 2023 boot-manager update while the VeraCrypt System Favorites service is enabled, then run VeraCrypt Repair/Reinstall so VeraCrypt can import a compatible serviced EFI_EX/EFI copy. Verify the embedded issuer of bootmgfw_ms.vc is Windows UEFI CA 2023 and make sure you have an up-to-date VeraCrypt Rescue Disk. + Outer p&assword: + Operation failed while hidden volume protection was enabled.\n\nUse the OUTER volume password, PIM, KDF, and keyfile(s), if any, in the main password dialog. Use the HIDDEN volume password, PIM, KDF, and keyfile(s), if any, in Mount Options > Hidden Volume Protection.\n\nOne or more credentials may be incorrect, or the volume may be invalid or unsupported. + OUTER volume (this dialog): password, PIM, KDF, and keyfile(s).\nHIDDEN volume (Mount Options): password, PIM, KDF, and keyfile(s). diff --git a/Translations/Language.ro.xml b/Translations/Language.ro.xml index 579db09333..8aad4aaf75 100644 --- a/Translations/Language.ro.xml +++ b/Translations/Language.ro.xml @@ -1691,6 +1691,9 @@ Warning: VeraCrypt could not validate the installed EFI bootloader files against one complete embedded resource set and confirm that all known required signing CAs are present in db and not listed by dbx. Firmware may reject VeraCrypt when Secure Boot is enabled.\n\nBefore booting with Secure Boot enabled, restore the required Microsoft certificates and current dbx as needed, then run VeraCrypt Repair/Reinstall. Do not remove Microsoft Corporation UEFI CA 2011 until db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and the actual installed files match VeraCrypt's 2023 set. This check cannot model every image-hash or security-version revocation. Make sure you have an up-to-date VeraCrypt Rescue Disk. Warning: VeraCrypt could not validate the embedded signature and known-CA compatibility of the Windows Boot Manager it chainloads (bootmgfw_ms.vc). The file may be missing, unreadable, not a Windows Boot Manager, have an unrecognized embedded signer, or use a known signing CA that is absent from db or listed by dbx. The handoff to Windows may fail when Secure Boot is enabled.\n\nComplete or repair the Windows Secure Boot certificate and boot-manager update, keep the VeraCrypt System Favorites service enabled, and run VeraCrypt Repair/Reinstall. Repair also checks Windows' serviced EFI_EX/EFI copies for a compatible current Boot Manager. If Windows cannot start, temporarily disable Secure Boot to recover. Make sure you have an up-to-date VeraCrypt Rescue Disk. Warning: The embedded signature of the Windows Boot Manager used by VeraCrypt (bootmgfw_ms.vc) is still issued by Microsoft Windows Production PCA 2011, although firmware db already contains Windows UEFI CA 2023. Its known CA is currently allowed, but it will no longer start after the PCA 2011 certificate is added to dbx.\n\nDo not apply the PCA 2011 revocation (AvailableUpdates bit 0x80, including combined value 0x280) yet. First complete the Windows 2023 boot-manager update while the VeraCrypt System Favorites service is enabled, then run VeraCrypt Repair/Reinstall so VeraCrypt can import a compatible serviced EFI_EX/EFI copy. Verify the embedded issuer of bootmgfw_ms.vc is Windows UEFI CA 2023 and make sure you have an up-to-date VeraCrypt Rescue Disk. + Outer p&assword: + Operation failed while hidden volume protection was enabled.\n\nUse the OUTER volume password, PIM, KDF, and keyfile(s), if any, in the main password dialog. Use the HIDDEN volume password, PIM, KDF, and keyfile(s), if any, in Mount Options > Hidden Volume Protection.\n\nOne or more credentials may be incorrect, or the volume may be invalid or unsupported. + OUTER volume (this dialog): password, PIM, KDF, and keyfile(s).\nHIDDEN volume (Mount Options): password, PIM, KDF, and keyfile(s). diff --git a/Translations/Language.ru.xml b/Translations/Language.ru.xml index b8ab6d36a8..2e029fb6b4 100644 --- a/Translations/Language.ru.xml +++ b/Translations/Language.ru.xml @@ -1691,6 +1691,9 @@ Warning: VeraCrypt could not validate the installed EFI bootloader files against one complete embedded resource set and confirm that all known required signing CAs are present in db and not listed by dbx. Firmware may reject VeraCrypt when Secure Boot is enabled.\n\nBefore booting with Secure Boot enabled, restore the required Microsoft certificates and current dbx as needed, then run VeraCrypt Repair/Reinstall. Do not remove Microsoft Corporation UEFI CA 2011 until db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and the actual installed files match VeraCrypt's 2023 set. This check cannot model every image-hash or security-version revocation. Make sure you have an up-to-date VeraCrypt Rescue Disk. Warning: VeraCrypt could not validate the embedded signature and known-CA compatibility of the Windows Boot Manager it chainloads (bootmgfw_ms.vc). The file may be missing, unreadable, not a Windows Boot Manager, have an unrecognized embedded signer, or use a known signing CA that is absent from db or listed by dbx. The handoff to Windows may fail when Secure Boot is enabled.\n\nComplete or repair the Windows Secure Boot certificate and boot-manager update, keep the VeraCrypt System Favorites service enabled, and run VeraCrypt Repair/Reinstall. Repair also checks Windows' serviced EFI_EX/EFI copies for a compatible current Boot Manager. If Windows cannot start, temporarily disable Secure Boot to recover. Make sure you have an up-to-date VeraCrypt Rescue Disk. Warning: The embedded signature of the Windows Boot Manager used by VeraCrypt (bootmgfw_ms.vc) is still issued by Microsoft Windows Production PCA 2011, although firmware db already contains Windows UEFI CA 2023. Its known CA is currently allowed, but it will no longer start after the PCA 2011 certificate is added to dbx.\n\nDo not apply the PCA 2011 revocation (AvailableUpdates bit 0x80, including combined value 0x280) yet. First complete the Windows 2023 boot-manager update while the VeraCrypt System Favorites service is enabled, then run VeraCrypt Repair/Reinstall so VeraCrypt can import a compatible serviced EFI_EX/EFI copy. Verify the embedded issuer of bootmgfw_ms.vc is Windows UEFI CA 2023 and make sure you have an up-to-date VeraCrypt Rescue Disk. + Outer p&assword: + Operation failed while hidden volume protection was enabled.\n\nUse the OUTER volume password, PIM, KDF, and keyfile(s), if any, in the main password dialog. Use the HIDDEN volume password, PIM, KDF, and keyfile(s), if any, in Mount Options > Hidden Volume Protection.\n\nOne or more credentials may be incorrect, or the volume may be invalid or unsupported. + OUTER volume (this dialog): password, PIM, KDF, and keyfile(s).\nHIDDEN volume (Mount Options): password, PIM, KDF, and keyfile(s). diff --git a/Translations/Language.sk.xml b/Translations/Language.sk.xml index 04289aa8a7..efd22a6b5c 100644 --- a/Translations/Language.sk.xml +++ b/Translations/Language.sk.xml @@ -1691,6 +1691,9 @@ Warning: VeraCrypt could not validate the installed EFI bootloader files against one complete embedded resource set and confirm that all known required signing CAs are present in db and not listed by dbx. Firmware may reject VeraCrypt when Secure Boot is enabled.\n\nBefore booting with Secure Boot enabled, restore the required Microsoft certificates and current dbx as needed, then run VeraCrypt Repair/Reinstall. Do not remove Microsoft Corporation UEFI CA 2011 until db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and the actual installed files match VeraCrypt's 2023 set. This check cannot model every image-hash or security-version revocation. Make sure you have an up-to-date VeraCrypt Rescue Disk. Warning: VeraCrypt could not validate the embedded signature and known-CA compatibility of the Windows Boot Manager it chainloads (bootmgfw_ms.vc). The file may be missing, unreadable, not a Windows Boot Manager, have an unrecognized embedded signer, or use a known signing CA that is absent from db or listed by dbx. The handoff to Windows may fail when Secure Boot is enabled.\n\nComplete or repair the Windows Secure Boot certificate and boot-manager update, keep the VeraCrypt System Favorites service enabled, and run VeraCrypt Repair/Reinstall. Repair also checks Windows' serviced EFI_EX/EFI copies for a compatible current Boot Manager. If Windows cannot start, temporarily disable Secure Boot to recover. Make sure you have an up-to-date VeraCrypt Rescue Disk. Warning: The embedded signature of the Windows Boot Manager used by VeraCrypt (bootmgfw_ms.vc) is still issued by Microsoft Windows Production PCA 2011, although firmware db already contains Windows UEFI CA 2023. Its known CA is currently allowed, but it will no longer start after the PCA 2011 certificate is added to dbx.\n\nDo not apply the PCA 2011 revocation (AvailableUpdates bit 0x80, including combined value 0x280) yet. First complete the Windows 2023 boot-manager update while the VeraCrypt System Favorites service is enabled, then run VeraCrypt Repair/Reinstall so VeraCrypt can import a compatible serviced EFI_EX/EFI copy. Verify the embedded issuer of bootmgfw_ms.vc is Windows UEFI CA 2023 and make sure you have an up-to-date VeraCrypt Rescue Disk. + Outer p&assword: + Operation failed while hidden volume protection was enabled.\n\nUse the OUTER volume password, PIM, KDF, and keyfile(s), if any, in the main password dialog. Use the HIDDEN volume password, PIM, KDF, and keyfile(s), if any, in Mount Options > Hidden Volume Protection.\n\nOne or more credentials may be incorrect, or the volume may be invalid or unsupported. + OUTER volume (this dialog): password, PIM, KDF, and keyfile(s).\nHIDDEN volume (Mount Options): password, PIM, KDF, and keyfile(s). diff --git a/Translations/Language.sl.xml b/Translations/Language.sl.xml index 084205b0fc..f1636948e1 100644 --- a/Translations/Language.sl.xml +++ b/Translations/Language.sl.xml @@ -1691,6 +1691,9 @@ Warning: VeraCrypt could not validate the installed EFI bootloader files against one complete embedded resource set and confirm that all known required signing CAs are present in db and not listed by dbx. Firmware may reject VeraCrypt when Secure Boot is enabled.\n\nBefore booting with Secure Boot enabled, restore the required Microsoft certificates and current dbx as needed, then run VeraCrypt Repair/Reinstall. Do not remove Microsoft Corporation UEFI CA 2011 until db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and the actual installed files match VeraCrypt's 2023 set. This check cannot model every image-hash or security-version revocation. Make sure you have an up-to-date VeraCrypt Rescue Disk. Warning: VeraCrypt could not validate the embedded signature and known-CA compatibility of the Windows Boot Manager it chainloads (bootmgfw_ms.vc). The file may be missing, unreadable, not a Windows Boot Manager, have an unrecognized embedded signer, or use a known signing CA that is absent from db or listed by dbx. The handoff to Windows may fail when Secure Boot is enabled.\n\nComplete or repair the Windows Secure Boot certificate and boot-manager update, keep the VeraCrypt System Favorites service enabled, and run VeraCrypt Repair/Reinstall. Repair also checks Windows' serviced EFI_EX/EFI copies for a compatible current Boot Manager. If Windows cannot start, temporarily disable Secure Boot to recover. Make sure you have an up-to-date VeraCrypt Rescue Disk. Warning: The embedded signature of the Windows Boot Manager used by VeraCrypt (bootmgfw_ms.vc) is still issued by Microsoft Windows Production PCA 2011, although firmware db already contains Windows UEFI CA 2023. Its known CA is currently allowed, but it will no longer start after the PCA 2011 certificate is added to dbx.\n\nDo not apply the PCA 2011 revocation (AvailableUpdates bit 0x80, including combined value 0x280) yet. First complete the Windows 2023 boot-manager update while the VeraCrypt System Favorites service is enabled, then run VeraCrypt Repair/Reinstall so VeraCrypt can import a compatible serviced EFI_EX/EFI copy. Verify the embedded issuer of bootmgfw_ms.vc is Windows UEFI CA 2023 and make sure you have an up-to-date VeraCrypt Rescue Disk. + Outer p&assword: + Operation failed while hidden volume protection was enabled.\n\nUse the OUTER volume password, PIM, KDF, and keyfile(s), if any, in the main password dialog. Use the HIDDEN volume password, PIM, KDF, and keyfile(s), if any, in Mount Options > Hidden Volume Protection.\n\nOne or more credentials may be incorrect, or the volume may be invalid or unsupported. + OUTER volume (this dialog): password, PIM, KDF, and keyfile(s).\nHIDDEN volume (Mount Options): password, PIM, KDF, and keyfile(s). diff --git a/Translations/Language.sv.xml b/Translations/Language.sv.xml index 264fa04bee..57788ba2b1 100644 --- a/Translations/Language.sv.xml +++ b/Translations/Language.sv.xml @@ -1691,6 +1691,9 @@ Varning: VeraCrypt kunde inte validera de installerade EFI-startinläsarfilerna mot en fullständig uppsättning inbäddade resurser och bekräfta att alla kända certifikatutfärdare som krävs för signering finns i db och inte är upptagna i dbx. Den fasta programvaran kan avvisa VeraCrypt när Secure Boot är aktiverat.\n\nInnan du startar med Secure Boot aktiverat ska du vid behov återställa de Microsoft-certifikat som krävs och en aktuell dbx och därefter köra Reparera/installera om i VeraCrypt. Ta inte bort Microsoft Corporation UEFI CA 2011 förrän db innehåller både Microsoft UEFI CA 2023 och Microsoft Option ROM UEFI CA 2023 och de installerade filerna faktiskt motsvarar VeraCrypts uppsättning för 2023. Den här kontrollen kan inte ta hänsyn till varje återkallande som baseras på avbildningshashar eller säkerhetsversioner. Kontrollera att du har en aktuell VeraCrypt-återställningsdisk. Varning: VeraCrypt kunde inte validera den inbäddade signaturen och kompatibiliteten med kända certifikatutfärdare för Windows-starthanteraren som VeraCrypt kedjestartar (bootmgfw_ms.vc). Filen kan saknas, vara oläsbar, inte vara en Windows-starthanterare, ha en okänd inbäddad signerare eller använda en känd certifikatutfärdare som saknas i db eller finns i dbx. Överlämningen till Windows kan misslyckas när Secure Boot är aktiverat.\n\nSlutför eller reparera uppdateringen av Windows Secure Boot-certifikat och starthanterare, låt tjänsten VeraCrypt System Favorites vara aktiverad och kör Reparera/installera om i VeraCrypt. Reparationen kontrollerar även de EFI_EX-/EFI-kopior som Windows har uppdaterat för att hitta en kompatibel aktuell starthanterare. Inaktivera Secure Boot tillfälligt för återställning om Windows inte kan starta. Kontrollera att du har en aktuell VeraCrypt-återställningsdisk. Varning: Den inbäddade signaturen för den Windows-starthanterare som VeraCrypt använder (bootmgfw_ms.vc) är fortfarande utfärdad av Microsoft Windows Production PCA 2011, trots att den fasta programvarans db redan innehåller Windows UEFI CA 2023. Den kända certifikatutfärdaren är för närvarande tillåten, men starthanteraren kommer inte längre att kunna starta när PCA 2011-certifikatet har lagts till i dbx.\n\nVerkställ ännu inte återkallelsen av PCA 2011 (AvailableUpdates-bit 0x80, inklusive det kombinerade värdet 0x280). Slutför först Windows 2023-uppdatering av starthanteraren medan tjänsten VeraCrypt System Favorites är aktiverad och kör sedan Reparera/installera om i VeraCrypt, så att VeraCrypt kan importera en kompatibel EFI_EX-/EFI-kopia som Windows har uppdaterat. Kontrollera att den inbäddade utfärdaren för bootmgfw_ms.vc är Windows UEFI CA 2023 och att du har en aktuell VeraCrypt-återställningsdisk. + Outer p&assword: + Operation failed while hidden volume protection was enabled.\n\nUse the OUTER volume password, PIM, KDF, and keyfile(s), if any, in the main password dialog. Use the HIDDEN volume password, PIM, KDF, and keyfile(s), if any, in Mount Options > Hidden Volume Protection.\n\nOne or more credentials may be incorrect, or the volume may be invalid or unsupported. + OUTER volume (this dialog): password, PIM, KDF, and keyfile(s).\nHIDDEN volume (Mount Options): password, PIM, KDF, and keyfile(s). diff --git a/Translations/Language.th.xml b/Translations/Language.th.xml index 2cccacafd5..389a2c1b0c 100644 --- a/Translations/Language.th.xml +++ b/Translations/Language.th.xml @@ -1691,6 +1691,9 @@ Warning: VeraCrypt could not validate the installed EFI bootloader files against one complete embedded resource set and confirm that all known required signing CAs are present in db and not listed by dbx. Firmware may reject VeraCrypt when Secure Boot is enabled.\n\nBefore booting with Secure Boot enabled, restore the required Microsoft certificates and current dbx as needed, then run VeraCrypt Repair/Reinstall. Do not remove Microsoft Corporation UEFI CA 2011 until db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and the actual installed files match VeraCrypt's 2023 set. This check cannot model every image-hash or security-version revocation. Make sure you have an up-to-date VeraCrypt Rescue Disk. Warning: VeraCrypt could not validate the embedded signature and known-CA compatibility of the Windows Boot Manager it chainloads (bootmgfw_ms.vc). The file may be missing, unreadable, not a Windows Boot Manager, have an unrecognized embedded signer, or use a known signing CA that is absent from db or listed by dbx. The handoff to Windows may fail when Secure Boot is enabled.\n\nComplete or repair the Windows Secure Boot certificate and boot-manager update, keep the VeraCrypt System Favorites service enabled, and run VeraCrypt Repair/Reinstall. Repair also checks Windows' serviced EFI_EX/EFI copies for a compatible current Boot Manager. If Windows cannot start, temporarily disable Secure Boot to recover. Make sure you have an up-to-date VeraCrypt Rescue Disk. Warning: The embedded signature of the Windows Boot Manager used by VeraCrypt (bootmgfw_ms.vc) is still issued by Microsoft Windows Production PCA 2011, although firmware db already contains Windows UEFI CA 2023. Its known CA is currently allowed, but it will no longer start after the PCA 2011 certificate is added to dbx.\n\nDo not apply the PCA 2011 revocation (AvailableUpdates bit 0x80, including combined value 0x280) yet. First complete the Windows 2023 boot-manager update while the VeraCrypt System Favorites service is enabled, then run VeraCrypt Repair/Reinstall so VeraCrypt can import a compatible serviced EFI_EX/EFI copy. Verify the embedded issuer of bootmgfw_ms.vc is Windows UEFI CA 2023 and make sure you have an up-to-date VeraCrypt Rescue Disk. + Outer p&assword: + Operation failed while hidden volume protection was enabled.\n\nUse the OUTER volume password, PIM, KDF, and keyfile(s), if any, in the main password dialog. Use the HIDDEN volume password, PIM, KDF, and keyfile(s), if any, in Mount Options > Hidden Volume Protection.\n\nOne or more credentials may be incorrect, or the volume may be invalid or unsupported. + OUTER volume (this dialog): password, PIM, KDF, and keyfile(s).\nHIDDEN volume (Mount Options): password, PIM, KDF, and keyfile(s). diff --git a/Translations/Language.tr.xml b/Translations/Language.tr.xml index c7fbb5ba26..45efb6fb8c 100644 --- a/Translations/Language.tr.xml +++ b/Translations/Language.tr.xml @@ -1691,6 +1691,9 @@ Warning: VeraCrypt could not validate the installed EFI bootloader files against one complete embedded resource set and confirm that all known required signing CAs are present in db and not listed by dbx. Firmware may reject VeraCrypt when Secure Boot is enabled.\n\nBefore booting with Secure Boot enabled, restore the required Microsoft certificates and current dbx as needed, then run VeraCrypt Repair/Reinstall. Do not remove Microsoft Corporation UEFI CA 2011 until db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and the actual installed files match VeraCrypt's 2023 set. This check cannot model every image-hash or security-version revocation. Make sure you have an up-to-date VeraCrypt Rescue Disk. Warning: VeraCrypt could not validate the embedded signature and known-CA compatibility of the Windows Boot Manager it chainloads (bootmgfw_ms.vc). The file may be missing, unreadable, not a Windows Boot Manager, have an unrecognized embedded signer, or use a known signing CA that is absent from db or listed by dbx. The handoff to Windows may fail when Secure Boot is enabled.\n\nComplete or repair the Windows Secure Boot certificate and boot-manager update, keep the VeraCrypt System Favorites service enabled, and run VeraCrypt Repair/Reinstall. Repair also checks Windows' serviced EFI_EX/EFI copies for a compatible current Boot Manager. If Windows cannot start, temporarily disable Secure Boot to recover. Make sure you have an up-to-date VeraCrypt Rescue Disk. Warning: The embedded signature of the Windows Boot Manager used by VeraCrypt (bootmgfw_ms.vc) is still issued by Microsoft Windows Production PCA 2011, although firmware db already contains Windows UEFI CA 2023. Its known CA is currently allowed, but it will no longer start after the PCA 2011 certificate is added to dbx.\n\nDo not apply the PCA 2011 revocation (AvailableUpdates bit 0x80, including combined value 0x280) yet. First complete the Windows 2023 boot-manager update while the VeraCrypt System Favorites service is enabled, then run VeraCrypt Repair/Reinstall so VeraCrypt can import a compatible serviced EFI_EX/EFI copy. Verify the embedded issuer of bootmgfw_ms.vc is Windows UEFI CA 2023 and make sure you have an up-to-date VeraCrypt Rescue Disk. + Outer p&assword: + Operation failed while hidden volume protection was enabled.\n\nUse the OUTER volume password, PIM, KDF, and keyfile(s), if any, in the main password dialog. Use the HIDDEN volume password, PIM, KDF, and keyfile(s), if any, in Mount Options > Hidden Volume Protection.\n\nOne or more credentials may be incorrect, or the volume may be invalid or unsupported. + OUTER volume (this dialog): password, PIM, KDF, and keyfile(s).\nHIDDEN volume (Mount Options): password, PIM, KDF, and keyfile(s). diff --git a/Translations/Language.uk.xml b/Translations/Language.uk.xml index 7fb5f7844b..a7ab7e70b2 100644 --- a/Translations/Language.uk.xml +++ b/Translations/Language.uk.xml @@ -1691,6 +1691,9 @@ Warning: VeraCrypt could not validate the installed EFI bootloader files against one complete embedded resource set and confirm that all known required signing CAs are present in db and not listed by dbx. Firmware may reject VeraCrypt when Secure Boot is enabled.\n\nBefore booting with Secure Boot enabled, restore the required Microsoft certificates and current dbx as needed, then run VeraCrypt Repair/Reinstall. Do not remove Microsoft Corporation UEFI CA 2011 until db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and the actual installed files match VeraCrypt's 2023 set. This check cannot model every image-hash or security-version revocation. Make sure you have an up-to-date VeraCrypt Rescue Disk. Warning: VeraCrypt could not validate the embedded signature and known-CA compatibility of the Windows Boot Manager it chainloads (bootmgfw_ms.vc). The file may be missing, unreadable, not a Windows Boot Manager, have an unrecognized embedded signer, or use a known signing CA that is absent from db or listed by dbx. The handoff to Windows may fail when Secure Boot is enabled.\n\nComplete or repair the Windows Secure Boot certificate and boot-manager update, keep the VeraCrypt System Favorites service enabled, and run VeraCrypt Repair/Reinstall. Repair also checks Windows' serviced EFI_EX/EFI copies for a compatible current Boot Manager. If Windows cannot start, temporarily disable Secure Boot to recover. Make sure you have an up-to-date VeraCrypt Rescue Disk. Warning: The embedded signature of the Windows Boot Manager used by VeraCrypt (bootmgfw_ms.vc) is still issued by Microsoft Windows Production PCA 2011, although firmware db already contains Windows UEFI CA 2023. Its known CA is currently allowed, but it will no longer start after the PCA 2011 certificate is added to dbx.\n\nDo not apply the PCA 2011 revocation (AvailableUpdates bit 0x80, including combined value 0x280) yet. First complete the Windows 2023 boot-manager update while the VeraCrypt System Favorites service is enabled, then run VeraCrypt Repair/Reinstall so VeraCrypt can import a compatible serviced EFI_EX/EFI copy. Verify the embedded issuer of bootmgfw_ms.vc is Windows UEFI CA 2023 and make sure you have an up-to-date VeraCrypt Rescue Disk. + Outer p&assword: + Operation failed while hidden volume protection was enabled.\n\nUse the OUTER volume password, PIM, KDF, and keyfile(s), if any, in the main password dialog. Use the HIDDEN volume password, PIM, KDF, and keyfile(s), if any, in Mount Options > Hidden Volume Protection.\n\nOne or more credentials may be incorrect, or the volume may be invalid or unsupported. + OUTER volume (this dialog): password, PIM, KDF, and keyfile(s).\nHIDDEN volume (Mount Options): password, PIM, KDF, and keyfile(s). diff --git a/Translations/Language.uz.xml b/Translations/Language.uz.xml index 8878c0eeb0..d376950b46 100644 --- a/Translations/Language.uz.xml +++ b/Translations/Language.uz.xml @@ -1691,6 +1691,9 @@ Warning: VeraCrypt could not validate the installed EFI bootloader files against one complete embedded resource set and confirm that all known required signing CAs are present in db and not listed by dbx. Firmware may reject VeraCrypt when Secure Boot is enabled.\n\nBefore booting with Secure Boot enabled, restore the required Microsoft certificates and current dbx as needed, then run VeraCrypt Repair/Reinstall. Do not remove Microsoft Corporation UEFI CA 2011 until db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and the actual installed files match VeraCrypt's 2023 set. This check cannot model every image-hash or security-version revocation. Make sure you have an up-to-date VeraCrypt Rescue Disk. Warning: VeraCrypt could not validate the embedded signature and known-CA compatibility of the Windows Boot Manager it chainloads (bootmgfw_ms.vc). The file may be missing, unreadable, not a Windows Boot Manager, have an unrecognized embedded signer, or use a known signing CA that is absent from db or listed by dbx. The handoff to Windows may fail when Secure Boot is enabled.\n\nComplete or repair the Windows Secure Boot certificate and boot-manager update, keep the VeraCrypt System Favorites service enabled, and run VeraCrypt Repair/Reinstall. Repair also checks Windows' serviced EFI_EX/EFI copies for a compatible current Boot Manager. If Windows cannot start, temporarily disable Secure Boot to recover. Make sure you have an up-to-date VeraCrypt Rescue Disk. Warning: The embedded signature of the Windows Boot Manager used by VeraCrypt (bootmgfw_ms.vc) is still issued by Microsoft Windows Production PCA 2011, although firmware db already contains Windows UEFI CA 2023. Its known CA is currently allowed, but it will no longer start after the PCA 2011 certificate is added to dbx.\n\nDo not apply the PCA 2011 revocation (AvailableUpdates bit 0x80, including combined value 0x280) yet. First complete the Windows 2023 boot-manager update while the VeraCrypt System Favorites service is enabled, then run VeraCrypt Repair/Reinstall so VeraCrypt can import a compatible serviced EFI_EX/EFI copy. Verify the embedded issuer of bootmgfw_ms.vc is Windows UEFI CA 2023 and make sure you have an up-to-date VeraCrypt Rescue Disk. + Outer p&assword: + Operation failed while hidden volume protection was enabled.\n\nUse the OUTER volume password, PIM, KDF, and keyfile(s), if any, in the main password dialog. Use the HIDDEN volume password, PIM, KDF, and keyfile(s), if any, in Mount Options > Hidden Volume Protection.\n\nOne or more credentials may be incorrect, or the volume may be invalid or unsupported. + OUTER volume (this dialog): password, PIM, KDF, and keyfile(s).\nHIDDEN volume (Mount Options): password, PIM, KDF, and keyfile(s). diff --git a/Translations/Language.vi.xml b/Translations/Language.vi.xml index 088035224f..608a302a2d 100644 --- a/Translations/Language.vi.xml +++ b/Translations/Language.vi.xml @@ -1691,6 +1691,9 @@ Warning: VeraCrypt could not validate the installed EFI bootloader files against one complete embedded resource set and confirm that all known required signing CAs are present in db and not listed by dbx. Firmware may reject VeraCrypt when Secure Boot is enabled.\n\nBefore booting with Secure Boot enabled, restore the required Microsoft certificates and current dbx as needed, then run VeraCrypt Repair/Reinstall. Do not remove Microsoft Corporation UEFI CA 2011 until db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and the actual installed files match VeraCrypt's 2023 set. This check cannot model every image-hash or security-version revocation. Make sure you have an up-to-date VeraCrypt Rescue Disk. Warning: VeraCrypt could not validate the embedded signature and known-CA compatibility of the Windows Boot Manager it chainloads (bootmgfw_ms.vc). The file may be missing, unreadable, not a Windows Boot Manager, have an unrecognized embedded signer, or use a known signing CA that is absent from db or listed by dbx. The handoff to Windows may fail when Secure Boot is enabled.\n\nComplete or repair the Windows Secure Boot certificate and boot-manager update, keep the VeraCrypt System Favorites service enabled, and run VeraCrypt Repair/Reinstall. Repair also checks Windows' serviced EFI_EX/EFI copies for a compatible current Boot Manager. If Windows cannot start, temporarily disable Secure Boot to recover. Make sure you have an up-to-date VeraCrypt Rescue Disk. Warning: The embedded signature of the Windows Boot Manager used by VeraCrypt (bootmgfw_ms.vc) is still issued by Microsoft Windows Production PCA 2011, although firmware db already contains Windows UEFI CA 2023. Its known CA is currently allowed, but it will no longer start after the PCA 2011 certificate is added to dbx.\n\nDo not apply the PCA 2011 revocation (AvailableUpdates bit 0x80, including combined value 0x280) yet. First complete the Windows 2023 boot-manager update while the VeraCrypt System Favorites service is enabled, then run VeraCrypt Repair/Reinstall so VeraCrypt can import a compatible serviced EFI_EX/EFI copy. Verify the embedded issuer of bootmgfw_ms.vc is Windows UEFI CA 2023 and make sure you have an up-to-date VeraCrypt Rescue Disk. + Outer p&assword: + Operation failed while hidden volume protection was enabled.\n\nUse the OUTER volume password, PIM, KDF, and keyfile(s), if any, in the main password dialog. Use the HIDDEN volume password, PIM, KDF, and keyfile(s), if any, in Mount Options > Hidden Volume Protection.\n\nOne or more credentials may be incorrect, or the volume may be invalid or unsupported. + OUTER volume (this dialog): password, PIM, KDF, and keyfile(s).\nHIDDEN volume (Mount Options): password, PIM, KDF, and keyfile(s). diff --git a/Translations/Language.zh-cn.xml b/Translations/Language.zh-cn.xml index ffe9428796..b04fe58603 100644 --- a/Translations/Language.zh-cn.xml +++ b/Translations/Language.zh-cn.xml @@ -1692,6 +1692,9 @@ Warning: VeraCrypt could not validate the installed EFI bootloader files against one complete embedded resource set and confirm that all known required signing CAs are present in db and not listed by dbx. Firmware may reject VeraCrypt when Secure Boot is enabled.\n\nBefore booting with Secure Boot enabled, restore the required Microsoft certificates and current dbx as needed, then run VeraCrypt Repair/Reinstall. Do not remove Microsoft Corporation UEFI CA 2011 until db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and the actual installed files match VeraCrypt's 2023 set. This check cannot model every image-hash or security-version revocation. Make sure you have an up-to-date VeraCrypt Rescue Disk. Warning: VeraCrypt could not validate the embedded signature and known-CA compatibility of the Windows Boot Manager it chainloads (bootmgfw_ms.vc). The file may be missing, unreadable, not a Windows Boot Manager, have an unrecognized embedded signer, or use a known signing CA that is absent from db or listed by dbx. The handoff to Windows may fail when Secure Boot is enabled.\n\nComplete or repair the Windows Secure Boot certificate and boot-manager update, keep the VeraCrypt System Favorites service enabled, and run VeraCrypt Repair/Reinstall. Repair also checks Windows' serviced EFI_EX/EFI copies for a compatible current Boot Manager. If Windows cannot start, temporarily disable Secure Boot to recover. Make sure you have an up-to-date VeraCrypt Rescue Disk. Warning: The embedded signature of the Windows Boot Manager used by VeraCrypt (bootmgfw_ms.vc) is still issued by Microsoft Windows Production PCA 2011, although firmware db already contains Windows UEFI CA 2023. Its known CA is currently allowed, but it will no longer start after the PCA 2011 certificate is added to dbx.\n\nDo not apply the PCA 2011 revocation (AvailableUpdates bit 0x80, including combined value 0x280) yet. First complete the Windows 2023 boot-manager update while the VeraCrypt System Favorites service is enabled, then run VeraCrypt Repair/Reinstall so VeraCrypt can import a compatible serviced EFI_EX/EFI copy. Verify the embedded issuer of bootmgfw_ms.vc is Windows UEFI CA 2023 and make sure you have an up-to-date VeraCrypt Rescue Disk. + Outer p&assword: + Operation failed while hidden volume protection was enabled.\n\nUse the OUTER volume password, PIM, KDF, and keyfile(s), if any, in the main password dialog. Use the HIDDEN volume password, PIM, KDF, and keyfile(s), if any, in Mount Options > Hidden Volume Protection.\n\nOne or more credentials may be incorrect, or the volume may be invalid or unsupported. + OUTER volume (this dialog): password, PIM, KDF, and keyfile(s).\nHIDDEN volume (Mount Options): password, PIM, KDF, and keyfile(s). diff --git a/Translations/Language.zh-hk.xml b/Translations/Language.zh-hk.xml index 8660e6bb65..fc3cacd630 100644 --- a/Translations/Language.zh-hk.xml +++ b/Translations/Language.zh-hk.xml @@ -1691,6 +1691,9 @@ Warning: VeraCrypt could not validate the installed EFI bootloader files against one complete embedded resource set and confirm that all known required signing CAs are present in db and not listed by dbx. Firmware may reject VeraCrypt when Secure Boot is enabled.\n\nBefore booting with Secure Boot enabled, restore the required Microsoft certificates and current dbx as needed, then run VeraCrypt Repair/Reinstall. Do not remove Microsoft Corporation UEFI CA 2011 until db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and the actual installed files match VeraCrypt's 2023 set. This check cannot model every image-hash or security-version revocation. Make sure you have an up-to-date VeraCrypt Rescue Disk. Warning: VeraCrypt could not validate the embedded signature and known-CA compatibility of the Windows Boot Manager it chainloads (bootmgfw_ms.vc). The file may be missing, unreadable, not a Windows Boot Manager, have an unrecognized embedded signer, or use a known signing CA that is absent from db or listed by dbx. The handoff to Windows may fail when Secure Boot is enabled.\n\nComplete or repair the Windows Secure Boot certificate and boot-manager update, keep the VeraCrypt System Favorites service enabled, and run VeraCrypt Repair/Reinstall. Repair also checks Windows' serviced EFI_EX/EFI copies for a compatible current Boot Manager. If Windows cannot start, temporarily disable Secure Boot to recover. Make sure you have an up-to-date VeraCrypt Rescue Disk. Warning: The embedded signature of the Windows Boot Manager used by VeraCrypt (bootmgfw_ms.vc) is still issued by Microsoft Windows Production PCA 2011, although firmware db already contains Windows UEFI CA 2023. Its known CA is currently allowed, but it will no longer start after the PCA 2011 certificate is added to dbx.\n\nDo not apply the PCA 2011 revocation (AvailableUpdates bit 0x80, including combined value 0x280) yet. First complete the Windows 2023 boot-manager update while the VeraCrypt System Favorites service is enabled, then run VeraCrypt Repair/Reinstall so VeraCrypt can import a compatible serviced EFI_EX/EFI copy. Verify the embedded issuer of bootmgfw_ms.vc is Windows UEFI CA 2023 and make sure you have an up-to-date VeraCrypt Rescue Disk. + Outer p&assword: + Operation failed while hidden volume protection was enabled.\n\nUse the OUTER volume password, PIM, KDF, and keyfile(s), if any, in the main password dialog. Use the HIDDEN volume password, PIM, KDF, and keyfile(s), if any, in Mount Options > Hidden Volume Protection.\n\nOne or more credentials may be incorrect, or the volume may be invalid or unsupported. + OUTER volume (this dialog): password, PIM, KDF, and keyfile(s).\nHIDDEN volume (Mount Options): password, PIM, KDF, and keyfile(s). diff --git a/Translations/Language.zh-tw.xml b/Translations/Language.zh-tw.xml index 4c17ca8d0c..bea934468c 100644 --- a/Translations/Language.zh-tw.xml +++ b/Translations/Language.zh-tw.xml @@ -1691,6 +1691,9 @@ Warning: VeraCrypt could not validate the installed EFI bootloader files against one complete embedded resource set and confirm that all known required signing CAs are present in db and not listed by dbx. Firmware may reject VeraCrypt when Secure Boot is enabled.\n\nBefore booting with Secure Boot enabled, restore the required Microsoft certificates and current dbx as needed, then run VeraCrypt Repair/Reinstall. Do not remove Microsoft Corporation UEFI CA 2011 until db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and the actual installed files match VeraCrypt's 2023 set. This check cannot model every image-hash or security-version revocation. Make sure you have an up-to-date VeraCrypt Rescue Disk. Warning: VeraCrypt could not validate the embedded signature and known-CA compatibility of the Windows Boot Manager it chainloads (bootmgfw_ms.vc). The file may be missing, unreadable, not a Windows Boot Manager, have an unrecognized embedded signer, or use a known signing CA that is absent from db or listed by dbx. The handoff to Windows may fail when Secure Boot is enabled.\n\nComplete or repair the Windows Secure Boot certificate and boot-manager update, keep the VeraCrypt System Favorites service enabled, and run VeraCrypt Repair/Reinstall. Repair also checks Windows' serviced EFI_EX/EFI copies for a compatible current Boot Manager. If Windows cannot start, temporarily disable Secure Boot to recover. Make sure you have an up-to-date VeraCrypt Rescue Disk. Warning: The embedded signature of the Windows Boot Manager used by VeraCrypt (bootmgfw_ms.vc) is still issued by Microsoft Windows Production PCA 2011, although firmware db already contains Windows UEFI CA 2023. Its known CA is currently allowed, but it will no longer start after the PCA 2011 certificate is added to dbx.\n\nDo not apply the PCA 2011 revocation (AvailableUpdates bit 0x80, including combined value 0x280) yet. First complete the Windows 2023 boot-manager update while the VeraCrypt System Favorites service is enabled, then run VeraCrypt Repair/Reinstall so VeraCrypt can import a compatible serviced EFI_EX/EFI copy. Verify the embedded issuer of bootmgfw_ms.vc is Windows UEFI CA 2023 and make sure you have an up-to-date VeraCrypt Rescue Disk. + Outer p&assword: + Operation failed while hidden volume protection was enabled.\n\nUse the OUTER volume password, PIM, KDF, and keyfile(s), if any, in the main password dialog. Use the HIDDEN volume password, PIM, KDF, and keyfile(s), if any, in Mount Options > Hidden Volume Protection.\n\nOne or more credentials may be incorrect, or the volume may be invalid or unsupported. + OUTER volume (this dialog): password, PIM, KDF, and keyfile(s).\nHIDDEN volume (Mount Options): password, PIM, KDF, and keyfile(s). diff --git a/src/Common/Dlgcode.c b/src/Common/Dlgcode.c index ed03e5b4df..11ed51f27b 100644 --- a/src/Common/Dlgcode.c +++ b/src/Common/Dlgcode.c @@ -5748,11 +5748,11 @@ BOOL BrowseDirectories(HWND hwndDlg, char *lpszDlgTitle, wchar_t *dirName, const return bOK; } -std::wstring GetWrongPasswordErrorMessage (HWND hwndDlg) +static std::wstring GetWrongPasswordErrorMessageEx (HWND hwndDlg, BOOL hiddenVolumeProtection) { WCHAR szTmp[8192]; - StringCbPrintfW (szTmp, sizeof(szTmp), GetString (KeyFilesEnable ? "PASSWORD_OR_KEYFILE_WRONG" : "PASSWORD_WRONG")); + StringCbPrintfW (szTmp, sizeof(szTmp), GetString (hiddenVolumeProtection ? "HIDVOL_PROT_PASSWORD_OR_KEYFILE_WRONG" : (KeyFilesEnable ? "PASSWORD_OR_KEYFILE_WRONG" : "PASSWORD_WRONG"))); if (CheckCapsLock (hwndDlg, TRUE)) StringCbCatW (szTmp, sizeof(szTmp), GetString ("PASSWORD_WRONG_CAPSLOCK_ON")); @@ -5762,10 +5762,13 @@ std::wstring GetWrongPasswordErrorMessage (HWND hwndDlg) if (TCBootLoaderOnInactiveSysEncDrive (szDevicePath)) { - StringCbPrintfW (szTmp, sizeof(szTmp), GetString (KeyFilesEnable ? "PASSWORD_OR_KEYFILE_OR_MODE_WRONG" : "PASSWORD_OR_MODE_WRONG")); + if (!hiddenVolumeProtection) + { + StringCbPrintfW (szTmp, sizeof(szTmp), GetString (KeyFilesEnable ? "PASSWORD_OR_KEYFILE_OR_MODE_WRONG" : "PASSWORD_OR_MODE_WRONG")); - if (CheckCapsLock (hwndDlg, TRUE)) - StringCbCatW (szTmp, sizeof(szTmp), GetString ("PASSWORD_WRONG_CAPSLOCK_ON")); + if (CheckCapsLock (hwndDlg, TRUE)) + StringCbCatW (szTmp, sizeof(szTmp), GetString ("PASSWORD_WRONG_CAPSLOCK_ON")); + } StringCbCatW (szTmp, sizeof(szTmp), GetString ("SYSENC_MOUNT_WITHOUT_PBA_NOTE")); } @@ -5784,6 +5787,11 @@ std::wstring GetWrongPasswordErrorMessage (HWND hwndDlg) return msg; } +std::wstring GetWrongPasswordErrorMessage (HWND hwndDlg) +{ + return GetWrongPasswordErrorMessageEx (hwndDlg, FALSE); +} + void handleError (HWND hwndDlg, int code, const char* srcPos) { @@ -9577,24 +9585,33 @@ int MountVolume (HWND hwndDlg, goto retry; } - if (bDevice && mount.bProtectHiddenVolume) + if (mount.bProtectHiddenVolume) { - int diskNo; + BOOL passwordErrorMessageShown = FALSE; - if (swscanf (volumePath, L"\\Device\\Harddisk%d\\Partition", &diskNo) == 1) + if (bDevice) { - OPEN_TEST_STRUCT openTestStruct; - memset (&openTestStruct, 0, sizeof (openTestStruct)); + int diskNo; - openTestStruct.bDetectTCBootLoader = TRUE; - StringCchPrintfW ((wchar_t *) openTestStruct.wszFileName, array_capacity (openTestStruct.wszFileName), L"\\Device\\Harddisk%d\\Partition0", diskNo); + if (swscanf (volumePath, L"\\Device\\Harddisk%d\\Partition", &diskNo) == 1) + { + OPEN_TEST_STRUCT openTestStruct; + memset (&openTestStruct, 0, sizeof (openTestStruct)); - DWORD cbBytesReturned; - if (DeviceIoControl (hDriver, TC_IOCTL_OPEN_TEST, &openTestStruct, sizeof (OPEN_TEST_STRUCT), &openTestStruct, sizeof (OPEN_TEST_STRUCT), &cbBytesReturned, NULL) && openTestStruct.TCBootLoaderDetected) - WarningDirect ((GetWrongPasswordErrorMessage (hwndDlg) + L"\n\n" + GetString ("HIDDEN_VOL_PROT_PASSWORD_US_KEYB_LAYOUT")).c_str(), hwndDlg); - else - handleError (hwndDlg, mount.nReturnCode, SRC_POS); + openTestStruct.bDetectTCBootLoader = TRUE; + StringCchPrintfW ((wchar_t *) openTestStruct.wszFileName, array_capacity (openTestStruct.wszFileName), L"\\Device\\Harddisk%d\\Partition0", diskNo); + + DWORD cbBytesReturned; + if (DeviceIoControl (hDriver, TC_IOCTL_OPEN_TEST, &openTestStruct, sizeof (OPEN_TEST_STRUCT), &openTestStruct, sizeof (OPEN_TEST_STRUCT), &cbBytesReturned, NULL) && openTestStruct.TCBootLoaderDetected) + { + WarningDirect ((GetWrongPasswordErrorMessageEx (hwndDlg, TRUE) + L"\n\n" + GetString ("HIDDEN_VOL_PROT_PASSWORD_US_KEYB_LAYOUT")).c_str(), hwndDlg); + passwordErrorMessageShown = TRUE; + } + } } + + if (!passwordErrorMessageShown) + WarningDirect (AppendSrcPos (GetWrongPasswordErrorMessageEx (hwndDlg, TRUE).c_str(), SRC_POS).c_str(), hwndDlg); } else handleError (hwndDlg, mount.nReturnCode, SRC_POS); diff --git a/src/Common/Language.xml b/src/Common/Language.xml index f205f6f9dc..f89f75562c 100644 --- a/src/Common/Language.xml +++ b/src/Common/Language.xml @@ -1691,6 +1691,9 @@ Warning: VeraCrypt could not validate the installed EFI bootloader files against one complete embedded resource set and confirm that all known required signing CAs are present in db and not listed by dbx. Firmware may reject VeraCrypt when Secure Boot is enabled.\n\nBefore booting with Secure Boot enabled, restore the required Microsoft certificates and current dbx as needed, then run VeraCrypt Repair/Reinstall. Do not remove Microsoft Corporation UEFI CA 2011 until db contains both Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023 and the actual installed files match VeraCrypt's 2023 set. This check cannot model every image-hash or security-version revocation. Make sure you have an up-to-date VeraCrypt Rescue Disk. Warning: VeraCrypt could not validate the embedded signature and known-CA compatibility of the Windows Boot Manager it chainloads (bootmgfw_ms.vc). The file may be missing, unreadable, not a Windows Boot Manager, have an unrecognized embedded signer, or use a known signing CA that is absent from db or listed by dbx. The handoff to Windows may fail when Secure Boot is enabled.\n\nComplete or repair the Windows Secure Boot certificate and boot-manager update, keep the VeraCrypt System Favorites service enabled, and run VeraCrypt Repair/Reinstall. Repair also checks Windows' serviced EFI_EX/EFI copies for a compatible current Boot Manager. If Windows cannot start, temporarily disable Secure Boot to recover. Make sure you have an up-to-date VeraCrypt Rescue Disk. Warning: The embedded signature of the Windows Boot Manager used by VeraCrypt (bootmgfw_ms.vc) is still issued by Microsoft Windows Production PCA 2011, although firmware db already contains Windows UEFI CA 2023. Its known CA is currently allowed, but it will no longer start after the PCA 2011 certificate is added to dbx.\n\nDo not apply the PCA 2011 revocation (AvailableUpdates bit 0x80, including combined value 0x280) yet. First complete the Windows 2023 boot-manager update while the VeraCrypt System Favorites service is enabled, then run VeraCrypt Repair/Reinstall so VeraCrypt can import a compatible serviced EFI_EX/EFI copy. Verify the embedded issuer of bootmgfw_ms.vc is Windows UEFI CA 2023 and make sure you have an up-to-date VeraCrypt Rescue Disk. + Outer p&assword: + Operation failed while hidden volume protection was enabled.\n\nUse the OUTER volume password, PIM, KDF, and keyfile(s), if any, in the main password dialog. Use the HIDDEN volume password, PIM, KDF, and keyfile(s), if any, in Mount Options > Hidden Volume Protection.\n\nOne or more credentials may be incorrect, or the volume may be invalid or unsupported. + OUTER volume (this dialog): password, PIM, KDF, and keyfile(s).\nHIDDEN volume (Mount Options): password, PIM, KDF, and keyfile(s). diff --git a/src/Mount/Mount.c b/src/Mount/Mount.c index 8d72805d73..11333ecab3 100644 --- a/src/Mount/Mount.c +++ b/src/Mount/Mount.c @@ -3572,6 +3572,29 @@ static wchar_t PasswordDlgVolume[MAX_PATH + 1]; static BOOL PasswordDialogDisableMountOptions; static char *PasswordDialogTitleStringId; +static void UpdatePasswordDlgPasswordLabel (HWND hwndDlg) +{ + BOOL hiddenVolumeProtection = !PasswordDialogDisableMountOptions && mountOptions.ProtectHiddenVolume; + HWND credentialsNote = GetDlgItem (hwndDlg, HIDVOL_PROT_OUTER_CREDENTIALS_NOTE); + BOOL credentialsNoteVisible = (GetWindowLongPtr (credentialsNote, GWL_STYLE) & WS_VISIBLE) != 0; + + SetDlgItemTextW (hwndDlg, IDT_PASSWORD, GetString (hiddenVolumeProtection ? "IDT_OUTER_VOL_PASSWORD" : "IDT_PASSWORD")); + + if (hiddenVolumeProtection != credentialsNoteVisible) + { + RECT dialogRect; + RECT sizeChange = { 0, 0, 0, 23 }; + MapDialogRect (hwndDlg, &sizeChange); + GetWindowRect (hwndDlg, &dialogRect); + + ShowWindow (credentialsNote, hiddenVolumeProtection ? SW_SHOW : SW_HIDE); + SetWindowPos (hwndDlg, NULL, + dialogRect.left, dialogRect.top + (hiddenVolumeProtection ? -sizeChange.bottom / 2 : sizeChange.bottom / 2), + dialogRect.right - dialogRect.left, dialogRect.bottom - dialogRect.top + (hiddenVolumeProtection ? sizeChange.bottom : -sizeChange.bottom), + SWP_NOACTIVATE | SWP_NOZORDER); + } +} + /* Except in response to the WM_INITDIALOG message, the dialog box procedure should return nonzero if it processes the message, and zero if it does not. - see DialogProc */ @@ -3639,6 +3662,7 @@ BOOL CALLBACK PasswordDlgProc (HWND hwndDlg, UINT msg, WPARAM wParam, LPARAM lPa SendMessage (hComboBox, CB_SETCURSEL, defaultPrfIndex, 0); ToNormalPwdField (hwndDlg, IDC_PASSWORD); + UpdatePasswordDlgPasswordLabel (hwndDlg); SendMessage (GetDlgItem (hwndDlg, IDC_CACHE), BM_SETCHECK, bCacheInDriver ? BST_CHECKED:BST_UNCHECKED, 0); SendMessage (GetDlgItem (hwndDlg, IDC_PIM), EM_LIMITTEXT, MAX_PIM, 0); @@ -3842,6 +3866,7 @@ BOOL CALLBACK PasswordDlgProc (HWND hwndDlg, UINT msg, WPARAM wParam, LPARAM lPa DialogBoxParamW (hInst, MAKEINTRESOURCEW (IDD_MOUNT_OPTIONS), hwndDlg, (DLGPROC) MountOptionsDlgProc, (LPARAM) &mountOptions); + UpdatePasswordDlgPasswordLabel (hwndDlg); if (!bPrebootPasswordDlgMode && mountOptions.PartitionInInactiveSysEncScope) SendMessage (hwndDlg, TC_APPMSG_PREBOOT_PASSWORD_MODE, 0, 0); @@ -6618,7 +6643,8 @@ static BOOL MountAllDevicesThreadCode (HWND hwndDlg, MountAllDevicesThreadParam* { WCHAR szTmp[4096]; - StringCbPrintfW (szTmp, sizeof(szTmp), GetString (KeyFilesEnable || FirstCmdKeyFile ? "PASSWORD_OR_KEYFILE_WRONG_AUTOMOUNT" : "PASSWORD_WRONG_AUTOMOUNT")); + StringCbPrintfW (szTmp, sizeof(szTmp), + GetString (mountOptions.ProtectHiddenVolume ? "HIDVOL_PROT_PASSWORD_OR_KEYFILE_WRONG" : (KeyFilesEnable || FirstCmdKeyFile ? "PASSWORD_OR_KEYFILE_WRONG_AUTOMOUNT" : "PASSWORD_WRONG_AUTOMOUNT"))); if (CheckCapsLock (hwndDlg, TRUE)) StringCbCatW (szTmp, sizeof(szTmp), GetString ("PASSWORD_WRONG_CAPSLOCK_ON")); diff --git a/src/Mount/Mount.rc b/src/Mount/Mount.rc index 09c7501c06..cf6a1fb602 100644 --- a/src/Mount/Mount.rc +++ b/src/Mount/Mount.rc @@ -207,7 +207,7 @@ BEGIN CONTROL "",IDC_LOWER_BOX,"Static",SS_ETCHEDFRAME,2,151,372,119 END -IDD_PASSWORD_DLG DIALOGEX 0, 0, 330, 103 +IDD_PASSWORD_DLG DIALOGEX 0, 0, 330, 126 STYLE DS_SETFONT | DS_MODALFRAME | DS_3DLOOK | DS_FIXEDSYS | DS_CENTER | WS_POPUP | WS_VISIBLE | WS_CAPTION CAPTION "Enter VeraCrypt Volume Password" FONT 8, "MS Shell Dlg", 0, 0, 0x0 @@ -228,6 +228,7 @@ BEGIN RTEXT "Password:",IDT_PASSWORD,0,10,65,13 RTEXT "KDF:",IDT_KDF,0,27,65,11 RTEXT "Volume PIM:",IDT_PIM,0,46,65,8,NOT WS_VISIBLE + LTEXT "OUTER volume (this dialog): password, PIM, KDF, and keyfile(s).\nHIDDEN volume (Mount Options): password, PIM, KDF, and keyfile(s).",HIDVOL_PROT_OUTER_CREDENTIALS_NOTE,7,103,316,18 END IDD_TRAVELER_DLG DIALOGEX 0, 0, 300, 299 @@ -511,7 +512,7 @@ BEGIN IDD_PASSWORD_DLG, DIALOG BEGIN RIGHTMARGIN, 321 - BOTTOMMARGIN, 98 + BOTTOMMARGIN, 121 END IDD_TRAVELER_DLG, DIALOG diff --git a/src/Mount/Resource.h b/src/Mount/Resource.h index 444fbc42d8..bb212ba88c 100644 --- a/src/Mount/Resource.h +++ b/src/Mount/Resource.h @@ -206,6 +206,7 @@ #define IDC_DISABLE_SCREEN_PROTECTION 1181 #define IDC_PREF_TAB 1182 #define IDC_SECURE_DESKTOP_ENABLE_IME 1183 +#define HIDVOL_PROT_OUTER_CREDENTIALS_NOTE 1184 #define IDM_HELP 40001 #define IDM_ABOUT 40002 #define IDM_UNMOUNT_VOLUME 40003 @@ -284,7 +285,7 @@ #define _APS_NO_MFC 1 #define _APS_NEXT_RESOURCE_VALUE 123 #define _APS_NEXT_COMMAND_VALUE 40071 -#define _APS_NEXT_CONTROL_VALUE 1184 +#define _APS_NEXT_CONTROL_VALUE 1185 #define _APS_NEXT_SYMED_VALUE 101 #endif #endif