New Windows updates replace expiring Secure Boot certificates
微软开始为符合条件的Windows 11 24H2和25H2设备自动替换即将过期的Secure Boot证书。这些证书用于验证UEFI固件的安全性,防止恶意软件在启动时运行。旧证书将于2026年6月起失效,未及时更新可能导致设备无法安全启动或接收安全更新。微软通过Windows Update自动推送新证书,并建议IT管理员手动安装以确保设备安全。 2026-1-13 20:0:19 Author: www.bleepingcomputer.com(查看原文) 阅读量:0 收藏

Windows

Microsoft has started automatically replacing expiring Secure Boot certificates on eligible Windows 11 24H2 and 25H2 systems.

Secure Boot is a security feature that blocks malicious software (like rootkit malware) from executing during the system startup sequence by ensuring that only trusted bootloaders can load on computers with UEFI firmware. This is done by checking the software's digital signature against a set of trusted digital certificates that are stored in the device's firmware.

Today's announcement comes after Microsoft warned IT admins in November to update the security certificates used to validate UEFI firmware before they expire.

Wiz

"Secure Boot certificates used by most Windows devices are set to expire starting in June 2026. This might affect the ability of certain personal and business devices to boot securely if not updated in time," Microsoft said.

"Starting with this update, Windows quality updates include a subset of high confidence device targeting data that identifies devices eligible to automatically receive new Secure Boot certificates. Devices will receive the new certificates only after demonstrating sufficient successful update signals, ensuring a safe and phased deployment," it added.

IT admins who want to maintain Secure Boot functionality and ensure their endpoints' security should install the new certificates before the old certificates expire this summer.

Failing to do so could result in losing Windows Boot Manager and Secure Boot protections, as security updates for pre-boot components will no longer be provided to Secure Boot-enabled devices.

"Without updates, the Secure Boot-enabled Windows devices risk not receiving security updates or trusting new boot loaders which will compromise both serviceability and security," Microsoft explains.

While Microsoft will automatically update high-confidence devices via Windows Update, organizations can also deploy Secure Boot certificates using registry keys, the Windows Configuration System (WinCS), and Group Policy settings.

According to Microsoft's Secure Boot playbook, admins should first inventory their device fleets, verify Secure Boot status using PowerShell commands or registry keys, and then apply manufacturer firmware updates before installing Microsoft's certificate updates.

Wiz

Secrets Security Cheat Sheet: From Sprawl to Control

Whether you're cleaning up old keys or setting guardrails for AI-generated code, this guide helps your team build securely from the start.

Get the cheat sheet and take the guesswork out of secrets management.


文章来源: https://www.bleepingcomputer.com/news/security/microsoft-rolls-out-new-secure-boot-certificates-for-windows-devices/
如有侵权请联系:admin#unsafe.sh