TwistedHelixis Posted January 5 Posted January 5 Not sure which forum to post this in. Have others been pro actively making sure all their systems are ready for the new certificates? The main companies (Dell, HP) offer a few tools for managing this on client endpoints, but I have some schools that have purchased cheaper (Chinese laptops / desktops) that might not ever get a BIOS update. What are their options for installing the certs? We have Dell PowerEdge host servers, with a couple of VMs on each. How are you making sure that the servers are ready? Honestly, I am very confused over this issue.
jthompson Posted January 5 Posted January 5 (edited) Thanks for raising this one. I had no idea about it until reading your post! The majority of our computers (Dell) aren't going to have or get the new certificates, it seems. The models that are recent enough already have the new certificates I think by virtue of UEFI updates via Windows Update (we're using WUfB so our UEFI updates come through that), but Dell aren't updating certificates for models not on this list - https://www.dell.com/support/kbdoc/en-uk/000347876/microsoft-2011-secure-boot-certificate-expiration. I'll add this to my list of reasons to get new hardware purchased sooner rather than later! Edited January 5 by jthompson
Fazza Posted January 5 Posted January 5 A BIOS update is required to update the certificate details on your computer. If the manufacturer does not provide a BIOS update then it's likely that we will have to turn off secure boot for the device to boot and load Windows.
TwistedHelixis Posted January 5 Author Posted January 5 8 minutes ago, Fazza said: A BIOS update is required to update the certificate details on your computer. If the manufacturer does not provide a BIOS update then it's likely that we will have to turn off secure boot for the device to boot and load Windows. Windows doesn't always boot after doing this 😞
Fazza Posted January 5 Posted January 5 From experience of over 30ish years of Tech Support I've seen less than a handful of machines die due to a BIOS update and most of those were on unbranded Desktops from 25 years ago. The only 'issue' that you may have after a BIOS update (on some Lenovo laptops for example) is the bit-locker key may need re-entering, as long as you have it store in Active Directory Users and Computers you should be fine.
Olliedawg Posted January 5 Posted January 5 The system will still boot with the old certificates. We still have some old desktops in 2 of our IT rooms which we are plodding along with for another year minimum with the Windows 10 ESU's, which haven't had a BIOS update for a while now.
TwistedHelixis Posted January 5 Author Posted January 5 (edited) Quote From experience of over 30ish years of Tech Support I've seen less than a handful of machines die due to a BIOS update and most of those were on unbranded Desktops from 25 years ago. The only 'issue' that you may have after a BIOS update (on some Lenovo laptops for example) is the bit-locker key may need re-entering, as long as you have it store in Active Directory Users and Computers you should be fine. The issue is not updating the BIOS, its a) what if a device doesn't have the BIOS update that can support the new certs, 2) how to manage this on hundreds of different devices across different sites and some at remote locations. Even starting with the servers, If I install the latest BIOS and that doesn't have the new certs, what do I do then? Edited January 5 by TwistedHelixis
Fazza Posted January 5 Posted January 5 3 minutes ago, Olliedawg said: The system will still boot with the old certificates. We still have some old desktops in 2 of our IT rooms which we are plodding along with for another year minimum with the Windows 10 ESU's, which haven't had a BIOS update for a while now. But the old certificate hasn't expired yet, we have that to come in a few months. If the certificate expires and a system that is still looking for the old certificate still boots and loads Windows, what's the point in the certificate?
TwistedHelixis Posted January 5 Author Posted January 5 5 minutes ago, Olliedawg said: The system will still boot with the old certificates. We still have some old desktops in 2 of our IT rooms which we are plodding along with for another year minimum with the Windows 10 ESU's, which haven't had a BIOS update for a while now. In September or October the old certs get removed from the MS servers, even they say devices might fail to boot after that.
Fazza Posted January 5 Posted January 5 1 minute ago, TwistedHelixis said: The issue is not updating the BIOS, its a) what if a device doesn't have the BIOS update that can support the new certs, 2) how to manage this on hundreds of different devices across different sites and some at remote locations. Even starting with the servers, If I install the latest BIOS and that doesn't have the new certs, what do I do then? Turn off Secure Boot in the BIOS - Bit-Locker keys may need to be re-entered when this is done. It's a manual process to change the BIOS settings.
Popular Post Olliedawg Posted January 5 Popular Post Posted January 5 According to Dell, machines will still boot without the 2023 certificates : Secure Boot Transition FAQ | Dell UK What happens when the current Secure Boot certificate expires? The computer is still able to boot. However, with an expired certificate, the computer cannot get future updates to the bootloader or Secure Boot. Quote from Microsoft Frequently asked questions about the Secure Boot update process - Microsoft Support Q4: What happens if a device does not have the new Secure Boot certificates after the old certificates expire? The device will continue to boot and function normally. However, it will no longer be eligible to receive security fixes related to the Windows boot manager updates or Secure Boot. Obviously this is a big security vulnerability, but according to that, it wont suddenly break. 4 2
TwistedHelixis Posted January 5 Author Posted January 5 Thanks @Olliedawg, that does make things less stressful
DavR Posted January 5 Posted January 5 Looking at the Dell "supported" list for these updates, looks like only our most recent desktops will be getting the certificate update for BIOS (Optiplex 7010 SFF). What are we thinking is the best strategy for unsupported devices - let the certs lapse and leave it at that, or, should we be actively going round disabling Secure Boot?
Fazza Posted January 5 Posted January 5 1 hour ago, Olliedawg said: According to Dell, machines will still boot without the 2023 certificates : Secure Boot Transition FAQ | Dell UK What happens when the current Secure Boot certificate expires? The computer is still able to boot. However, with an expired certificate, the computer cannot get future updates to the bootloader or Secure Boot. Quote from Microsoft Frequently asked questions about the Secure Boot update process - Microsoft Support Q4: What happens if a device does not have the new Secure Boot certificates after the old certificates expire? The device will continue to boot and function normally. However, it will no longer be eligible to receive security fixes related to the Windows boot manager updates or Secure Boot. Obviously this is a big security vulnerability, but according to that, it wont suddenly break. Thanks for that! I think people were worried that it might stop computers from working the day after the certificate expires.
jthompson Posted January 5 Posted January 5 (edited) Reading up a bit, here's my somewhat woolly understanding. Hardware that's stuck with only the old certs in BIOS will continue to boot an existing installation of Windows, since that OS will have itself been signed using the old certs. The expiration date apparently isn't a factor when it comes to Secure Boot deciding whether to trust the boot loader: it simply cares whether the signing matches up with the certs in BIOS. Edit: there may be some certificate revocation happening via Windows Updates, such that the computer's firmware would then know to ditch the old 2011 certs. I dunno. Attempting to deploy a new image to that hardware might require Secure Boot to be disabled if the WinPE boot image used for deployment (or the OS itself) is signed only with the newer certs (since the signing and the certs in BIOS won't relate). I don't know what version of ADK that points to, however. Looking at an old Latitude E5470 (i.e. something too old for Dell to be updating) there are options in the Secure Boot settings in BIOS for adding keys into the database. I wonder if this might be an avenue for contining to be able to use Secure Boot? Obviously, the correct answer is buy new computers, but I'd like to know what might be doable here. Edited January 5 by jthompson 4
DavR Posted January 5 Posted January 5 Just gonna throw this on here, because I haven't seen it widely reported anywhere else yet and it was driving me nuts.... Hyper-V guests do NOT support the certificate upgrade yet. For the certificate upgrade to complete, you need to upgrade the virtual device firmware first, but the ability to update this firmware hasn't been released yet. It IS possible to create a brand new Hyper-V 2nd Gen guest, and as long as you've updated the host first, this should be created with the new certificates. But upgrading the certs on existing Hyper-V VMs doesn't seem to be available yet. 3
TwistedHelixis Posted January 5 Author Posted January 5 8 minutes ago, DavR said: Just gonna throw this on here, because I haven't seen it widely reported anywhere else yet and it was driving me nuts.... Hyper-V guests do NOT support the certificate upgrade yet. For the certificate upgrade to complete, you need to upgrade the virtual device firmware first, but the ability to update this firmware hasn't been released yet. It IS possible to create a brand new Hyper-V 2nd Gen guest, and as long as you've updated the host first, this should be created with the new certificates. But upgrading the certs on existing Hyper-V VMs doesn't seem to be available yet. I was going to ask about Hyper-V VMs. Would have been handy if MS had already supplied a way of doing this. It will be June before we know it.
jthompson Posted January 6 Posted January 6 One part of the puzzle... I've worked out how to add the "Windows UEFI CA 2023" certificate to legacy devices (i.e. those not in line for a UEFI update from maufacturers). Get a blank USB stick formatted as FAT32. From an existing Windows system that has the July 2024 cumulative update installed, take a copy of "C:\Windows\Boot\EFI\securebootrecovery.efi" and save that file onto the USB as "\EFI\BOOT\bootx64.efi". Confirm that you have a BitLocker recovery key for the device being updated. Boot that device from the USB. It'll display a message indicating that the "Windows UEFI CA2023" certificate has been added to the device's secure boot db. It's very quick and the device will restart automatically. Enter the BitLocker recovery key to continue with the Windows boot. In an admin PowerShell prompt, the following command will indicate whether the "Windows UEFI CA 2023" certificate is present in the UEFI Secure Boot db: (-join [char[]](Get-SecureBootUEFI db).bytes) -match 'Windows UEFI CA 2023' That certificate will persist in the device through a subsequent fresh OS deployment. There are other certs inolved in Secure Boot, but that one is the one that governs whether a Windows image signed with the new cert can boot. Next on my list is to look at MDT and the Windows ADK. I'm currently using the Win11 22H2 ADK, which won't be using the new certs. After the expiration, I'm wondering whether newer devices, where Windows updates have added the old certs to a revocation list in the UEFI, will fail to boot that WinPE image. I'll try a newer ADK version that's signed with the new ones, but only after checking that all our devices have the new cert installed (since devices without it may reject the newer WinPE image?). 2
jthompson Posted January 6 Posted January 6 Actually, my last post is probably redundant. The same can be achieved by manually running a Windows update instead. The cert that that addds to the db ("Windows UEFI CA 2023") is what can be added to the db via Windows update. On the systems I've looked at here, they all need a couple of manual steps to run that update. Maybe MS are holding off on rolling this out everywhere still? From: https://techcommunity.microsoft.com/blog/windows-itpro-blog/updating-microsoft-secure-boot-keys/4055324 Adjust the required reg key: Set-ItemProperty -Path “HKLM:\SYSTEM\CurrentControlSet\Control\SecureBoot” -Name “AvailableUpdates” -Value 0x40 Then run the required scheduled task: Start-ScheduledTask -TaskName “\Microsoft\Windows\PI\Secure-Boot-Update” That then adds the new cert to the db. The earlier certificate for that ("Microsoft Windows Production PCA 2011") remains in place. These certs are used to sign the Windows boot loader. The expiration for that is October 2026. This works on a Hyper-V guest, too. The manufacturer BIOS updates will add the new certs into the default db, not the active db. Having them in the default db means that they'll be there after factory resetting a device. If you were to do that with a legacy device, you'd therefore lose the newer key(s) and would need to add them from USB before then booting/deploying Windows. WRT to Hyper-V, I guess you'd want a firmware upgrade on the host so as to have the newer keys then being available in newly created VMs?
DavR Posted January 6 Posted January 6 11 minutes ago, jthompson said: Actually, my last post is probably redundant. The same can be achieved by manually running a Windows update instead. The cert that that addds to the db ("Windows UEFI CA 2023") is what can be added to the db via Windows update. On the systems I've looked at here, they all need a couple of manual steps to run that update. Maybe MS are holding off on rolling this out everywhere still? From: https://techcommunity.microsoft.com/blog/windows-itpro-blog/updating-microsoft-secure-boot-keys/4055324 Adjust the required reg key: Set-ItemProperty -Path “HKLM:\SYSTEM\CurrentControlSet\Control\SecureBoot” -Name “AvailableUpdates” -Value 0x40 Then run the required scheduled task: Start-ScheduledTask -TaskName “\Microsoft\Windows\PI\Secure-Boot-Update” That then adds the new cert to the db. The earlier certificate for that ("Microsoft Windows Production PCA 2011") remains in place. These certs are used to sign the Windows boot loader. The expiration for that is October 2026. This works on a Hyper-V guest, too. The manufacturer BIOS updates will add the new certs into the default db, not the active db. Having them in the default db means that they'll be there after factory resetting a device. If you were to do that with a legacy device, you'd therefore lose the newer key(s) and would need to add them from USB before then booting/deploying Windows. WRT to Hyper-V, I guess you'd want a firmware upgrade on the host so as to have the newer keys then being available in newly created VMs? I was just going to reply and say actually - the above method with the reg key is probably quicker if you're just adding the new certs to the Secure Boot active DB. As you say though, this doesn't add the certs to the default DB, this still needs a manufacturers firmware update. So you will lose those certs again if someone does a BIOS reset. Not that people do, but, CMOS batteries do fail, which would cause that same loss. I'm wary of doing it that way myself. Hyper-V - we've tried a firmware update on the host, but it doesn't update the guests. I guess it's whatever Hyper-V "virtual BIOS/firmware" it serves to guest OS that needs an upgrade, and that we're still waiting for. 1
MYK-IT Posted January 29 Posted January 29 I too, have been attempting to obtain a clearer understanding of the overall requirement for updating and applying the Windows UEFI CA 2023 Certificate process (Secure Boot Certificate updates: Guidance for IT professionals and organizations - Microsoft Support) as well as what is needed to be applied and when etc. I have ascertained, that all our computers have received the applicable Windows Updates etc all desktop computers have received the latest BIOS updates containing the Windows UEFI CA 2023 certificate Despite the above (two) being applied, the new certificates are currently within the Default DB, not Active I assume at some point, we will need to enable the extra settings via Intune to switch over to Active DB before June/October 2026? (How to update Secure Boot for Windows Certificates using Intune – James Vincent) Or will the Windows Update suffice, until perhaps a rebuild or the BIOS has been reset for whatever reason? (which would revoke the Microsoft Corporation UEFI CA 2011 Certificate). In relation to image deployment, again from what I have read, regardless if you are using MDT (even with latest ADK, as that just mitigates BlackLotus ) or MECM/SCCM the (PXE) Boot Image will still have and use the Microsoft Corporation UEFI CA 2011 Certificate. Meaning that once the Microsoft Corporation UEFI CA 2011 Certificates have been revoked /expired (on a computer/laptop) it won't be able to (PXE) boot from this existing WIM(?) Suggesting that two (PXE) Boot WIM images may be needed, one for those devices with 2023 Certificates, and another for those (legacy) devices without. I am not sure if Updating Windows bootable media to use the PCA2023 signed boot manager - Microsoft Support could be an option (e.g. modifying a copy of existing PXE Boot WIM, and adding to WDS) until Microsoft release an updated ADK that has the Windows UEFI CA 2023 Certificate by default. But I am going to give it a try... Either way, depending on what (compatible) devices everyone has (probably mixed due to funding etc), or as and when Microsoft update their ADK - two (PXE) Boot WIM (or USB) may be needed in the interim.... if i have understood this all correctly! 😉
itskdog Posted January 29 Posted January 29 1 minute ago, MYK-IT said: I have ascertained, that all our computers have received the applicable Windows Updates etc all desktop computers have received the latest BIOS updates containing the Windows UEFI CA 2023 certificate Despite the above (two) being applied, the new certificates are currently within the Default DB, not Active This is expected - the Default DB in the UEFI is, as the name suggests, a default for when you factory reset the secure boot or UEFI settings in the UEFI setup, or the CMOS is cleared. The UEFI updates are still important, as they may fix issues that prevent Windows from installing the updates to the Active DB. Only Microsoft have the authority to update the Active DB, which is where these updates come in. Currently, I have enabled the Microsoft Managed Opt-in policy, to get behaviour similar to personal devices through Microsoft's Controlled Feature Rollout, to have a slow rollout across our estate, but depending on how many devices end up completing the update (I have some detection scripts in Intune to tide me over until the report is released to show the device status) I may finish by enabling the policy that pushes out the certs to the UEFI immediately to ensure devices remain secure. 1
DavR Posted January 29 Posted January 29 4 minutes ago, MYK-IT said: I assume at some point, we will need to enable the extra settings via Intune to switch over to Active DB before June/October 2026? (How to update Secure Boot for Windows Certificates using Intune – James Vincent) Or will the Windows Update suffice, until perhaps a rebuild or the BIOS has been reset for whatever reason? (which would revoke the Microsoft Corporation UEFI CA 2011 Certificate). I can't comment on your point about boot images and installers, I'm kinda winging it on that one 😂 What I can say though, is that installing necessary BIOS updates will update the Default DB on each machine. Windows is prepared by Windows Update to update the Active DB, but yes, you do need to roll out a few settings via Intune or Group Policy first, in most enterprise situations I don't think it'll do it on it's own. We did the Intune method described in your link the other day and that seems to be working. I'll be doing the GP method for our AD based devices Feb half term. 1
gaz350b Posted January 29 Posted January 29 (edited) Just to add you can brick a device if you apply the reg key to a device that hasn’t got a compatible bios. It will boot but would lock up within 5 minutes when it tries to update the cert. (this was on a dell 3040) Edited January 29 by gaz350b
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now