Microsoft rolls out new Secure Boot certificates before June expiration
好的,我现在需要帮用户总结一篇文章,控制在100字以内,而且不需要特定的开头。首先,我得仔细阅读文章内容,抓住主要信息。 文章讲的是微软正在通过每月的Windows更新推出更新的Secure Boot证书,替换2011年的旧证书,这些旧证书将在2026年6月底过期。Secure Boot是2011年引入的,用于确保只有可信的引导程序在UEFI固件的电脑上加载,防止恶意软件在启动时执行。微软在1月宣布了更新计划,并警告IT管理员更新证书。 接下来,微软已经开始通过每月更新分发新证书,适用于家庭、企业和学校设备。组织可以选择自己管理更新。新证书将自动安装,但部分设备可能需要单独的固件更新。未及时更新的设备将进入降级安全状态。 用户的需求是用中文总结文章内容,并且控制在100字以内。我需要提取关键点:微软替换过期的Secure Boot证书,通过每月更新分发新证书,涉及UEFI固件安全,影响范围广,部分设备需手动更新。 现在组织语言:微软开始通过每月Windows更新替换即将过期的Secure Boot证书(原2011年发布),以提升UEFI固件安全性。新证书将自动安装于支持设备,并建议升级至Windows 11以获取保护。 这样既涵盖了主要内容,又符合字数要求。 </think> 微软开始通过每月Windows更新替换即将于2026年6月过期的Secure Boot证书(原2011年发布),以提升UEFI固件安全性。新证书将自动安装于支持设备,并建议升级至Windows 11以获取保护。 2026-2-10 17:15:22 Author: www.bleepingcomputer.com(查看原文) 阅读量:3 收藏

Windows

Microsoft has begun rolling out updated Secure Boot certificates through monthly Windows updates to replace the original 2011 certificates that will expire in late June 2026.

Introduced in 2011, Secure Boot ensures that only trusted bootloaders can load on computers with UEFI firmware, helping block malicious software, such as rootkits, from executing during system startup by verifying its digital signature against a set of trusted digital certificates stored in the firmware.

Microsoft first revealed plans to refresh expiring Secure Boot certificates on eligible Windows 11 24H2 and 25H2 systems in January, following a November alert warning IT admins to update the security certificates used to validate UEFI firmware before they expire.

Wiz

"After more than 15 years of continuous service, the original Secure Boot certificates are reaching the end of their planned lifecycle and begin expiring in late June 2026," said Windows Servicing and Delivery partner director Nuno Costa on Tuesday.

"We've begun rolling out new certificates as part of the regular monthly Windows updates to in-support Windows devices for home users, businesses, and schools with Microsoft-managed updates. Organizations also have the option to manage the update process themselves using their preferred management tools."

Costa added that the certificate refresh represents "one of the largest coordinated security maintenance efforts across the Windows ecosystem," as it involves firmware updates across millions of device configurations from many hardware manufacturers and original equipment
manufacturers (OEMs).

The new Secure Boot certificates will be installed automatically via regular monthly updates for customers who allow Microsoft to manage Windows updates on their systems. Additionally, many PCs manufactured since 2024, and the vast majority shipped last year, already include updated certificates.

However, some devices may require separate firmware updates from manufacturers before applying new certificates, and Microsoft advised customers to check OEM support pages for the latest firmware versions.

Although Microsoft will automatically update high-confidence devices via Windows Update, IT admins can also deploy Secure Boot certificates using registry keys, Group Policy settings, and the Windows Configuration System (WinCS) to ensure that endpoints don't lose Windows Boot Manager and Secure Boot protections.

While devices that fail to receive updated certificates before June will continue to function normally, they will enter what Microsoft describes as a "degraded security state," with "limited" boot-level protections and no protection against attacks that exploit newly discovered vulnerabilities because they cannot install new mitigations.

Microsoft advised all customers to upgrade to Windows 11, which now officially powers more than a billion devices, as unsupported Windows versions like Windows 10 will not receive new certificates.

"It's important to note that devices running unsupported versions (Windows 10 and older, excluding those who have enrolled in Extended Security Updates) do not receive Windows updates and will not receive the new certificates," Costa noted. "We continue to encourage customers to always use a supported version of Windows for best performance and protection."

tines

The future of IT infrastructure is here

Modern IT infrastructure moves faster than manual workflows can handle.

In this new Tines guide, learn how your team can reduce hidden manual delays, improve reliability through automated response, and build and scale intelligent workflows on top of tools you already use.


文章来源: https://www.bleepingcomputer.com/news/microsoft/microsoft-rolls-out-new-secure-boot-certificates-before-june-expiration/
如有侵权请联系:admin#unsafe.sh