Microsoft’s 2011 UEFI Certificate Authority Expired Yesterday
A blog entry on einval.com reports the expiration of Microsoft’s old UEFI Certificate Authority. The CA was originally created in 2011 to sign firmware for secure boot. The
A blog entry on einval.com reports the expiration of Microsoft’s old UEFI Certificate
Authority. The CA was originally created in 2011 to sign firmware for secure boot. The
author notes that the certificate’s validity ended yesterday. The expiration means the CA
can no longer be used to issue trusted UEFI signatures. Existing devices that rely on the
CA must transition to newer certificates. The post discusses potential impacts on legacy
hardware that still trusts the old CA. It advises system administrators to audit firmware
signing chains for compliance. The article suggests monitoring future Microsoft updates
for replacement certificates.