Microsoft will start refreshing Secure Boot certificates in March for Windows 11 and Windows 10 ESU users

Get ye to Windows Update, because there’s a good chance you’ve got new Secure Boot certificates to install. Microsoft just announced that it will be refreshing those certificates, which were originally introduced when Secure Boot debuted in 2011, as a security precaution. Secure Boot was a way for Microsoft to protect systems from running unsigned and potentially malicious code before Windows launched. It went on to be an installation requirement for Windows 11, as well as anti-cheat software used in Valorant, Call of Duty: Black Ops 6/7 and Battlefield 6.

Without the new Secure Boot certificates, Microsoft says your system will still function normally, but it will enter “a degraded security state that limits its ability to receive future boot-level protections.” Basically, you won’t be protected from malware and viruses targeting vulnerabilities in older versions of Windows. As expected, Microsoft also notes that unsupported versions of Windows won’t be receiving the new Secure Boot certificates. They’re only coming to Windows 11 systems, as well as Windows 10 PCs subscribed to Microsoft’s Extended Security Updates.

Microsoft says many users will be able to pick up the updated Secure Boot certificates by visiting Windows Update, but a few may need additional firmware updates from their system (or motherboard’s) OEM. You’ll also be able to track the status of your security certificates in the Windows Security app in the “coming months.”

“As cryptographic security evolves, certificates and keys must be periodically refreshed to maintain strong protection,” Nuno Costa, Partner Director of Windows Servicing and Delivery, wrote in a blog post today. “Retiring old certificates and introducing new ones is a standard industry practice that helps prevent aging credentials from becoming a weak point and keeps platforms aligned with modern security expectations.”

Costa says Microsoft has been working with OEMs like Dell and HP to ensure a smooth transition to the new Secure Boot certificates. Many new systems built in 2024 already have the updated certs, while “almost all” devices shipped last year have them as well. Microsoft has also been alerting IT customers to this transition since last year.

This article originally appeared on Engadget at https://www.engadget.com/computing/microsoft-will-start-refreshing-secure-boot-certificates-in-march-for-windows-11-and-windows-10-esu-users-170000777.html?src=rss

Read more @ Engadget

Latest posts

How Live Nation allegedly terrorized the concert industry

SeatGeek was close to a deal that would bring its ticketing business to the next level. The company was in negotiations with the Dallas...

Apple iPad Air M4 review: a little bit faster now

For the record: if you’re getting an iPad Air, you should also get the keyboard case. | Photo by Amelia Holowaty Krales / The...

The iPhone 17E is good, but you probably shouldn’t buy it

It’s about time. The iPhone 17E is a better value than the 16E was when it arrived, but that should matter to basically nobody. The...

Panic’s gaming ambitions hinge on the weird and whimsical

Four players in Big Walk. A game about an annoying goose with a button dedicated entirely to honking isn't the obvious recipe for a hit....

Hasbro’s CEO has an AI Peppa Pig help design toys

Today, I’m talking with Chris Cocks, CEO of Hasbro. You know, Hasbro — the toy and game company that makes some of the most iconic...

Samsung’s Mario-themed microSD card for Switch 2 is 35 percent off

Add more games to your Switch 2 with a microSD Express card. | Photo: Amelia Holowaty Krales / The Verge Nintendo has cut the cost...

X says you can block Grok from editing your photos

Pay attention to that small print about tagging @Grok, this new toggle has disappointing limitations. | Image by The Verge / xAI X has introduced...

Yashica’s new retro point-and-shoot revival sounds surprisingly capable for $100

The Yashica Tank looks like a camera that costs way more than it does. | Image: Yashica Yashica has announced a new throwback camera called...

Donut Lab says latest test proves its solid-state battery isn’t a supercapacitor

When Donut Lab first announced its solid-state battery earlier this year, there was some speculation around whether the Finnish startup had actually produced a...

Live Nation settles government antitrust suit — that probably doesn’t include a breakup

On Monday, Live Nation-Ticketmaster agreed to settle a federal antitrust lawsuit with the Department of Justice. Eight states so far have indicated they plan...