Issues after revoking the "Windows Production CA 2011" certificate

York Waugh 90 Reputation points
2024-09-09T10:30:31.8966667+00:00

A few months ago, I followed the instructions from KB5025885 and completed the 4-step mitigation deployment. Now, my EFI files are signed with the "Windows UEFI CA 2023" certificate, and the "Windows Production CA 2011" certificate has been revoked.

However, I have encountered an issue: I can't perform major version updates (e.g., updating from 23H2 to 24H2) via OTA, nor can I install the update using the official ISO images when Secure Boot is enabled. Currently, all images are still signed with the old certificate, and I understand that the "Windows UEFI CA 2023" certificate hasn't been widely added to UEFI firmware yet.

I can complete the update manually by following the steps in the "Updating Windows install media" section to update the boot certificate. However, this means I won’t be able to update via OTA or use the system recovery function in the future unless I disable Secure Boot.

Is there a better solution to this issue? Also, is there a clear timeline for updating the boot manager signature in the official ISO images?

Thank you!

Windows for business | Windows Client for IT Pros | User experience | Other
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Anonymous
    2024-09-10T07:38:11.46+00:00

    Hello York Waugh,

    Thank you for posting in Q&A forum.

    As a temporary workaround, you might want to try turning off Secure Boot while updating and then switch it back on once you're done. It's not the best solution, but it could help bridge the gap. And there is no clear timeline yet, please be patient and stay tuned for official information.

    I hope the information above is helpful.

    If you have any questions or concerns, please feel free to let us know.

    Best Regards,

    Daisy Zhou

    ============================================

    If the Answer is helpful, please click "Accept Answer" and upvote it.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.