Skip to content

UEFI CA 2011 revocations to remain mandatory - #460

Open
jcoester wants to merge 1 commit into
microsoft:mainfrom
jcoester:optional-flags
Open

UEFI CA 2011 revocations to remain mandatory#460
jcoester wants to merge 1 commit into
microsoft:mainfrom
jcoester:optional-flags

Conversation

@jcoester

@jcoester jcoester commented Aug 29, 2026

Copy link
Copy Markdown

This has been discussed repeatedly and remains a security issue, still unresolved as of 29th August 2026:

Three Canonical images signed by Microsoft Corporation UEFI CA 2011 are marked as isOptional, meaning Windows Update does not automatically apply these revocations on my latest 25H2 (Build 26200.9278), and I had to append them via firmware Secure Boot Key Management.

While Microsoft Corporation UEFI CA 2011 is expired, it remains quasi-required for Windows systems with dedicated graphics cards for many years to come. The affected three Canonical images are associated with a wide range of known Secure Boot vulnerabilities: CVE-2020-10713, CVE-2020-14308, CVE-2020-14309, CVE-2020-14310, CVE-2020-14311, CVE-2020-15705, CVE-2020-15706, CVE-2020-15707.

Strongly suggest keeping these three UEFI CA 2011 revocations mandatory so the intended Secure Boot protection is automatically applied through Windows Update.

Maybe it can be clarified why the optional revocations are not rolled out on systems with the respective certs present; in which case they are not optional. As suggested before, future rollouts may use DB-aware DBX servicing to prevent major security gaps and optimize NVRAM storage (#447).

UEFI CA 2011 revocations need to remain mandatory because systems with dedicated GPUs may depend on UEFI CA 2011. As Windows Update currently skips applying optional revocations after unrelated PCA 2011 is revoked, marking these UEFI CA 2011 revocations as “optional” leaves systems vulnerable.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant