Windows secure boot certificate, how is this even possible?
Posted by frankv1971@reddit | sysadmin | View on Reddit | 103 comments
\[rant I guess\]
The last couple of weeks I have been trying to get our physical and virtual servers updated. I am just wondering who in the world decided to keep a certificate for secure boot alive for 15 years and not update this in the meantime so it would be updated during normal hardware/os replacements. So now a couple of months before the first one expires we have to update our servers.
I have servers that have the new Windows UEFI CA 2023 installed, Microsoft UEFI CA 2023 and Microsoft Corporation KEK 2K CA 2023 not installed. Others have Windows UEFI CA 2023 and Microsoft Corporation KEK 2K CA 2023 installed, Microsoft UEFI CA 2023 not installed. Some have Windows UEFI CA 2023 and Microsoft UEFI CA 2023 installed, Microsoft Corporation KEK 2K CA 2023 not installed. Most are still status InProgress, I even have one that says it is completed but is missing Microsoft UEFI CA 2023.
This is with servers up to CU 3/2026. You would expect this to be a smooth transition but instead I never met such a shitshow in more than 25 years in IT.
We are a rather small shop and not using Intune so that might not help.
103 Comments
djtterb@reddit
Technical_Gold_8278@reddit
bjc1960@reddit
xtobotn@reddit
bjc1960@reddit
frankv1971@reddit (OP)
xtobotn@reddit
TheJesusGuy@reddit
frankv1971@reddit (OP)
DL72-Alpha@reddit
Break2FixIT@reddit
pc_load_letter_in_SD@reddit
NoURider@reddit
HearthOfDarkness@reddit
praetorthesysadmin@reddit
TheJesusGuy@reddit
eater_of_spaetzle@reddit
Own_Back_2038@reddit
looncraz@reddit
TheJesusGuy@reddit
Apachez@reddit
Own_Back_2038@reddit
Apachez@reddit
Own_Back_2038@reddit
looncraz@reddit
TheJesusGuy@reddit
jake04-20@reddit
TheJesusGuy@reddit
jake04-20@reddit
TheJesusGuy@reddit
jake04-20@reddit
Apachez@reddit
riazzzz@reddit
xfilesvault@reddit
looncraz@reddit
xfilesvault@reddit
looncraz@reddit
Own_Back_2038@reddit
looncraz@reddit
slippery_hemorrhoids@reddit
New-Seesaw1719@reddit
r4x@reddit
nyckidryan@reddit
r4x@reddit
rundgren@reddit
mb194dc@reddit
pdp10@reddit
Schourend@reddit
beren12@reddit
pdp10@reddit
Laxarus@reddit
KnightNZ@reddit
jess-sch@reddit
Walbabyesser@reddit
Schourend@reddit
frankv1971@reddit (OP)
Imobia@reddit
pdp10@reddit
thetrivialstuff@reddit
frankv1971@reddit (OP)
BlockBannington@reddit
frankv1971@reddit (OP)
BlockBannington@reddit
VexingRaven@reddit
frankv1971@reddit (OP)
BlockBannington@reddit
Apachez@reddit
frankv1971@reddit (OP)
iceph03nix@reddit
frankv1971@reddit (OP)
Apachez@reddit
thetrivialstuff@reddit
frankv1971@reddit (OP)
cluberti@reddit
Brilliant-Advisor958@reddit
VexingRaven@reddit
Adam_Kearn@reddit
Fuzzy_Paul@reddit
AP_ILS@reddit
Darkk_Knight@reddit
bentleythekid@reddit
bjc1960@reddit
log_a_ticket@reddit
RedditSold0ut@reddit
log_a_ticket@reddit
RedditSold0ut@reddit
log_a_ticket@reddit
RedditSold0ut@reddit
frankv1971@reddit (OP)
log_a_ticket@reddit
ka-splam@reddit
frankv1971@reddit (OP)
pops107@reddit
RedditSold0ut@reddit
Apachez@reddit
ka-splam@reddit
frankv1971@reddit (OP)
Wolfram_And_Hart@reddit
frankv1971@reddit (OP)
Wolfram_And_Hart@reddit
eater_of_spaetzle@reddit
frankv1971@reddit (OP)
Substantial_Tough289@reddit