更新SafeNet令牌后Windows 10/11驱动签名验证异常问题
驱动代码签名令牌替换后未开启Secure Boot设备验证失败问题
我们用于软件和驱动签名的旧SafeNet身份验证令牌(原Symantec品牌)已过期,遂采购了归属Thales的新令牌(Thales已收购Symantec相关业务)。
旧令牌相关信息
- CA信任链:
- VeriSign Class 3 Public Primary Certification Authority - G5
- Symantec Class 3 Extended Validation Code Signing CA - G2
- 用户证书预期用途:Code Signing
- 使用情况:签名驱动和目录后,可直接在未开启Secure Boot的PC上使用;经Microsoft attestation签名后可在开启Secure Boot的PC上使用。
新令牌相关信息
- CA信任链:
- Digicert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1
- Digicert Trusted Root G4
- 用户证书预期用途:Code Signing
- 使用情况:可正常签名驱动和目录,经Microsoft attestation签名后可在开启/未开启Secure Boot的PC上使用,但未开启Secure Boot的PC无法直接使用签名后的驱动,设备管理器报错:
Windows cannot verify the digital signature for the drivers required
for this device. A recent hardware or software change might have installed
a file that is signed incorrectly or damaged, or that might be malicious
software from an unknown source. (Code 52)
驱动本身显示新签名及完整信任链,但未开启Secure Boot的设备仍无法验证。目前可通过bcedit禁用驱动验证解决,但不愿强制测试人员操作,也不想为每个CI构建手动进行attestation签名,这已破坏CI基础设施及自动化测试环境。
问询问题
- 新代码签名令牌出现此情况是否为预期行为?
- 我们收到的替换令牌是否存在问题或不符合要求?
使用的签名命令
sign /s MY /sha1 KEY_SHA1 /n "My GmbH" /fd sha256 /tr http://timestamp.digicert.com driver.sys
内容的提问来源于stack exchange,提问作者Gunther
相关产品推荐
相关产品推荐

