You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

更新SafeNet令牌后Windows 10/11驱动签名验证异常问题

驱动代码签名令牌替换后未开启Secure Boot设备验证失败问题

我们用于软件和驱动签名的旧SafeNet身份验证令牌(原Symantec品牌)已过期,遂采购了归属Thales的新令牌(Thales已收购Symantec相关业务)。

旧令牌相关信息

  • CA信任链:
    • VeriSign Class 3 Public Primary Certification Authority - G5
    • Symantec Class 3 Extended Validation Code Signing CA - G2
  • 用户证书预期用途:Code Signing
  • 使用情况:签名驱动和目录后,可直接在未开启Secure Boot的PC上使用;经Microsoft attestation签名后可在开启Secure Boot的PC上使用。

新令牌相关信息

  • CA信任链:
    • Digicert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1
    • Digicert Trusted Root G4
  • 用户证书预期用途:Code Signing
  • 使用情况:可正常签名驱动和目录,经Microsoft attestation签名后可在开启/未开启Secure Boot的PC上使用,但未开启Secure Boot的PC无法直接使用签名后的驱动,设备管理器报错:

Windows cannot verify the digital signature for the drivers required
for this device. A recent hardware or software change might have installed
a file that is signed incorrectly or damaged, or that might be malicious
software from an unknown source. (Code 52)

驱动本身显示新签名及完整信任链,但未开启Secure Boot的设备仍无法验证。目前可通过bcedit禁用驱动验证解决,但不愿强制测试人员操作,也不想为每个CI构建手动进行attestation签名,这已破坏CI基础设施及自动化测试环境。

问询问题

  1. 新代码签名令牌出现此情况是否为预期行为?
  2. 我们收到的替换令牌是否存在问题或不符合要求?

使用的签名命令

sign /s MY /sha1 KEY_SHA1 /n "My GmbH" /fd sha256 /tr http://timestamp.digicert.com driver.sys

内容的提问来源于stack exchange,提问作者Gunther

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.12 16:20:28